Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:20:00 | WinXP | 41.233.227.118 (TEDATA.NET): PROVIDER LOCAL REGISTRY, EG. |
n/a | CN:hail2.dns2go.com US:209.63.232.19:8885 |
445 | pcap | raw alerts ruleset |
ftp irc 23 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:51 hits: 05-29 to 06-02] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
01:16:00 | WinXP | 79.138.208.158 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | CN:hail2.dns2go.com US:209.63.232.19:8885 |
445 | pcap | raw alerts ruleset |
ftp irc 22 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:51 hits: 05-29 to 06-02] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
01:59:00 | WinXP | 116.59.34.14 (-): MOBILE BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a0139d7ad8 [Firefox:438 hits: 05-02 to 06-01] |
d9e9662db1 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:03:38:00 | WinXP | 219.105.90.50 (ADACHI.NE.JP): CABLE TELEVISION ADACHI CORP, JP. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 31 | 03c8316704 NEW |
f8ba804137 [0] | none:none |
none|none | none | trace | |
04:09:00 | Win2K-f | 91.124.8.218 (UKRTEL.NET): UKRTELECOM, BROVARY, KYYIVS'KA OBLAST', UA. |
n/a | CN:hail2.dns2go.com US:209.63.232.19:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:51 hits: 05-29 to 06-02] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
04:23:00 | WinXP | 118.86.203.252 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
05:09:00 | Win2K-f | 201.19.87.234 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | CN:hail2.dns2go.com US:209.63.232.19:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:51 hits: 05-29 to 06-02] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
T:06:09:00 | Win2K-f | 89.214.185.221 (-): TMN - TELECOMUNICACOES MOVEIS NACIONAIS SA, PT. |
n/a | CN:hail2.dns2go.com US:209.63.232.19:8885 |
445 | pcap | raw alerts ruleset |
ftp 17 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:51 hits: 05-29 to 06-02] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
T:06:39:00 | Win2K-f | 96.13.246.127 (-): . |
n/a | US:www.blackirc.us US:64.131.76.60:80 |
445 | pcap | raw alerts ruleset |
http 9 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:06:40:00 | Win2K-f | 79.81.148.203 (G-M-I.NET): EU-ZZ, UK. |
n/a | US:qtas.net SE:dzuc.net SE:84.244.5.183:2345 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
8 of 31 | 859e6786f0 [Firefox: 2 hits: 05-30 to 05-31] |
859e6786f0 [1] | ASM:Graph |
StarForce| | lines=95 | trace |
T:07:42:00 | Win2K-f | 200.228.107.5 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | US:qtas.net SE:dzuc.net SE:84.244.5.183:2345 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 31 | f800daf83e [Firefox: 2 hits: 05-31 to 05-31] |
f800daf83e [1] | ASM:Graph |
StarForce| | lines=86 | trace |
08:25:00 | WinXP | 122.2.146.156 (PLDT.NET): IPG, PH. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | d42c1cc7c0 [Firefox:279 hits: 05-01 to 05-31] |
af9ca5bed1 [0] | ASM:Graph |
PolyEnE| | lines=54 | trace |
T:08:34:00 | Win2K-f | 85.135.142.97 (SLOVANET.SK): SLOVANET ADSL DATA POOL, BRATISLAVA, BRATISLAVSKY, SK. (DSL) |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
15 of 31 | 6c4c3242ba [Firefox: 5 hits: 05-31 to 06-02] |
47300e90ee [0] | none:none |
none|none | none | trace |
08:37:00 | WinXP | 60.52.99.161 (TM.NET.MY): TELEKOM MALAYSIA BERHAD, PUCHONG, SELANGOR, MY. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
15 of 31 | 6c4c3242ba [Firefox: 5 hits: 05-31 to 06-02] |
47300e90ee [0] | none:none |
none|none | none | trace |
08:51:00 | Win2K-f | 81.190.93.175 (MM.PL): MULTIMEDIA POLSKA S. A, GDYNIA, POMORSKIE, PL. |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:09:06:00 | Win2K-f | 170.51.102.21 (COM.AR): CTI COMPANIA DE TELEFONAS DEL INTERIOR S.A, AR. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
28 of 31 | 703730b32b [Firefox: 2 hits: 05-31 to 05-31] |
5e5af423e8 [0] | none:none |
Armadillo| | none | trace | |
T:09:24:00 | Win2K-f | 166.136.224.202 (MYVZW.COM): SERVICE PROVIDER CORPORATION, BEDMINSTER, NEW JERSEY, US. |
n/a | US:qtas.net SE:dzuc.net |
445 | pcap | raw alerts ruleset |
http irc 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 31 | f800daf83e [Firefox: 2 hits: 05-31 to 05-31] |
f800daf83e [1] | ASM:Graph |
StarForce| | lines=86 | trace |
09:56:00 | WinXP | 201.19.137.33 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:51 hits: 05-29 to 06-02] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
10:17:00 | WinXP | 60.53.245.255 (TM.NET.MY): TELEKOM MALAYSIA BERHAD, MALACCA, MELAKA, MY. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
4 of 31 | fcb2cd80a1 NEW |
none[3] | none:none |
Obsidium| | none | trace | |
T:10:27:00 | Win2K-f | 130.13.220.227 (QWEST.NET): QWEST BROADBAND SERVICES INC, PHOENIX, ARIZONA, US. |
64.32.28.8:1977 | FI:neo12.cjb.net | 135 | pcap | raw alerts ruleset |
irc 368 lines |
Yeah : 1.3 profile |
none | summary tarball |
5 of 31 | 0b6af9e88a [Firefox: 3 hits: 05-31 to 06-01] |
24b6fb10de [0] | none:none |
StarForce| | none | trace |
T:10:28:00 | Win2K-f | 82.253.105.70 (PROXAD.NET): PROXAD / FREE SAS, NICE, PROVENCE-ALPES-COTE D'AZUR, FR. (DSL) |
84.244.5.183:2345 | US:wow.blackirc.us SE:tap.radioprishtina.net |
445 | pcap | raw alerts ruleset |
http irc 37 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 31 | 0c6fc94f09 NEW |
0c6fc94f09 [1] | ASM:Graph |
StarForce| | lines=86 | trace |
10:42:00 | WinXP | 190.31.241.168 (NET.AR): APOLO -GOLD-TELECOM-PER, BUENOS AIRES, BUENOS AIRES, AR. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 19 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:51 hits: 05-29 to 06-02] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
T:11:10:00 | Win2K-f | 59.96.48.11 (10/24.BSNL.IN): NIB (NATIONAL INTERNET BACKBONE), BANGALORE, KARNATAKA, IN. |
84.244.6.253:2345 66.29.25.194:80 | US:www.blackirc.us SE:tap.tronko.net |
445 | pcap | raw alerts ruleset |
http irc 70 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 32 3 of 31 |
05ec072edf [Firefox: 4 hits: 05-30 to 06-01] 7287487211 [Firefox: 3 hits: 05-30 to 05-31] |
05ec072edf [1] 7287487211[1] |
ASM:Graph ASM:Graph |
StarForce| StarForce| |
lines=86 lines=86 |
trace trace |
T:12:05:00 | WinXP | 216.79.206.161 (BELLSOUTH.NET): BELLSOUTH.NET INC, SHREVEPORT, LOUISIANA, US. |
85.114.137.60:65520 | DE:proxim.ircgalaxy.pl UA:citi-bank.ru UA:194.54.90.246:80 DE:85.114.137.60:65520 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
30 of 31 | bcbabdf952 NEW |
none[4] | none:none |
PolyEnE| | none | trace |
T:12:06:00 | Win2K-f | 89.116.229.125 (ERDVES.LT): SC LITHUANIAN RADIO AND TV CENTER, VILNIUS, VILNIAUS APSKRITIS, LT. |
n/a | CN:hail2.dns2go.com | 445 | pcap | raw alerts ruleset |
ftp irc 22 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:51 hits: 05-29 to 06-02] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
T:12:15:00 | WinXP | 200.114.10.214 (INTERCABLE.NET.CO): TV CABLE PROMISION S.A, BUCARAMANGA, SANTANDER, CO. (DSL) |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3018 hits: 12-31 to 06-01] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:12:22:00 | WinXP | 200.127.190.248 (NET.AR): PRIMA S.A, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 31 | af0c4989ca [Firefox: 3 hits: 05-31 to 06-02] |
none[4] | none:none |
PolyEnE| | none | trace |
T:12:28:00 | WinXP | 98.140.130.18 (-): . |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 33 | bce12aa21f [Firefox:12 hits: 05-12 to 06-01] |
none[4] | none:none |
PolyEnE| | none | trace |
12:30:00 | WinXP | 66.75.88.141 (RR.COM): ROAD RUNNER HOLDCO LLC, RESEDA, CALIFORNIA, US. |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 55fe9d9ade [Firefox:49 hits: 05-03 to 05-31] |
4bce6c4887 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
12:49:00 | WinXP | 170.51.101.120 (COM.AR): CTI COMPANIA DE TELEFONAS DEL INTERIOR S.A, AR. |
85.114.137.60:65520 | DE:proxim.ircgalaxy.pl UA:citi-bank.ru UA:194.54.90.246:80 DE:85.114.137.60:65520 |
445 | pcap | raw alerts ruleset |
http irc 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 31 | ed6e30072f NEW |
none[4] | none:none |
PolyEnE| | none | trace |
T:13:48:00 | Win2K-f | 78.96.171.204 (ASTRAL.RO): ASTRAL TELECOM SA, RO. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:51 hits: 05-29 to 06-02] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
T:13:51:00 | Win2K-f | 170.51.166.127 (COM.AR): CTI COMPANIA DE TELEFONAS DEL INTERIOR S.A, AR. |
85.114.137.60:80 64.85.160.111:5001 | DE:proxim.ircgalaxy.pl US:cookie.roltf.ws DE:85.114.137.60:80 |
445 | pcap | raw alerts ruleset |
ftp irc 22 lines |
Yeah : 1.3 profile |
none | summary tarball |
28 of 31 | 703730b32b [Firefox: 2 hits: 05-31 to 05-31] |
5e5af423e8 [0] | none:none |
Armadillo| | none | trace |
13:53:00 | Win2K-f | 200.29.234.189 (-): . |
n/a | CN:hail2.dns2go.com | 445 | pcap | raw alerts ruleset |
ftp irc 24 lines |
Yeah : 0.8 profile |
none | summary tarball |
15 of 31 | 6c4c3242ba [Firefox: 5 hits: 05-31 to 06-02] |
47300e90ee [0] | none:none |
none|none | none | trace |
14:00:00 | WinXP | 86.7.169.209 (NTL.COM): NTL INFRASTRUCTURE - BROMLEY, WARRINGTON, ENGLAND, UK. (DSL) |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | dd02947289 [Firefox:10 hits: 05-09 to 05-31] |
62b3e97bda [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:14:07:00 | WinXP | 91.124.77.77 (UKRTEL.NET): UKRTELECOM, BROVARY, KYYIVS'KA OBLAST', UA. |
n/a | CN:hail2.dns2go.com | 445 | pcap | raw alerts ruleset |
ftp irc 26 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:51 hits: 05-29 to 06-02] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
14:33:00 | WinXP | 122.18.136.81 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:616 hits: 07-11 to 06-01] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
15:30:00 | Win2K-f | 82.236.37.172 (PROXAD.NET): PROXAD / FREE SAS, NICE, PROVENCE-ALPES-COTE D'AZUR, FR. |
213.239.192.125:5001 | DE:cookie.roltf.ws US:64.85.160.111:5001 |
445 | pcap | raw alerts ruleset |
ftp irc 21 lines |
Yeah : 1.3 profile |
none | summary tarball |
19 of 32 | 382279b44f [Firefox: 7 hits: 05-22 to 06-01] |
049e62d55b [0] | none:none |
Armadillo| | none | trace |
T:17:13:00 | Win2K-f | 88.160.61.162 (PROXAD.NET): PROXAD / FREE SAS, FR. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:51 hits: 05-29 to 06-02] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
17:30:00 | Win2K-f | 190.31.174.248 (NET.AR): APOLO -GOLD-TELECOM-PER, BUENOS AIRES, BUENOS AIRES, AR. |
n/a | CN:hail2.dns2go.com | 445 | pcap | raw alerts ruleset |
ftp irc 22 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:51 hits: 05-29 to 06-02] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
17:39:00 | Win2K-f | 220.131.229.66 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAINAN, KAO-HSIUNG, TW. |
222.177.11.165:8885 | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp irc 23 lines |
Yeah : 1.3 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:51 hits: 05-29 to 06-02] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
19:21:00 | WinXP | 121.102.134.60 (HI-HO.NE.JP): PANASONIC NETWORK SERVICES INC, JP. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:616 hits: 07-11 to 06-01] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
T:19:22:00 | Win2K-f | 190.31.174.248 (NET.AR): APOLO -GOLD-TELECOM-PER, BUENOS AIRES, BUENOS AIRES, AR. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp irc 26 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:51 hits: 05-29 to 06-02] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
21:41:00 | WinXP | 62.11.157.65 (DIALUP.TISCALI.IT): TISCALI ITALIA SPA, CAGLIARI, SARDEGNA, IT. (DIAL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com :www.proxy-socks.net :wpad US:208.73.212.12:80 DE:217.11.54.126:80 |
445 | pcap | raw alerts ruleset |
http http http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee [Firefox:453 hits: 05-04 to 06-02] |
9bbdd086c5 [0] | none:none |
ASPack| | none | trace |
T:22:14:00 | Win2K-f | 85.179.248.78 (ALICEDSL.DE): HANSENET-ADSL, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
19 of 32 | 382279b44f [Firefox: 7 hits: 05-22 to 06-01] |
049e62d55b [0] | none:none |
Armadillo| | none | trace | |
T:23:36:00 | Win2K-f | 78.60.172.115 (ZEBRA.LT): LIETUVOS, LT. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:51 hits: 05-29 to 06-02] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
23:39:00 | Win2K-f | 78.62.109.132 (ZEBRA.LT): LIETUVOS, LT. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:51 hits: 05-29 to 06-02] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |