Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:21:00 | WinXP | 80.191.186.131 (-): AREA NO 1-5 PARTITION, TEHRAN, TEHRAN, IR. (100Mbps) |
n/a | 445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
01:16:00 | WinXP | 122.2.152.92 (PLDT.NET): IPG, PH. |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | d42c1cc7c0 [Firefox:282 hits: 05-01 to 06-04] |
af9ca5bed1 [0] | ASM:Graph |
PolyEnE| | lines=54 | trace | |
T:01:16:00 | WinXP | 122.2.152.92 (PLDT.NET): IPG, PH. |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | d42c1cc7c0 [Firefox:282 hits: 05-01 to 06-04] |
af9ca5bed1 [0] | ASM:Graph |
PolyEnE| | lines=54 | trace | |
T:01:17:00 | WinXP | 4.242.108.114 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, CENTRAL POINT, OREGON, US. (DIAL) |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 32 | 677536d92f NEW |
none[none] | none:none |
none|none | none | none |
04:09:00 | WinXP | 77.197.201.180 (GAOLAND.NET): DYNAMIC POOLS, FR. |
n/a | DE:siliconfireware.ru GB:welcome3.smile.co.uk :wpad GB:195.92.84.198:80 DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef [Firefox:1034 hits: 05-01 to 06-04] |
40f7f463c4 [0] | ASM:Graph |
ASPack| | lines=281 embedded dns |
trace |
04:41:00 | Win2K-f | 91.142.20.64 (KABELSPEED.AT): KABELSPEED, AT. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
28 of 32 | 7cafcda796 NEW |
none[none] | none:none |
none|none | none | none |
T:04:51:00 | WinXP | 222.5.234.231 (DION.NE.JP): DION (KDDI CORPORATION), JP. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 [Firefox:402 hits: 12-31 to 06-04] |
048df78048 [0] | ASM:Graph |
none|none | lines=61 | trace | |
05:36:00 | Win2K-f | 122.52.21.57 (PLDT.NET): IPG, PH. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
15 of 31 | 6c4c3242ba [Firefox: 7 hits: 05-31 to 06-04] |
47300e90ee [0] | none:none |
none|none | none | trace |
06:33:00 | WinXP | 41.214.174.30 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:06:34:00 | WinXP | 41.214.174.30 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:08:09:00 | WinXP | 62.215.53.122 (-): FAST TELCO INFRA STRUCTURE WEB ACCESS USERS, KUWAIT, AL KUWAYT, KW. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
30 of 32 | a636f5ce05 NEW |
none[none] | none:none |
none|none | none | none |
T:12:36:00 | Win2K-f | 92.112.181.123 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:61 hits: 05-29 to 06-04] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
12:52:00 | WinXP | 210.139.205.56 (SO-NET.NE.JP): SO-NET ENTERTAINMENT CORPORATION, JP. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3022 hits: 12-31 to 06-04] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:14:34:00 | Win2K-f | 89.124.86.12 (IRISHBROADBAND.IE): ESB ORANMORE CUSTOMER EXPANSION, IE. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
15 of 31 | 6c4c3242ba [Firefox: 7 hits: 05-31 to 06-04] |
47300e90ee [0] | none:none |
none|none | none | trace |
16:08:00 | WinXP | 78.49.37.47 (ALICEDSL.DE): HANSENET TELEKOMMUNIKATION GMBH, HAMBURG, HAMBURG, DE. (DSL) |
217.170.244.2:443 | 445 | pcap | raw alerts ruleset |
shell ftp irc 29 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2633 hits: 12-31 to 05-19] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace | |
16:16:00 | WinXP | 170.51.111.236 (COM.AR): CTI COMPANIA DE TELEFONAS DEL INTERIOR S.A, AR. |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c [Firefox:1314 hits: 12-31 to 06-04] |
1aad8e4632 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
T:17:08:00 | Win2K-f | 4.243.53.79 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, SEATTLE, WASHINGTON, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell 11 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
17:14:00 | WinXP | 207.177.46.246 (WCCTA.NET): WEBSTER CALHOUN TELEPHONE CO, FT. DODGE, IOWA, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:20:02:00 | Win2K-f | 96.15.86.221 (-): . |
217.170.244.2:443 | 445 | pcap | raw alerts ruleset |
shell ftp irc 28 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2633 hits: 12-31 to 05-19] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace | |
T:20:12:00 | Win2K-f | 219.255.214.101 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:20:43:00 | WinXP | 66.27.180.44 (RR.COM): ROAD RUNNER HOLDCO LLC, CANOGA PARK, CALIFORNIA, US. |
n/a | CZ:217.170.244.2:443 CZ:82.114.90.2:443 |
445 | pcap | raw alerts ruleset |
shell ftp 110 lines |
Yeah : 0.8 profile |
none | summary tarball |
16 of 31 | 23c32fbd78 [Firefox: 2 hits: 05-03 to 05-11] |
none[4] | none:none |
PeCompact| | none | trace |
21:13:00 | Win2K-f | 116.206.54.180 (-): MOBIF WIRELESS BROADBAND SDN. BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:61 hits: 05-29 to 06-04] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
22:33:00 | WinXP | 170.51.136.20 (COM.AR): CTI COMPANIA DE TELEFONAS DEL INTERIOR S.A, AR. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3022 hits: 12-31 to 06-04] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:23:58:00 | WinXP | 79.81.10.216 (G-M-I.NET): EU-ZZ, UK. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 20 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 32 | 5708dc9e50 NEW |
none[none] | none:none |
none|none | none | none |