| 
Time | 
      
Victim  OS  | 
      
Infection Source  | 
      
C&C Server  | 
      
DNS Lookups & Failed Connects  | 
      
Infection Port  | 
      
      
Packet Trace  | 
      
Detection Signatures  | 
      
Infection Chatter  | 
      
BotHunter Analysis  | 
      
Behavioral Cluster  | 
      
Forensic Logs  | 
      
Antivirus Labels  | 
      Packed Malware_Binary | 
Unpacked egg.exe | 
      
Unpacked egg.asm | 
      
Packer PEID | 
      
Data Strings | 
      
Syscall Trace | 
    
| T:01:22:00 | Win2K-f |    74.214.47.11 (METROCAST.NET): GMP CABLE TV, BERWICK, PENNSYLVANIA, US.  | 
      n/a | 135 | pcap | raw alerts ruleset  | 
      other 298 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      32 of 33 | fe22b8315f NEW  | 
      bb25603f41 [0] | none:none | 
      StarForce| | none | trace | |
| T:01:54:00 | WinXP | 203.118.238.245 (-): GRAND TAINAN TECHNOLOGY CO.LTD, TAINAN, KAO-HSIUNG, TW.  | 
      n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset  | 
      other 75 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      
      33 of 33 0 of 33  | 
      53bfe15e91 NEW a08f3b74a4 NEW  | 
      1473091351 [0] none [0]  | 
      ASM:Graph none:none  | 
      tElock| Armadillo|  | 
      lines=75 embedded dns lines=90  | 
      trace trace  | 
    
| T:02:05:00 | Win2K-f |  203.54.167.237 (TMNS.NET.AU): TELSTRAINTERNET5, SYDNEY, NEW SOUTH WALES, AU.  | 
      n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset  | 
      other 132 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      
      33 of 33 8 of 33  | 
      53bfe15e91 NEW b7082104e4 NEW  | 
      1473091351 [0] c5b49e7b82[0] c5b49e7b82[0]  | 
      ASM:Graph ASM:Graph  | 
      tElock| tElock|  | 
      lines=75 embedded dns lines=41  | 
      trace trace  | 
    
| T:03:28:00 | WinXP |  193.250.134.53 (ABO.WANADOO.FR): IP2000-ADSL-BAS, FR.  | 
      n/a | 445 | pcap | raw alerts ruleset  | 
      ftp 14 lines  | 
      Yeah : 0.8 profile  | 
      none | summary tarball  | 
      29 of 29 | 1a2c0e6130 NEW  | 
      none [0] | none:none | 
      none|none | lines=60 | trace | |
| T:03:36:00 | WinXP |  218.163.44.227 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW.  | 
      213.219.245.212:80 | RU:citi-bank.ru RU:213.219.245.212:80  | 
      445 | pcap | raw alerts ruleset  | 
      http 3 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      39 of 41 | ed96c03ca8 NEW  | 
      c0028e9e98 [0] | none:none | 
      PolyEnE| | none | trace | 
| T:05:50:00 | WinXP |  219.254.99.231 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR.  | 
      218.93.205.30:65520 | CN:proxim.ircgalaxy.pl  US:microsoft.com CN:gidromash.cn CN:211.95.79.170:80  | 
      135 | pcap | raw alerts ruleset  | 
      irc 153 lines  | 
      Yeah : 1.8 profile  | 
      none | summary tarball  | 
      
      30 of 33 31 of 33  | 
      87bd0a062f NEW c7d6018f97 NEW  | 
      dc70d9623a [0] 5c1d8bbd5b[0] 5c1d8bbd5b[0]  | 
      none:none none:none  | 
      Armadillo| tElock|  | 
      none none  | 
      trace trace  | 
    
| T:07:00:00 | Win2K-f |   75.60.192.208 (SBCGLOBAL.NET): PPPOX POOL - SE1.WOTNOH, COLUMBUS, OHIO, US. (DSL)  | 
      n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset  | 
      other 75 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      
      33 of 33 0 of 33  | 
      53bfe15e91 NEW a08f3b74a4 NEW  | 
      1473091351 [0] none [0]  | 
      ASM:Graph none:none  | 
      tElock| Armadillo|  | 
      lines=75 embedded dns lines=90  | 
      trace trace  | 
    
