Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:52:00 | WinXP | 80.199.162.184 (ADSL-DHCP.TELE.DK): TELEDANMARK, COPENHAGEN, COPENHAGEN, DK. (DSL) |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 33 | bce12aa21f [Firefox:14 hits: 05-12 to 06-04] |
none[4] | none:none |
PolyEnE| | none | trace |
04:09:00 | WinXP | 219.105.120.187 (ADACHI.NE.JP): CABLE TELEVISION ADACHI CORP, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 32 | dd5b183a77 NEW |
none[4] | none:none |
none|none | none | trace | |
05:12:00 | WinXP | 82.207.47.124 (UKRTEL.NET): UKRTELECOM IP ACCESS NETWORK, UA. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 986b59708d [Firefox:291 hits: 05-03 to 06-08] |
8a00217866 [0] | ASM:Graph |
PolyEnE| | lines=57 | trace |
05:59:00 | WinXP | 61.207.160.149 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:629 hits: 07-11 to 06-08] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
T:07:08:00 | WinXP | 79.75.71.26 (AS9105.COM): TELINCO, UK. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 986b59708d [Firefox:291 hits: 05-03 to 06-08] |
8a00217866 [0] | ASM:Graph |
PolyEnE| | lines=57 | trace |
07:53:00 | WinXP | 74.141.72.198 (INSIGHTBB.COM): INSIGHT COMMUNICATIONS COMPANY L.P, LOUISVILLE, KENTUCKY, US. |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c [Firefox:1317 hits: 12-31 to 06-07] |
1aad8e4632 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
T:08:10:00 | WinXP | 74.141.72.198 (INSIGHTBB.COM): INSIGHT COMMUNICATIONS COMPANY L.P, LOUISVILLE, KENTUCKY, US. |
n/a | RU:moscow-advokat.ru RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c [Firefox:1317 hits: 12-31 to 06-07] |
1aad8e4632 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
T:08:17:00 | WinXP | 122.147.96.8 (SPARQNET.NET): NEW CENTURY INFOCOMM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | 135 | pcap | raw alerts ruleset |
other 89 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
08:34:00 | WinXP | 79.75.112.168 (AS9105.COM): TELINCO, UK. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 986b59708d [Firefox:291 hits: 05-03 to 06-08] |
8a00217866 [0] | ASM:Graph |
PolyEnE| | lines=57 | trace |
T:09:13:00 | WinXP | 202.123.10.238 (P10-10.INTNET.MU): NATIONAL ISP, QUATRE BORNES, PLAINES WILHEMS, MU. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | d42c1cc7c0 [Firefox:286 hits: 05-01 to 06-08] |
af9ca5bed1 [0] | ASM:Graph |
PolyEnE| | lines=54 | trace |
09:20:00 | WinXP | 81.154.188.232 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, UK. |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 32 | a482c5c718 NEW |
none[4] | none:none |
PolyEnE| | none | trace |
T:10:12:00 | WinXP | 4.228.123.105 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, AURORA, COLORADO, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
10:20:00 | WinXP | 93.120.128.81 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | RU:moscow-advokat.ru RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c [Firefox:1317 hits: 12-31 to 06-07] |
1aad8e4632 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
T:10:20:00 | WinXP | 93.120.128.81 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | RU:moscow-advokat.ru RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c [Firefox:1317 hits: 12-31 to 06-07] |
1aad8e4632 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
T:11:23:00 | WinXP | 79.138.180.49 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | a92e3f8fc8 [Firefox:114 hits: 05-03 to 05-30] |
dfe02a1e52 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
11:49:00 | WinXP | 12.203.116.140 (MCHSI.COM): AT&T WORLDNET SERVICES, SPRINGFIELD, ILLINOIS, US. |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 986b59708d [Firefox:291 hits: 05-03 to 06-08] |
8a00217866 [0] | ASM:Graph |
PolyEnE| | lines=57 | trace |
T:12:40:00 | WinXP | 4.228.123.105 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, AURORA, COLORADO, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:00:00 | WinXP | 78.130.93.183 (REV.OPTIMUS.PT): OPTIMUS TELECOMUNICAGUES S.A, PT. |
194.54.90.246:80 | :proxim.ircgalaxy.pl UA:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 32 | 4e05133c5e NEW |
none[4] | none:none |
PolyEnE| | none | trace |
13:26:00 | WinXP | 208.83.217.222 (-): . |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 986b59708d [Firefox:291 hits: 05-03 to 06-08] |
8a00217866 [0] | ASM:Graph |
PolyEnE| | lines=57 | trace |
13:32:00 | WinXP | 66.50.89.25 (PRTC.NET): PUERTO RICO TELEPHONE COMPANY, SAN JUAN, PUERTO RICO, PR. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3038 hits: 12-31 to 06-08] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:13:38:00 | WinXP | 87.253.196.155 (VOLOGDA.RU): OJSC NORTH-WEST TELECOM BRANCH ELECTROSVYAS OF VOLOGDA REGION, RU. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3038 hits: 12-31 to 06-08] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:13:47:00 | WinXP | 64.139.104.242 (RCABLETV.COM): NCI DATA.COM INC, REPUBLIC, WASHINGTON, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 93 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:14:20:00 | WinXP | 70.60.4.218 (RR.COM): ROAD RUNNER HOLDCO LLC, COLUMBUS, OHIO, US. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 1e5df7ba74 [Firefox:21 hits: 03-24 to 06-01] |
a5331b711f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:14:32:00 | Win2K-f | 24.234.201.231 (COX.NET): COX COMMUNICATIONS INC, LAS VEGAS, NEVADA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
15:52:00 | WinXP | 72.174.65.227 (BRESNAN.NET): BRESNAN COMMUNICATIONS LLC, PURCHASE, NEW YORK, US. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | f2668b51f1 [Firefox: 5 hits: 08-10 to 01-04] |
none[4] | none:none |
PolyEnE| | none | trace |
T:16:04:00 | Win2K-f | 71.98.81.62 (VERIZON.NET): VERIZON INTERNET SERVICES INC, LAFAYETTE, INDIANA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:17:07:00 | WinXP | 24.84.196.153 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SURREY, BRITISH COLUMBIA, CA. (DSL) |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 32a0d7d0e0 [Firefox:43 hits: 05-04 to 06-04] |
d791762796 [0] | ASM:Graph |
tElock| | lines=81 embedded dns |
trace |
17:18:00 | WinXP | 208.28.222.127 (KIMBANET.COM): SPRINT, MARTINSVILLE, VIRGINIA, US. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3038 hits: 12-31 to 06-08] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:17:54:00 | WinXP | 4.154.82.165 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, SUWANEE, GEORGIA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 88 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:17:55:00 | WinXP | 63.26.118.57 (UU.NET): UUNET TECHNOLOGIES INC, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 4 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:18:48:00 | WinXP | 98.140.130.18 (-): . |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
31 of 33 | bce12aa21f [Firefox:14 hits: 05-12 to 06-04] |
none[4] | none:none |
PolyEnE| | none | trace |
18:51:00 | WinXP | 98.140.130.18 (-): . |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 33 | bce12aa21f [Firefox:14 hits: 05-12 to 06-04] |
none[4] | none:none |
PolyEnE| | none | trace |
T:19:07:00 | WinXP | 24.77.205.226 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, KELOWNA, BRITISH COLUMBIA, CA. (DSL) |
67.43.236.98:10324 | CA:xx.nadnadzz.info CA:nadsam0.info US:130.107.163.157:18509 |
135 | pcap | raw alerts ruleset |
irc http 292 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 32 13 of 32 19 of 32 31 of 33 24 of 32 |
2b9c32bee9 NEW 2c11ff8e99 NEW 797863ab19 NEW 954a98c971 NEW e8f2f5bfe0 NEW |
2b9c32bee9 [1] none [4] none [4] none [4] none [4] |
ASM:Graph none:none none:none none:none none:none |
none|none none|none Mew| FSG| none|none |
lines=37 none none none none |
trace trace trace trace trace |
T:19:22:00 | WinXP | 4.228.123.105 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, AURORA, COLORADO, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:20:30:00 | Win2K-f | 61.17.221.73 (VSNL.NET.IN): VIDESH SANCHAR NIGAM LTD - INDIA, COCHIN, KERALA, IN. (DSL) |
84.244.5.183:2345 66.29.31.3:80 | US:wow.blackirc.us SE:tap.radioprishtina.net |
445 | pcap | raw alerts ruleset |
http irc 81 lines |
Yeah : 1.3 profile |
none | summary tarball |
4 of 31 12 of 32 |
3e69c64639 NEW a224cce2a7 NEW |
3e69c64639 [1] a224cce2a7[1] |
ASM:Graph ASM:Graph |
none|none StarForce| |
lines=32 lines=37 |
trace trace |
T:20:47:00 | WinXP | 61.218.193.218 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:20:58:00 | WinXP | 68.145.83.221 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |