Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:59:00 | Win2K-f | 78.96.76.190 (ASTRAL.RO): ASTRAL TELECOM SA, RO. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp irc 24 lines |
Yeah : 0.8 profile |
none | summary tarball |
15 of 31 | 6c4c3242ba [Firefox: 5 hits: 05-31 to 06-02] |
47300e90ee [0] | none:none |
none|none | none | trace |
01:12:00 | Win2K-f | 89.117.77.137 (ERDVES.LT): SC LITHUANIAN RADIO AND TV CENTER, VILNIUS, VILNIAUS APSKRITIS, LT. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
22 of 32 | 9a8996e51e NEW |
none[none] | none:none |
none|none | none | none |
01:41:00 | Win2K-f | 83.8.107.46 (TPNET.PL): NEOSTRADA PLUS, PL. |
n/a | US:qtas.net SE:scl.jullope.com SE:84.244.5.183:2345 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 33 | 1c8163ae44 NEW |
none[none] | none:none |
none|none | none | none |
02:38:00 | Win2K-f | 41.203.225.227 (-): . |
85.114.137.60:65520 | DE:proxim.ircgalaxy.pl CN:hail2.dns2go.com CN:222.177.11.165:8885 DE:85.114.137.60:65520 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
28 of 32 | dc0b7d619d NEW |
none[none] | none:none |
none|none | none | none |
02:46:00 | WinXP | 218.173.176.150 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
30 of 32 | 23c6886399 NEW |
none[none] | none:none |
none|none | none | none |
T:02:48:00 | Win2K-f | 24.185.110.88 (OPTONLINE.NET): OPTIMUM ONLINE (CABLEVISION SYSTEMS), BROOKLYN, NEW YORK, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:02:48:00 | WinXP | 218.173.176.150 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
30 of 32 | 23c6886399 NEW |
none[none] | none:none |
none|none | none | none |
T:02:50:00 | WinXP | 79.132.202.253 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | EU:siliconfireware.ru UA:vit.ln.ua :baner.vit :www.proxy-socks.net :wpad DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http 22 lines |
Yeah : 0.8 profile |
none | summary tarball |
30 of 32 | 7dd1fe2970 [Firefox:19 hits: 09-07 to 04-01] |
dcc673c815 [0] | ASM:Graph |
ASPack| | lines=374 embedded dns |
trace |
02:50:00 | Win2K-f | 92.46.6.17 (IKBCC.COM): EU-ZZ, UK. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:51 hits: 05-29 to 06-02] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
04:16:00 | WinXP | 87.61.171.12 (IP.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, DK. |
n/a | DE:siliconfireware.ru :wpad DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee [Firefox:453 hits: 05-04 to 06-02] |
9bbdd086c5 [0] | none:none |
ASPack| | none | trace |
T:04:42:00 | WinXP | 91.142.20.64 (KABELSPEED.AT): KABELSPEED, AT. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
28 of 32 | 7cafcda796 NEW |
none[none] | none:none |
none|none | none | none |
06:38:00 | WinXP | 86.155.86.208 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, SWANSEA, WALES, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:616 hits: 07-11 to 06-01] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
T:06:50:00 | WinXP | 222.236.119.144 (HANANET.NET): HANARO TELECOM INC, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 94 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
07:04:00 | Win2K-f | 79.185.194.231 (TPNET.PL): TPSA, PL. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
12 of 32 | 2b3773ee10 NEW |
none[none] | none:none |
none|none | none | none |
T:07:38:00 | WinXP | 86.7.142.217 (NTL.COM): NTL INFRASTRUCTURE - BROMLEY, LONDON, ENGLAND, UK. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a0139d7ad8 [Firefox:438 hits: 05-02 to 06-01] |
d9e9662db1 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace | |
T:09:01:00 | WinXP | 92.40.61.67 (IKBCC.COM): EU-ZZ, UK. |
85.114.137.60:80 | DE:proxim.ircgalaxy.pl UA:citi-bank.ru UA:194.54.90.246:80 DE:85.114.137.60:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 6f1691e3b3 NEW |
none[none] | none:none |
none|none | none | none |
T:09:12:00 | Win2K-f | 79.140.12.128 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:51 hits: 05-29 to 06-02] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
T:09:44:00 | Win2K-f | 92.47.253.174 (IKBCC.COM): EU-ZZ, UK. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
28 of 32 | 6acb8a7a56 NEW |
none[none] | none:none |
none|none | none | none | |
T:09:54:00 | Win2K-f | 87.70.56.143 (012.NET.IL): GOLDEN LINES INTERNATIONAL COMMUNICATION SERVICES LTD, IL. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 17 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:10:19:00 | WinXP | 201.74.162.191 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3018 hits: 12-31 to 06-01] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
10:37:00 | WinXP | 216.255.167.30 (TVCCONNECT.NET): THAMES VALLEY COMMUNICATIONS INC, GROTON, CONNECTICUT, US. |
n/a | DE:siliconfireware.ru EU:ebookfinaltrash.ru :wpad DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef [Firefox:1032 hits: 05-01 to 06-02] |
40f7f463c4 [0] | ASM:Graph |
ASPack| | lines=281 embedded dns |
trace |
T:11:17:00 | WinXP | 92.40.30.209 (IKBCC.COM): EU-ZZ, UK. |
85.114.137.60:80 | DE:proxim.ircgalaxy.pl DE:85.114.137.60:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
28 of 31 | f58222344f [Firefox:11 hits: 12-31 to 05-21] |
2a56436a64 [0] | ASM:Graph |
PolyEnE| | lines=265 embedded dns |
trace |
T:11:28:00 | WinXP | 66.50.89.40 (PRTC.NET): PUERTO RICO TELEPHONE COMPANY, SAN JUAN, PUERTO RICO, PR. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3018 hits: 12-31 to 06-01] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:11:28:00 | Win2K-f | 89.174.123.250 (IPARTNERS.PL): GTS POLSKA SP. Z O.O, KRAKOW, MALOPOLSKIE, PL. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:51 hits: 05-29 to 06-02] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
11:40:00 | Win2K-f | 189.54.9.168 (BRASILTELECOM.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:51 hits: 05-29 to 06-02] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
T:11:49:00 | WinXP | 83.93.179.220 (ADSL-DHCP.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, DK. (DSL) |
85.114.137.60:80 | DE:proxim.ircgalaxy.pl UA:citi-bank.ru UA:194.54.90.246:80 DE:85.114.137.60:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
30 of 32 | 2a0cd9d140 NEW |
none[none] | none:none |
none|none | none | none |
T:12:41:00 | Win2K-f | 78.54.135.136 (ALICEDSL.DE): HANSENET TELEKOMMUNIKATION GMBH, HAMBURG, HAMBURG, DE. (DSL) |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:51 hits: 05-29 to 06-02] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
T:13:09:00 | WinXP | 85.152.149.163 (CM-85-152-150-10.TELECABLE.ES): TELECABLE, GIJON, ASTURIAS, ES. (DSL) |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 042774a2b7 [Firefox:137 hits: 05-01 to 05-09] |
1c9a472cd7 [0] | ASM:Graph |
PolyEnE| | lines=71 embedded dns |
trace |
13:10:00 | WinXP | 190.188.72.215 (NET.AR): PRIMA S.A, AR. |
85.114.137.60:65520 | DE:proxim.ircgalaxy.pl UA:citi-bank.ru UA:194.54.90.246:80 DE:85.114.137.60:65520 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 028454d36b NEW |
none[none] | none:none |
none|none | none | none |
13:10:00 | WinXP | 194.65.179.86 (DIAL-B1-178-10.TELEPAC.PT): TELEPAC - COMUNICACOES INTERACTIVAS SA, PORTO, PORTO, PT. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 [Firefox:399 hits: 12-31 to 06-01] |
048df78048 [0] | ASM:Graph |
none|none | lines=61 | trace | |
13:10:00 | WinXP | 85.152.149.163 (CM-85-152-150-10.TELECABLE.ES): TELECABLE, GIJON, ASTURIAS, ES. (DSL) |
n/a | RU:moscow-advokat.ru US:lia.zanet.net :irc.kar.net :gaspode.zanet.org.za :caen.fr.eu.undernet.org :washington.dc.us.undernet.org RU:irc.tsk.ru NO:london.uk.eu.undernet.org RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 042774a2b7 [Firefox:137 hits: 05-01 to 05-09] |
1c9a472cd7 [0] | ASM:Graph |
PolyEnE| | lines=71 embedded dns |
trace |
15:49:00 | WinXP | 24.162.133.232 (RR.COM): ROAD RUNNER HOLDCO LLC, WACO, TEXAS, US. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 [Firefox:399 hits: 12-31 to 06-01] |
048df78048 [0] | ASM:Graph |
none|none | lines=61 | trace | |
T:15:51:00 | WinXP | 69.134.103.153 (RR.COM): ROAD RUNNER HOLDCO LLC, CONCORD, NORTH CAROLINA, US. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3018 hits: 12-31 to 06-01] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:18:37:00 | WinXP | 190.137.123.33 (NET.AR): TELECOM ARGENTINA S.A, AR. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 33 | bce12aa21f [Firefox:12 hits: 05-12 to 06-01] |
none[4] | none:none |
PolyEnE| | none | trace |
19:25:00 | WinXP | 92.40.43.229 (IKBCC.COM): EU-ZZ, UK. |
85.114.137.60:80 | DE:proxim.ircgalaxy.pl DE:85.114.137.60:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
27 of 32 | 9c037c69f6 [Firefox: 2 hits: 04-21 to 04-26] |
none[3] | none:none |
ASPack| | none | trace |
T:19:57:00 | WinXP | 64.48.134.40 (ALGX.NET): XO COMMUNICATIONS, CLEVELAND, OHIO, US. |
n/a | US:www.yahoo.com US:www.altavista.com :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 17028f1eda [Firefox: 4 hits: 09-29 to 04-18] |
none[3] | none:none |
tElock| | none | trace |
T:20:24:00 | WinXP | 24.70.131.49 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:20:51:00 | WinXP | 98.140.251.237 (-): . |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | d42c1cc7c0 [Firefox:279 hits: 05-01 to 05-31] |
af9ca5bed1 [0] | ASM:Graph |
PolyEnE| | lines=54 | trace |
20:55:00 | WinXP | 98.140.251.237 (-): . |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | d42c1cc7c0 [Firefox:279 hits: 05-01 to 05-31] |
af9ca5bed1 [0] | ASM:Graph |
PolyEnE| | lines=54 | trace |
20:57:00 | WinXP | 4.226.0.125 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DESOTO, TEXAS, US. (DIAL) |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 3ae357d17b [Firefox:712 hits: 05-01 to 05-30] |
462a7be171 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:23:39:00 | Win2K-f | 89.117.77.137 (ERDVES.LT): SC LITHUANIAN RADIO AND TV CENTER, VILNIUS, VILNIAUS APSKRITIS, LT. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
22 of 32 | 9a8996e51e NEW |
none[none] | none:none |
none|none | none | none |