| T:07:33:00 | WinXP |   86.105.216.12 (PANEVO.RO): SC PAN ELECTRO SRL, RO.  | 
      213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset  | 
      http 2 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      39 of 41 | ed96c03ca8 NEW  | 
      c0028e9e98 [0] | none:none | 
      PolyEnE| | none | trace | 
| T:07:40:00 | WinXP |    75.50.255.74 (SBCGLOBAL.NET): PPPOX POOL - RBACK6.MILWWI, MILWAUKEE, WISCONSIN, US. (DSL)  | 
      n/a | 445 | pcap | raw alerts ruleset  | 
      shell ftp 13 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      32 of 32 | 03f912899b NEW  | 
      none [0] | none:none | 
      none|none | lines=64 | trace | |
| T:08:11:00 | WinXP |   193.250.12.56 (ABO.WANADOO.FR): WANADOO, DIJON, BOURGOGNE, FR.  | 
      n/a | EU:siliconfireware.ru  US:searchportal.information.com :wpad US:208.73.210.125:80  | 
      445 | pcap | raw alerts ruleset  | 
      http http http 3 lines  | 
      Yeah : 0.8 profile  | 
      none | summary tarball  | 
      29 of 29 | df17a625ee NEW  | 
      none [0] | none:none | 
      ASPack| | lines=298 embedded dns  | 
      trace | 
| T:08:22:00 | WinXP |   92.40.221.126 (IKBCC.COM): EU-ZZ, UK.  | 
      n/a | DE:siliconfireware.ru  US:searchportal.information.com RU:www.bbin.ru RU:www.binbank.ru :wpad US:spi.domainsponsor.com US:208.73.210.125:80  | 
      445 | pcap | raw alerts ruleset  | 
      http http http http 32 lines  | 
      Yeah : 0.8 profile  | 
      none | summary tarball  | 
      40 of 41 | c4ab97fc12 NEW  | 
      50ed7b9394 [0] | none:none | 
      ASPack| | none | trace | 
| T:09:07:00 | Win2K-f | 121.121.155.116 (MAXIS.NET.MY): MAXIS COMMUNICATIONS BHD, MY.  | 
      n/a | CZ:qtas.net | 445 | pcap | raw alerts ruleset  | 
      http 1 line  | 
      Yeah : 0.8 profile  | 
      none | summary tarball  | 
      12 of 41 | 2a27386964 NEW  | 
      af2777b025 [0] | none:none | 
      FASM| | none | trace | 
| T:10:09:00 | Win2K-f |    4.167.92.209 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, US. (DIAL)  | 
      n/a | 135 | pcap | raw alerts ruleset  | 
      other 28 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      5 of 41 | 3fe7912340 NEW  | 
      none [3] | none:none | 
      FASM| | none | trace | |
| T:10:11:00 | Win2K-f |  113.255.102.60 (-): .  | 
      n/a | 135 | pcap | raw alerts ruleset  | 
      other 11 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      none | none | none | none | none | none | none | |
| T:11:47:00 | WinXP |   87.116.205.58 (TNP.PL): BROADBAND_SERVICES, PL.  | 
      n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset  | 
      http 1 line  | 
      Yeah : 0.8 profile  | 
      none | summary tarball  | 
      32 of 32 | 5818023061 NEW  | 
      none [0] | ASM:Graph | 
      PolyEnE| | lines=68 | trace | 
| T:12:26:00 | Win2K-f |    4.233.127.63 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, LOS ANGELES, CALIFORNIA, US. (DIAL)  | 
      n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset  | 
      other 75 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      
      33 of 33 0 of 33  | 
      53bfe15e91 NEW a08f3b74a4 NEW  | 
      1473091351 [0] none [0]  | 
      ASM:Graph none:none  | 
      tElock| Armadillo|  | 
      lines=75 embedded dns lines=90  | 
      trace trace  | 
    
| T:12:43:00 | WinXP |    64.144.35.70 (LADDFINANCIAL.COM): DSL.NET INC, US. (DSL)  | 
      n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset  | 
      other 75 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      
      33 of 33 0 of 32  | 
      53bfe15e91 NEW 73f1082158 NEW  | 
      1473091351 [0] none [0]  | 
      ASM:Graph none:none  | 
      tElock| Armadillo|  | 
      lines=75 embedded dns lines=90  | 
      trace trace  | 
    
| T:12:44:00 | WinXP |   84.47.201.114 (-): PARSCYBERIAN CONSULTANTS, AE.  | 
      n/a | DE:siliconfireware.ru  US:searchportal.information.com US:spi.domainsponsor.com :vit.ln.ua GB:new.egg.com :wpad  | 
      445 | pcap | raw alerts ruleset  | 
      http http http 38 lines  | 
      Yeah : 0.8 profile  | 
      none | summary tarball  | 
      30 of 32 | 7dd1fe2970 NEW  | 
      none [0] | ASM:Graph | 
      ASPack| | lines=374 embedded dns  | 
      trace | 
| T:14:03:00 | WinXP |   85.174.24.246 (RUNEXT.COM): PROVIDER LOCAL REGISTRY, RU.  | 
      n/a | RU:citi-bank.ru RU:213.219.245.212:80  | 
      445 | pcap | raw alerts ruleset  | 
      http 1 line  | 
      Yeah : 0.8 profile  | 
      none | summary tarball  | 
      40 of 41 | aab1b56620 NEW  | 
      3b2e1c5b9d [0] | none:none | 
      PolyEnE| | none | trace | 
| T:14:36:00 | WinXP |    72.181.45.25 (RR.COM): ROAD RUNNER HOLDCO LLC, HOUSTON, TEXAS, US.  | 
      n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset  | 
      other 75 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      
      33 of 33 0 of 33  | 
      53bfe15e91 NEW a08f3b74a4 NEW  | 
      1473091351 [0] none [0]  | 
      ASM:Graph none:none  | 
      tElock| Armadillo|  | 
      lines=75 embedded dns lines=90  | 
      trace trace  | 
    
| T:14:43:00 | Win2K-f |      4.225.23.3 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, KOKOMO, INDIANA, US. (DIAL)  | 
      n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset  | 
      other 75 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      
      33 of 33 0 of 33  | 
      53bfe15e91 NEW a08f3b74a4 NEW  | 
      1473091351 [0] none [0]  | 
      ASM:Graph none:none  | 
      tElock| Armadillo|  | 
      lines=75 embedded dns lines=90  | 
      trace trace  | 
    
| T:14:50:00 | WinXP |   71.108.148.40 (VERIZON.NET): VERIZON INTERNET SERVICES INC, HUNTINGTON BEACH, CALIFORNIA, US. (DSL)  | 
      n/a | 445 | pcap | raw alerts ruleset  | 
      shell ftp 15 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      40 of 41 | 9fe0ab64c0 NEW  | 
      60b46aa7dd [0] | none:none | 
      none|none | none | trace | |
| T:14:56:00 | WinXP |    75.49.12.225 (SBCGLOBAL.NET): PPPOX POOL - SE1.WOTNOH 101906-1259, COLUMBUS, OHIO, US. (DSL)  | 
      n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset  | 
      other 76 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      
      33 of 33 0 of 33  | 
      53bfe15e91 NEW a08f3b74a4 NEW  | 
      1473091351 [0] none [0]  | 
      ASM:Graph none:none  | 
      tElock| Armadillo|  | 
      lines=75 embedded dns lines=90  | 
      trace trace  | 
    
| T:15:37:00 | WinXP |   64.203.49.113 (MINDSPRING.COM): EARTHLINK INC, SAN DIEGO, CALIFORNIA, US. (DSL)  | 
      n/a | EU:siliconfireware.ru  US:searchportal.information.com US:spi.domainsponsor.com :wpad US:splegacy.information.com RU:www.bbin.ru RU:www.binbank.ru  | 
      445 | pcap | raw alerts ruleset  | 
      http http http http 49 lines  | 
      Yeah : 0.8 profile  | 
      none | summary tarball  | 
      29 of 29 | df17a625ee NEW  | 
      none [0] | none:none | 
      ASPack| | lines=298 embedded dns  | 
      trace | 
| T:19:08:00 | WinXP |    189.97.58.27 (-): .  | 
      213.219.245.212:80 | RU:citi-bank.ru RU:213.219.245.212:80  | 
      445 | pcap | raw alerts ruleset  | 
      http 3 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      40 of 41 | eda3b7766c NEW  | 
      7556343561 [0] | none:none | 
      PolyEnE| | none | trace | 
| T:19:14:00 | Win2K-f |   208.79.59.198 (GROUPTELECOM.NET): 3757277 CANADA INC. (OA 295.CA), KITCHENER, ONTARIO, CA.  | 
      n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset  | 
      other 160 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      
      33 of 33 8 of 33  | 
      53bfe15e91 NEW b7082104e4 NEW  | 
      1473091351 [0] c5b49e7b82[0] c5b49e7b82[0]  | 
      ASM:Graph ASM:Graph  | 
      tElock| tElock|  | 
      lines=75 embedded dns lines=41  | 
      trace trace  | 
    
| T:19:55:00 | Win2K-f |   174.6.206.210 (-): .  | 
      n/a | 135 | pcap | raw alerts ruleset  | 
      other 18 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      none | none | none | none | none | none | none | |
| T:20:11:00 | Win2K-f |   70.184.219.41 (COX.NET): COX COMMUNICATIONS, OMAHA, NEBRASKA, US.  | 
      n/a | 135 | pcap | raw alerts ruleset  | 
      other 1008 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      32 of 41 | a34194ff12 NEW  | 
      none [3] | none:none | 
      none|none | none | trace | |
| T:20:38:00 | WinXP |   68.124.62.159 (PACBELL.NET): PPPOX POOL - BRAS1 IRVNCA, LOS ANGELES, CALIFORNIA, US. (DSL)  | 
      213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset  | 
      http 2 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      29 of 29 | d6df3972a0 NEW  | 
      none [0] | ASM:Graph | 
      PolyEnE| | lines=65 | trace | 
| T:21:16:00 | WinXP |    61.62.45.220 (SO-NET.NET.TW): SONY NETWORK TAIWAN LIMITED, TAIPEI, T'AI-PEI, TW. (DSL)  | 
      213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset  | 
      http 2 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      40 of 41 | eda3b7766c NEW  | 
      7556343561 [0] | none:none | 
      PolyEnE| | none | trace | 
| T:21:58:00 | WinXP |    110.12.67.17 (-): .  | 
      218.93.205.30:65520 | CN:proxim.ircgalaxy.pl  US:microsoft.com  | 
      135 | pcap | raw alerts ruleset  | 
      irc 139 lines  | 
      Yeah : 1.8 profile  | 
      none | summary tarball  | 
      
      37 of 41 38 of 41  | 
      598636aa73 NEW a57ddcdef0 NEW  | 
      613af3f9a2 [0] none [4]  | 
      none:none none:none  | 
      Armadillo| PolyEnE|  | 
      none none  | 
      trace trace  | 
    
| T:22:11:00 | WinXP |   122.146.83.69 (SPARQNET.NET): NEW CENTURY INFOCOMM TECH. CO. LTD, TW.  | 
      n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset  | 
      other 77 lines  | 
      Yeah : 1.3 profile  | 
      none | summary tarball  | 
      
      33 of 33 0 of 32  | 
      53bfe15e91 NEW 73f1082158 NEW  | 
      1473091351 [0] none [0]  | 
      ASM:Graph none:none  | 
      tElock| Armadillo|  | 
      lines=75 embedded dns lines=90  | 
      trace trace  |