Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:35:00 | WinXP | 62.1.12.1 (ACCI.GR): ATHENS CHAMBER OF COMMERCE AND INDUSTRY, ATHENS, ATTIKI, GR. |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | 96c5f931fe NEW |
none[4] | none:none |
PolyEnE| | none | trace | |
06:34:00 | WinXP | 85.24.168.201 (BAHNHOF.SE): BAHNHOF INTERNET AB, SE. |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c [Firefox:1311 hits: 12-31 to 06-02] |
1aad8e4632 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
T:06:39:00 | Win2K-f | 211.108.170.122 (-): YEUNGJIN JUNIOR COLLEGE, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:07:18:00 | WinXP | 190.3.85.76 (TECHTELNET.NET): TECHTEL LMDS COMUNICACIONES INTERACTIVAS S.A, AR. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp irc 25 lines |
Yeah : 0.8 profile |
none | summary tarball |
15 of 31 | 6c4c3242ba [Firefox: 6 hits: 05-31 to 06-03] |
47300e90ee [0] | none:none |
none|none | none | trace |
07:25:00 | WinXP | 82.66.222.30 (PROXAD.NET): PROXAD / FREE SAS, PARIS, ILE-DE-FRANCE, FR. |
n/a | RU:moscow-advokat.ru RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | b9d4312d9a NEW |
none[none] | none:none |
none|none | none | none |
T:07:41:00 | WinXP | 86.155.16.101 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, SWANSEA, WALES, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:617 hits: 07-11 to 06-03] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
08:27:00 | WinXP | 61.59.235.128 (SEED.NET.TW): DIGITAL UNITED INC, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 [Firefox:401 hits: 12-31 to 06-03] |
048df78048 [0] | ASM:Graph |
none|none | lines=61 | trace | |
10:13:00 | WinXP | 96.51.5.172 (-): . |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | d42c1cc7c0 [Firefox:281 hits: 05-01 to 06-03] |
af9ca5bed1 [0] | ASM:Graph |
PolyEnE| | lines=54 | trace |
T:10:36:00 | WinXP | 85.152.149.156 (CM-85-152-150-10.TELECABLE.ES): TELECABLE, GIJON, ASTURIAS, ES. (DSL) |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 042774a2b7 [Firefox:139 hits: 05-01 to 06-03] |
1c9a472cd7 [0] | ASM:Graph |
PolyEnE| | lines=71 embedded dns |
trace |
T:10:52:00 | WinXP | 212.45.81.134 (-): ISTAR LINK CUSTOMERS IN RADNEVO, KAZANLAK, STARA ZAGORA, BG. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp irc 23 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:56 hits: 05-29 to 06-03] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
T:13:24:00 | WinXP | 92.112.186.234 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | CN:hail2.dns2go.com | 445 | pcap | raw alerts ruleset |
ftp irc 24 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:56 hits: 05-29 to 06-03] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
T:13:58:00 | WinXP | 68.119.207.69 (CHARTER.COM): CHARTER COMMUNICATIONS, GREENVILLE, SOUTH CAROLINA, US. |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 32a0d7d0e0 [Firefox:42 hits: 05-04 to 06-01] |
d791762796 [0] | ASM:Graph |
tElock| | lines=81 embedded dns |
trace |
T:14:15:00 | WinXP | 170.51.110.166 (COM.AR): CTI COMPANIA DE TELEFONAS DEL INTERIOR S.A, AR. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3021 hits: 12-31 to 06-03] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
15:10:00 | Win2K-f | 92.112.186.234 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | CN:hail2.dns2go.com | 445 | pcap | raw alerts ruleset |
ftp 21 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:56 hits: 05-29 to 06-03] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
T:17:43:00 | WinXP | 66.75.89.162 (RR.COM): ROAD RUNNER HOLDCO LLC, RESEDA, CALIFORNIA, US. |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 55fe9d9ade [Firefox:49 hits: 05-03 to 05-31] |
4bce6c4887 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
T:19:47:00 | WinXP | 222.234.180.117 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:21:03:00 | WinXP | 74.69.172.227 (RR.COM): ROAD RUNNER HOLDCO LLC, HORSEHEADS, NEW YORK, US. |
n/a | EU:siliconfireware.ru :www.proxy-socks.net :wpad GB:welcome3.smile.co.uk GB:195.92.84.198:80 DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef [Firefox:1033 hits: 05-01 to 06-03] |
40f7f463c4 [0] | ASM:Graph |
ASPack| | lines=281 embedded dns |
trace |
21:40:00 | Win2K-f | 190.139.144.29 (NET.AR): TELECOM ARGENTINA S.A, AR. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:56 hits: 05-29 to 06-03] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
T:21:41:00 | WinXP | 75.137.158.144 (CHARTER.COM): CHARTER COMMUNICATIONS, CARROLLTON, GEORGIA, US. |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c [Firefox:1311 hits: 12-31 to 06-02] |
1aad8e4632 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
T:21:41:00 | Win2K-f | 64.181.117.26 (AUSTINCPAAC.COM): FIBERNET OF WEST VIRGINIA, CHARLESTON, WEST VIRGINIA, US. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
21:41:00 | WinXP | 75.137.158.144 (CHARTER.COM): CHARTER COMMUNICATIONS, CARROLLTON, GEORGIA, US. |
n/a | RU:moscow-advokat.ru RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c [Firefox:1311 hits: 12-31 to 06-02] |
1aad8e4632 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
T:22:08:00 | Win2K-f | 121.125.216.170 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
22:30:00 | WinXP | 69.41.138.236 (SEISMICINTERNET.NET): SEISMIC ENTERPRISES, KAILUA KONA, HAWAII, US. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 33 | bce12aa21f [Firefox:13 hits: 05-12 to 06-03] |
none[4] | none:none |
PolyEnE| | none | trace |
23:45:00 | WinXP | 116.206.63.199 (-): MOBIF WIRELESS BROADBAND SDN. BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp irc 23 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:56 hits: 05-29 to 06-03] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |