Time
|
Victim OS
|
Infection Source
|
C&C Server
|
DNS Lookups & Failed Connects
|
Infection Port
|
Packet Trace
|
Detection Signatures
|
Infection Chatter
|
BotHunter Analysis
|
Behavioral Cluster
|
Forensic Logs
|
Antivirus Labels
|
Packed Malware_Binary
|
Unpacked egg.exe
|
Unpacked egg.asm
|
Packer PEID
|
Data Strings
|
Syscall Trace
|
T:00:26:00
|
Win2K-f
|
63.27.21.229 (UU.NET): UUNET TECHNOLOGIES INC, US.
|
n/a
|
US:microsoft.com US:download.microsoft.com US:207.123.37.125:80 US:207.123.42.126:80 US:4.23.60.126:80
|
135
|
pcap
|
raw alerts ruleset
|
other 105 lines
|
Yeah : 1.3
profile
|
none
|
summary tarball
|
33 of 33 0 of 32 |
53bfe15e91 [Firefox:4016 hits: 06-17 to 11-16] 73f1082158 [Firefox:1991 hits: 06-18 to 11-16]
|
none[4] 73f1082158[1]
|
none:none ASM:Graph
|
tElock| Armadillo|
|
none lines=81
|
trace trace
|
00:27:00
|
Win2K-f
|
86.52.136.124 (REV.STOFANET.DK): STOFANET-INET-CIDR, TAASTRUP, VESTSJALLAND, DK.
|
63.173.172.98:6667
|
|
139
|
pcap
|
raw alerts ruleset
|
ftp irc 18 lines
|
Yeah : 1.3
profile
|
none
|
summary tarball
|
29 of 34 |
e362f1c062 [Firefox:54 hits: 08-15 to 11-16]
|
none[none]
|
none:none
|
none|none
|
none
|
none
|
00:32:00
|
WinXP
|
58.230.192.35 (-): THRUNET-INFRA-SEOUL03, SEOUL, KYONGGI-DO, KR.
|
n/a
|
EU:proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:204.160.126.124:80 US:206.33.45.125:80 EU:79.132.211.24:65520 US:8.12.222.126:80
|
135
|
pcap
|
raw alerts ruleset
|
other 124 lines
|
Yeah : 1.3
profile
|
none
|
summary tarball
|
27 of 33 31 of 33 |
1951eee0cd [Firefox:19 hits: 06-18 to 11-15] e5e0dbde57 [Firefox:19 hits: 06-18 to 11-15]
|
1951eee0cd [1] none [4]
|
ASM:Graph none:none
|
Armadillo| tElock|
|
lines=82 none
|
trace trace
|