|
Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
| 00:10:00 | WinXP | 72.64.30.16 (VERIZON.NET): VERIZON INTERNET SERVICES INC, CHARLESTON, WEST VIRGINIA, US. |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.108.126:80 US:199.93.41.126:80 US:199.93.44.124:80 |
135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:3740 hits: 06-17 to 11-04] 73f1082158 [Firefox:1859 hits: 06-18 to 11-04] |
none[4] 73f1082158[1] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| 00:18:00 | WinXP | 72.215.49.28 (COX.NET): COX COMMUNICATIONS, BRISTOL, RHODE ISLAND, US. |
n/a | US:microsoft.com US:download.microsoft.com US:205.128.70.126:80 US:207.123.37.125:80 US:207.123.46.125:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:3740 hits: 06-17 to 11-04] 73f1082158 [Firefox:1859 hits: 06-18 to 11-04] |
none[4] 73f1082158[1] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| T:00:30:00 | WinXP | 78.34.37.17 (NETCOLOGNE.DE): NETCOLOGNE GMBH, KOELN, NORDRHEIN-WESTFALEN, DE. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
35 of 36 | a8c10e184d [Firefox: 2 hits: 11-03 to 11-04] |
none [none] | none:none |
none|none | none | none |
| T:00:43:00 | WinXP | 84.139.231.91 (T-IPCONNECT.DE): DEUTSCHE TELEKOM AG, ROSTOCK, MECKLENBURG-VORPOMMERN, DE. |
n/a | :proxim.ircgalaxy.pl ES:tele-pc.com IT:macedonia.my1.ru CN:jrsx.jre.net.cn PL:tunska.komrel.net US:www.yahoo.com US:www.hkwebguru.com :soncibbs.eastday.com ES:www.familiaordonez.com **:2.0.0.127.bl.spamcop.net :45.206.107.130.bl.spamcop.net **:2.0.0.127.cbl.abuseat.org :45.206.107.130.cbl.abuseat.org :2.0.0.127.list.dsbl.org **:2.0.0.127.sbl-xbl.spamhaus.org AU:ozfloorball.com :45.206.107.130.sbl-xbl.spamhaus.org **:2.0.0.127.zen.spamhaus.org :45.206.107.130.zen.spamhaus.org **:2.0.0.127.combined.njabl.org :45.206.107.130.combined.njabl.org :2.0.0.127.multihop.dsbl.org :2.0.0.127.blackholes.uceb.org **:2.0.0.127.bl.csma.biz **:2.0.0.127.db.wpbl.info **:2.0.0.127.dnsbl.njabl.org US:mailin-02.mx.aol.com US:mailin-01.mx.aol.com US:mailin-03.mx.aol.com |
445 | pcap | raw alerts ruleset |
http 136 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
| T:00:49:00 | WinXP | 92.47.167.77 (IKBCC.COM): EU-ZZ, UK. |
194.54.90.246:80 | :proxim.ircgalaxy.pl UA:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 36 | a0012f058f [Firefox: 9 hits: 10-20 to 11-03] |
none [none] | none:none |
none|none | none | none |
| T:00:51:00 | WinXP | 117.99.31.130 (XLRI.AC.IN): BHARTI AIRTEL LTD, DELHI, DELHI, IN. |
n/a | CN:jrsx.jre.net.cn PL:tunska.komrel.net **:2.0.0.127.bl.spamcop.net :69.148.107.130.bl.spamcop.net **:2.0.0.127.cbl.abuseat.org :69.148.107.130.cbl.abuseat.org :2.0.0.127.list.dsbl.org **:2.0.0.127.sbl-xbl.spamhaus.org :69.148.107.130.sbl-xbl.spamhaus.org **:2.0.0.127.zen.spamhaus.org :69.148.107.130.zen.spamhaus.org **:2.0.0.127.combined.njabl.org :69.148.107.130.combined.njabl.org :2.0.0.127.multihop.dsbl.org :2.0.0.127.blackholes.uceb.org US:www.hkwebguru.com :soncibbs.eastday.com ES:www.familiaordonez.com AU:ozfloorball.com UA:citi-bank.ru **:2.0.0.127.bl.csma.biz :69.148.107.130.bl.csma.biz :proxim.ircgalaxy.pl **:2.0.0.127.db.wpbl.info **:2.0.0.127.dnsbl.njabl.org EU:mx1.yandex.ru US:mailin-01.mx.aol.com US:mailin-02.mx.aol.com US:mailin-03.mx.aol.com US:mailin-04.mx.aol.com :mxs.mail.ru :mx2.yandex.ru RU:imx1.rambler.ru US:c.mx.mail.yahoo.com UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 8 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a0139d7ad8 [Firefox:205 hits: 01-03 to 11-04] |
d9e9662db1 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
| 00:52:00 | WinXP | 114.137.41.220 (-): . |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
33 of 36 | 0e5f51ee8e [Firefox:19 hits: 10-11 to 11-04] |
none [none] | none:none |
none|none | none | none |
| 01:06:00 | WinXP | 204.116.246.110 (UNITED.NET): UNITED TELEPHONE COMPANY, MYRTLE BEACH, SOUTH CAROLINA, US. |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
35 of 36 | ebae9e44e3 NEW |
none [none] | none:none |
none|none | none | none |
| T:01:06:00 | WinXP | 204.116.246.110 (UNITED.NET): UNITED TELEPHONE COMPANY, MYRTLE BEACH, SOUTH CAROLINA, US. |
194.54.90.246:80 | :proxim.ircgalaxy.pl UA:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 36 | ebae9e44e3 NEW |
none [none] | none:none |
none|none | none | none |
| T:01:11:00 | WinXP | 78.106.36.230 (CORBINA.RU): BROADBAND CUSTOMERS IN MOSCOW, MOSCOW, MOSKVA, RU. |
