| 
Time | 
      
Victim  OS  | 
      
Infection Source  | 
      
C&C Server  | 
      
DNS Lookups & Failed Connects  | 
      
Infection Port  | 
      
      
Packet Trace  | 
      
Detection Signatures  | 
      
Infection Chatter  | 
      
BotHunter Analysis  | 
      
Behavioral Cluster  | 
      
Forensic Logs  | 
      
Antivirus Labels  | 
      Packed Malware_Binary | 
Unpacked egg.exe | 
      
Unpacked egg.asm | 
      
Packer PEID | 
      
Data Strings | 
      
Syscall Trace | 
    
| T:00:07:00 | WinXP |  119.228.80.212 (-): .  | 
      n/a | 445 | pcap | raw alerts ruleset  | 
      shell ftp 15 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      40 of 41 | 2cb7fb5674 NEW  | 
      4bf8dcd347 [0] | none:none | 
      none|none | none | trace | |
| T:00:12:00 | WinXP |   96.11.133.187 (-): .  | 
      n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset  | 
      other 75 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      
      33 of 33 0 of 32  | 
      53bfe15e91 NEW 73f1082158 NEW  | 
      1473091351 [0] none [0]  | 
      ASM:Graph none:none  | 
      tElock| Armadillo|  | 
      lines=75 embedded dns lines=90  | 
      trace trace  | 
    
| T:01:08:00 | Win2K-f |  116.127.127.93 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR.  | 
      218.93.205.30:65520 | CN:proxim.ircgalaxy.pl  US:microsoft.com CN:www.brans.pl CN:gidromash.cn CN:211.95.79.170:80 CN:218.93.205.19:80 CN:218.93.205.30:65520  | 
      135 | pcap | raw alerts ruleset  | 
      irc 131 lines  | 
      Yeah : 1.8 profile  | 
      none | summary tarball  | 
      
      29 of 32 28 of 32  | 
      8a75955033 NEW 9276c8b36b NEW  | 
      2bf3e548b9 [0] none [0]  | 
      ASM:Graph ASM:Graph  | 
      tElock| Armadillo|  | 
      lines=126 embedded dns lines=81  | 
      trace trace  | 
    
| T:04:18:00 | WinXP |    60.56.99.192 (EONET.NE.JP): K-OPTICOM CORPORATION, OSAKA, OSAKA, JP.  | 
      n/a | 445 | pcap | raw alerts ruleset  | 
      shell ftp 15 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      29 of 29 | 831f4ee0a7 NEW  | 
      none [0] | ASM:Graph | 
      none|none | lines=61 | trace | |
| T:04:22:00 | Win2K-f | 172.130.223.208 (AOL.COM): AMERICA ONLINE, RESTON, VIRGINIA, US. (DSL)  | 
      n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset  | 
      other 106 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      
      33 of 33 0 of 32  | 
      53bfe15e91 NEW 73f1082158 NEW  | 
      1473091351 [0] none [0]  | 
      ASM:Graph none:none  | 
      tElock| Armadillo|  | 
      lines=75 embedded dns lines=90  | 
      trace trace  | 
    
| T:04:41:00 | Win2K-f |    24.86.71.239 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SURREY, BRITISH COLUMBIA, CA. (DSL)  | 
      n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset  | 
      other 75 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      
      33 of 33 0 of 33  | 
      53bfe15e91 NEW a08f3b74a4 NEW  | 
      1473091351 [0] none [0]  | 
      ASM:Graph none:none  | 
      tElock| Armadillo|  | 
      lines=75 embedded dns lines=90  | 
      trace trace  | 
    
| T:06:24:00 | Win2K-f |   207.5.236.176 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US.  | 
      n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset  | 
      other 75 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      
      33 of 33 0 of 32  | 
      53bfe15e91 NEW 73f1082158 NEW  | 
      1473091351 [0] none [0]  | 
      ASM:Graph none:none  | 
      tElock| Armadillo|  | 
      lines=75 embedded dns lines=90  | 
      trace trace  | 
    
| T:07:54:00 | Win2K-f |    96.8.204.191 (-): .  | 
      n/a | 135 | pcap | raw alerts ruleset  | 
      other 10 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      none | none | none | none | none | none | none | |
| T:09:58:00 | WinXP |  87.173.120.188 (T-IPCONNECT.DE): DEUTSCHE TELEKOM AG, DE.  | 
      n/a | 445 | pcap | raw alerts ruleset  | 
      shell ftp 14 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      31 of 32 | 741e3b03b3 NEW  | 
      none [0] | none:none | 
      none|none | lines=61 | trace | |
| T:10:21:00 | WinXP |     66.184.4.23 (LDMI.COM): TALK AMERICA, DETROIT, MICHIGAN, US.  | 
      n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset  | 
      http 1 line  | 
      Yeah : 0.8 profile  | 
      none | summary tarball  | 
      35 of 36 | b27d73bfcb NEW  | 
      473c6454ce [0] | ASM:Graph | 
      PolyEnE| | lines=68 | trace | 
| T:10:40:00 | Win2K-f |  114.205.180.89 (-): .  | 
      218.93.205.30:65520 | CN:proxim.ircgalaxy.pl  US:microsoft.com CN:dl.guarddog2009.com CN:gidromash.cn CN:211.95.79.170:80 CN:218.93.205.19:80  | 
      135 | pcap | raw alerts ruleset  | 
      irc 127 lines  | 
      Yeah : 1.8 profile  | 
      none | summary tarball  | 
      
      29 of 32 28 of 32  | 
      8a75955033 NEW 9276c8b36b NEW  | 
      2bf3e548b9 [0] none [0]  | 
      ASM:Graph ASM:Graph  | 
      tElock| Armadillo|  | 
      lines=126 embedded dns lines=81  | 
      trace trace  | 
    
| T:11:05:00 | WinXP |   61.59.150.186 (SEED.NET.TW): DIGITAL UNITED INC, TAIPEI, T'AI-PEI, TW. (DSL)  | 
      n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset  | 
      http 1 line  | 
      Yeah : 0.8 profile  | 
      none | summary tarball  | 
      39 of 41 | e70e195b77 NEW  | 
      3d277747d3 [0] | none:none | 
      PolyEnE| | none | trace | 
| T:11:14:00 | WinXP |   114.48.30.243 (-): .  | 
      n/a | 445 | pcap | raw alerts ruleset  | 
      shell ftp 15 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      37 of 40 | 5285741560 NEW  | 
      60590b8b67 [0] | ASM:Graph | 
      none|none | lines=59 | trace | |
| T:12:12:00 | Win2K-f |      66.19.3.93 (USLEC.NET): USLEC CORP, WORCESTER, MASSACHUSETTS, US.  | 
      n/a | 135 | pcap | raw alerts ruleset  | 
      other 4 lines  | 
      Yeah : 0.8 profile  | 
      none | summary tarball  | 
      none | none | none | none | none | none | none | |
| T:13:21:00 | WinXP |    174.7.12.128 (-): .  | 
      n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset  | 
      other 76 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      
      33 of 33 0 of 33  | 
      53bfe15e91 NEW a08f3b74a4 NEW  | 
      1473091351 [0] none [0]  | 
      ASM:Graph none:none  | 
      tElock| Armadillo|  | 
      lines=75 embedded dns lines=90  | 
      trace trace  | 
    
| T:13:38:00 | WinXP | 172.129.139.131 (AOL.COM): AMERICA ONLINE, RESTON, VIRGINIA, US. (DSL)  | 
      n/a | 135 | pcap | raw alerts ruleset  | 
      other 168 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      0 of 32 | 73f1082158 NEW  | 
      none [0] | none:none | 
      Armadillo| | lines=90 | trace | |
| T:14:39:00 | WinXP |  218.220.142.12 (ZAQ.NE.JP): KITAKAWACHI CABLE NET CO LTD, OSAKA, OSAKA, JP.  | 
      n/a | CN:done.blacktiehsbdcs.com | 135 | pcap | raw alerts ruleset  | 
      irc http 589 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      
      23 of 41 39 of 40  | 
      3c77533bf6 NEW d8b652221d NEW  | 
      389c06c67e [0] edfa4116ba[0] edfa4116ba[0]  | 
      none:none none:none  | 
      StarForce| ASPack|  | 
      none none  | 
      trace trace  | 
    
| T:15:06:00 | WinXP |  173.29.130.232 (-): .  | 
      n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset  | 
      other 110 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      
      36 of 41 38 of 40  | 
      067917e07b NEW d764c1dcb2 NEW  | 
      dae35b319c [0] 3d2bc60c5d[0] 3d2bc60c5d[0]  | 
      none:none none:none  | 
      Armadillo| tElock|  | 
      none none  | 
      trace trace  | 
    
| T:16:21:00 | WinXP |   122.30.183.72 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP.  | 
      n/a | 445 | pcap | raw alerts ruleset  | 
      shell ftp 15 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      none | none | none | none | none | none | none | |
| T:17:05:00 | WinXP |  219.122.214.29 (EONET.NE.JP): K-OPTICOM CORPORATION, JP.  | 
      n/a | 445 | pcap | raw alerts ruleset  | 
      shell ftp 15 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      40 of 41 | 2cb7fb5674 NEW  | 
      4bf8dcd347 [0] | none:none | 
      none|none | none | trace | |
| T:18:17:00 | WinXP |    72.181.45.25 (RR.COM): ROAD RUNNER HOLDCO LLC, HOUSTON, TEXAS, US.  | 
      n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset  | 
      other 75 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      
      33 of 33 0 of 33  | 
      53bfe15e91 NEW a08f3b74a4 NEW  | 
      1473091351 [0] none [0]  | 
      ASM:Graph none:none  | 
      tElock| Armadillo|  | 
      lines=75 embedded dns lines=90  | 
      trace trace  | 
    
| T:18:59:00 | WinXP |   95.93.192.191 (-): .  | 
      n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset  | 
      http 1 line  | 
      Yeah : 0.8 profile  | 
      none | summary tarball  | 
      40 of 41 | a1f992a08e NEW  | 
      75ca0b4a8f [0] | none:none | 
      PolyEnE| | none | trace | 
| T:20:02:00 | Win2K-f |  70.123.103.157 (RR.COM): ROAD RUNNER HOLDCO LLC, LEAGUE CITY, TEXAS, US.  | 
      n/a | 135 | pcap | raw alerts ruleset  | 
      other 414 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      40 of 41 | fd120fafac NEW  | 
      3fbd04c869 [0] | none:none | 
      PENinja S| | none | trace | |
| T:20:03:00 | WinXP |   68.125.24.230 (PACBELL.NET): PPPOX POOL - BRAS1 IRVNCA, LOS ANGELES, CALIFORNIA, US. (DSL)  | 
      213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset  | 
      http 2 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      29 of 29 | d6df3972a0 NEW  | 
      none [0] | ASM:Graph | 
      PolyEnE| | lines=65 | trace | 
| T:21:29:00 | WinXP | 119.228.209.183 (-): .  | 
      n/a | 445 | pcap | raw alerts ruleset  | 
      shell ftp 15 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      38 of 41 | 7b313206a2 NEW  | 
      0c866c8cce [0] | none:none | 
      none|none | none | trace | |
| T:21:47:00 | WinXP |  119.228.136.40 (-): .  | 
      n/a | US:mx1.hotmail.com  US:ftp.newaol.com US:mailin-02.mx.aol.com US:yutunrz.1dumb.com US:mailin-01.mx.aol.com :wpad  | 
      445 | pcap | raw alerts ruleset  | 
      shell ftp http http 174 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      
      1 of 41 38 of 41 1 of 41  | 
      3137f0c609 NEW 85ea746b9a NEW bf01cf2a15 NEW  | 
      cb9eaddc3c [0] 54e7ab3f6f[0] cb9eaddc3c[0] cb9eaddc3c[0]  | 
      none:none none:none none:none  | 
      Free| none|none Free|  | 
      none none none  | 
      trace trace trace  | 
    
| T:22:09:00 | WinXP |  222.127.187.88 (SUMIFRU.COM): GLOBE TELECOM/INNOVE COMMUNICATION, PH.  | 
      n/a | US:mx1.hotmail.com  US:mailin-04.mx.aol.com US:ftp.newaol.com US:yutunrz.1dumb.com US:mailin-02.mx.aol.com US:ftp.icq.com US:mcduii.3-a.net US:http.icq.com.edgesuite.net  | 
      445 | pcap | raw alerts ruleset  | 
      http http 105 lines  | 
      Yeah : 0.8 profile  | 
      none | summary tarball  | 
      1 of 41 | 3137f0c609 NEW  | 
      cb9eaddc3c [0] | none:none | 
      Free| | none | trace | 
| T:22:44:00 | WinXP | 113.252.241.214 (-): .  | 
      n/a | US:imtoey.3-a.net  BE:ftp.scarlet.be US:yutunrz.1dumb.com US:ftp.icq.com US:http.icq.com.edgesuite.net US:mx1.hotmail.com US:mailin-04.mx.aol.com US:ftp.newaol.com US:mailin-01.mx.aol.com BE:193.74.22.160:80  | 
      135 | pcap | raw alerts ruleset  | 
      http http http 120 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      1 of 41 | edcdbe29d1 NEW  | 
      cb9eaddc3c [0] | none:none | 
      Free| | none | trace |