|
Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
| 00:05:00 | Win2K-f | 122.52.66.18 (PLDT.NET): IPG, PH. |
n/a | US:microsoft.com US:download.microsoft.com :proxim.ircgalaxy.pl US:198.78.201.126:80 US:207.123.37.124:80 |
135 | pcap | raw alerts ruleset |
http 127 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 33 33 of 33 0 of 32 |
16874933ea [Firefox:60 hits: 06-18 to 11-06] 76ee340669 [Firefox:60 hits: 06-18 to 11-06] b5919931fe [Firefox:1087 hits: 06-20 to 11-07] |
16874933ea [1] none [4] b5919931fe[1] b5919931fe[1] |
ASM:Graph none:none ASM:Graph |
Armadillo| PolyEnE| ASProtect| |
lines=82 none lines=90 |
trace trace trace |
| 00:09:00 | Win2K-f | 124.241.144.82 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, AICHI, JP. |
n/a | US:microsoft.com US:download.microsoft.com US:4.23.60.125:80 |
135 | pcap | raw alerts ruleset |
other 80 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:3791 hits: 06-17 to 11-07] a08f3b74a4 [Firefox:1353 hits: 06-18 to 11-07] |
none[4] a08f3b74a4[1] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| T:00:19:00 | WinXP | 70.62.226.28 (RR.COM): ROAD RUNNER HOLDCO LLC, FAIRFIELD, OHIO, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 1010 lines |
Yeah : 1.3 profile |
none | summary tarball |
15 of 36 13 of 36 |
5db0ec83f4 NEW df157c297c NEW |
none [none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
|
| T:00:22:00 | WinXP | 86.97.252.208 (NET.AE): EMIRATES TELECOMMUNICATIONS CORPORATION, SHARJAH, ASH SHARIQAH, AE. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:1465 hits: 12-31 to 11-07] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
| T:00:26:00 | WinXP | 24.86.124.146 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, BURNABY, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 579 lines |
Yeah : 1.3 profile |
none | summary tarball |
20 of 36 | 739739a85a NEW |
none [none] | none:none |
none|none | none | none | |
| 00:28:00 | WinXP | 115.83.169.25 (-): . |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:192.221.96.126:80 US:205.128.73.126:80 US:207.123.46.125:80 |
135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 36 32 of 36 |
58a2179594 NEW 72c2440514 NEW |
none [none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
| 00:48:00 | WinXP | 60.248.37.67 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | 135 | pcap | raw alerts ruleset |
other 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 00:49:00 | WinXP | 59.104.254.15 (SEED.NET.TW): DIGITAL UNITED I, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
35 of 36 | f4bffb9e96 NEW |
none [none] | none:none |
none|none | none | none |
| T:00:51:00 | WinXP | 84.237.205.57 (MICROLINK.LV): TELEKOM, RIGA, RIGA, LV. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 35 | 4246aed71d NEW |
none [none] | none:none |
none|none | none | none |
| 01:16:00 | WinXP | 78.139.155.182 (-): CAUCASUS NETWORK LTD, GE. |
n/a | :proxim.ircgalaxy.pl RU:moscow-advokat.ru RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
33 of 35 | 7530118606 NEW |
none [none] | none:none |
none|none | none | none |
| T:01:18:00 | WinXP | 24.85.82.128 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, VANCOUVER, BRITISH COLUMBIA, CA. (DSL) |
72.10.172.218:9928 | CA:dong.nagitiriheiwu.net CA:teek.ihshsd8.com CA:72.10.169.26:2293 CA:72.10.169.26:80 |
135 | pcap | raw alerts ruleset |
irc 285 lines |
Yeah : 1.8 profile |
none | summary tarball |
33 of 36 | 5982f6fc33 NEW |
none [none] | none:none |
none|none | none | none |
| 01:21:00 | WinXP | 82.254.90.88 (PROXAD.NET): PROXAD / FREE SAS, NICE, PROVENCE-ALPES-COTE D'AZUR, FR. (DSL) |
n/a | RU:moscow-advokat.ru RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 9dab636a01 [Firefox: 2 hits: 07-09 to 08-08] |
none [none] | none:none |
none|none | none | none |
| T:01:24:00 | Win2K-f | 71.130.22.21 (PACBELL.NET): WILLIAM MARTINEZ DBA, PLANO, TEXAS, US. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:204.160.126.126:80 US:205.128.70.126:80 US:4.23.60.126:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:3791 hits: 06-17 to 11-07] a08f3b74a4 [Firefox:1353 hits: 06-18 to 11-07] |
none[4] a08f3b74a4[1] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| 01:43:00 | WinXP | 211.178.55.152 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | :proxima.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:204.160.104.126:80 |
135 | pcap | raw alerts ruleset |
http 87 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 33 0 of 33 0 of 33 |
168aab35a3 [Firefox:185 hits: 06-17 to 11-07] 4c3df24b32 [Firefox:241 hits: 06-17 to 11-05] e07c29c4ae [Firefox:805 hits: 06-19 to 11-07] |
none[4] 4c3df24b32[1] e07c29c4ae[1] e07c29c4ae[1] |
none:none ASM:Graph ASM:Graph |
tElock| Armadillo| FSG| |
none lines=81 lines=92 |
trace trace trace |
| T:01:45:00 | WinXP | 92.84.22.17 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
194.54.90.246:80 | :proxim.ircgalaxy.pl UA:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 36 | 10c3e12a46 [Firefox:11 hits: 11-01 to 11-07] |
none [none] | none:none |
none|none | none | none |
| T:01:52:00 | WinXP | 193.227.109.250 (-): SC SKY NET SRL, IASI, IASI, RO. |
194.54.90.246:80 | :proxim.ircgalaxy.pl UA:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 36 | 08f7a637d6 [Firefox: 4 hits: 11-04 to 11-06] |
none [none] | none:none |
none|none | none | none |
| T:01:54:00 | WinXP | 77.253.102.152 (COM.PL): NETIA, PL. |
194.54.90.246:80 | :proxim.ircgalaxy.pl UA:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 36 | 08f7a637d6 [Firefox: 4 hits: 11-04 to 11-06] |
none [none] | none:none |
none|none | none | none |
| 01:58:00 | Win2K-f | 61.221.167.96 (HINET.NET): DATA COMMUNICATION BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | US:microsoft.com US:download.microsoft.com US:198.78.201.126:80 US:199.93.53.126:80 US:8.12.202.125:80 |
135 | pcap | raw alerts ruleset |
other 95 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:3791 hits: 06-17 to 11-07] 57ce4acac2 [Firefox:328 hits: 06-17 to 11-07] |
none[4] 57ce4acac2[1] 57ce4acac2[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| T:02:00:00 | WinXP | 88.141.150.26 (GAOLAND.NET): INTERNET RESIDENTIEL CEGETEL FRANCE, FR. |
n/a | UA:citi-bank.ru :makemegood24.com :73769.makemegood24.com :aaakemegood24.com :perfectchoice1.com :7393e.perfectchoice1.com **:bparfectchoice1.com DE:cash-ddt.net |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
33 of 36 | 0e5f51ee8e [Firefox:20 hits: 10-11 to 11-05] |
none [none] | none:none |
none|none | none | none |
| 02:08:00 | WinXP | 98.174.0.4 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 53 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | 73f1082158 [Firefox:1890 hits: 06-18 to 11-07] |
73f1082158 [1] | ASM:Graph |
Armadillo| | lines=81 | trace | |
| T:02:11:00 | Win2K-f | 172.133.110.36 (AOL.COM): AMERICA ONLINE, RESTON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.110.125:80 US:205.128.70.126:80 |
135 | pcap | raw alerts ruleset |
http 210 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 36 29 of 33 0 of 32 |
0474b4b09f [Firefox:13 hits: 09-24 to 11-05] 1c3210698a [Firefox:15 hits: 07-13 to 11-05] b5919931fe [Firefox:1087 hits: 06-20 to 11-07] |
none[none] none [none] b5919931fe[1] b5919931fe[1] |
none:none none:none ASM:Graph |
none|none none|none ASProtect| |
none none lines=90 |
none none trace |
| T:02:12:00 | Win2K-f | 203.91.180.130 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, AICHI, JP. |
n/a | 135 |