n/a | :proxim.ircgalaxy.pl ES:tele-pc.com IT:macedonia.my1.ru CN:jrsx.jre.net.cn US:www.yahoo.com **:2.0.0.127.bl.spamcop.net :1.209.107.130.bl.spamcop.net **:2.0.0.127.cbl.abuseat.org :1.209.107.130.cbl.abuseat.org :2.0.0.127.list.dsbl.org **:2.0.0.127.sbl-xbl.spamhaus.org :1.209.107.130.sbl-xbl.spamhaus.org **:2.0.0.127.zen.spamhaus.org PL:tunska.komrel.net :1.209.107.130.zen.spamhaus.org **:2.0.0.127.combined.njabl.org US:www.hkwebguru.com :2.0.0.127.multihop.dsbl.org ES:www.familiaordonez.com :2.0.0.127.blackholes.uceb.org AU:ozfloorball.com **:2.0.0.127.bl.csma.biz **:2.0.0.127.db.wpbl.info **:2.0.0.127.dnsbl.njabl.org :mxs.mail.ru |
445 | pcap | raw alerts ruleset |
http 134 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
| 01:11:00 | WinXP | 61.64.3.248 (-): PHOENIX CATV C, TW. |
n/a | :proxim.ircgalaxy.pl | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
35 of 36 | 7fd7475c63 [Firefox: 5 hits: 10-29 to 11-02] |
none [none] | none:none |
none|none | none | none |
| T:01:14:00 | WinXP | 82.240.145.182 (PROXAD.NET): PROXAD / FREE SAS, NICE, PROVENCE-ALPES-COTE D'AZUR, FR. |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 36 | f611bd0182 NEW |
none [none] | none:none |
none|none | none | none |
| T:01:36:00 | WinXP | 89.41.89.112 (HOST-89-41-64-10.MOLDTELECOM.MD): JSC MOLDTELECOM SA, CHISINAU, CHISINAU, MD. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
35 of 36 | 414ae45a85 NEW |
none [none] | none:none |
none|none | none | none |
| T:01:44:00 | WinXP | 84.13.7.82 (84.IN-ADDR.ARPA): OPAL TELECOM DSL NETWORK, LONDON, ENGLAND, UK. (DSL) |
n/a | ES:www.familiaordonez.com AU:ozfloorball.com |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
| T:01:47:00 | WinXP | 81.198.232.109 (-): ADDRESS POOL FOR LTC-HOME CUSTOMERS, RIGA, RIGA, LV. |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 36 | d9a4f2f314 [Firefox:12 hits: 09-29 to 11-04] |
none [none] | none:none |
none|none | none | none |
| 01:49:00 | WinXP | 24.67.166.46 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, KELOWNA, BRITISH COLUMBIA, CA. (DSL) |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 36 | 4ed031d88c [Firefox:13 hits: 10-20 to 11-04] |
none [none] | none:none |
none|none | none | none |
| T:01:50:00 | WinXP | 24.67.166.46 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, KELOWNA, BRITISH COLUMBIA, CA. (DSL) |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 36 | 4ed031d88c [Firefox:13 hits: 10-20 to 11-04] |
none [none] | none:none |
none|none | none | none |
| 02:24:00 | WinXP | 24.29.84.249 (RR.COM): ROAD RUNNER HOLDCO LLC, ALBANY, NEW YORK, US. |
n/a | US:microsoft.com US:download.microsoft.com US:199.93.41.126:80 US:204.160.104.126:80 US:207.123.37.124:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:3740 hits: 06-17 to 11-04] a08f3b74a4 [Firefox:1340 hits: 06-18 to 11-04] |
none[4] a08f3b74a4[1] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| 02:28:00 | WinXP | 212.220.192.0 (-): J/S CO ETS, EKATERINBURG, SVERDLOVSKAYA OBLAST', RU. |
n/a | :www.google.com.au :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 17028f1eda [Firefox:56 hits: 04-18 to 11-02] |
none [3] | none:none |
tElock| | none | trace |
| 02:28:00 | Win2K-f | 172.164.17.62 (AOL.COM): AMERICA ONLINE, US. |
n/a | US:microsoft.com US:download.microsoft.com US:199.93.41.124:80 US:205.128.70.126:80 US:8.12.202.125:80 |
135 | pcap | raw alerts ruleset |
other 130 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 36 29 of 33 |
0474b4b09f [Firefox:12 hits: 09-24 to 10-31] 1c3210698a [Firefox:14 hits: 07-13 to 10-31] |
none [none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
| 02:48:00 | Win2K-f | 61.218.193.250 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.99.126:80 |
135 | pcap | raw alerts ruleset |
http 83 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 0 of 32 |
53bfe15e91 [Firefox:3740 hits: 06-17 to 11-04] 57ce4acac2 [Firefox:321 hits: 06-17 to 11-04] b5919931fe [Firefox:1065 hits: 06-20 to 11-04] |
none[4] 57ce4acac2[1] b5919931fe[1] b5919931fe[1] |
none:none ASM:Graph ASM:Graph |
tElock| Armadillo| ASProtect| |
none lines=81 lines=90 |
trace trace trace |
| 02:53:00 | WinXP | 62.11.118.115 (DIALUP.TISCALI.IT): TISCALI ITALIA SPA, IT. (DIAL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :wpad |
445 | pcap | raw alerts ruleset |
http http http 19 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee [Firefox:297 hits: 01-01 to 11-02] |
9bbdd086c5 [0] | ASM:Graph |
ASPack| | lines=186 embedded dns |
trace |
| T:03:36:00 | WinXP | 218.164.38.162 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, KAOHSIUNG, KAO-HSIUNG, TW. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:656 hits: 01-01 to 11-04] |