Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:14:00 | Win2K-f | 122.3.252.173 (PLDT.NET): IPG, PH. |
n/a | US:www.maxmind.com :getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | 917c085aca NEW |
none[3] | none:none |
Armadillo| | none | trace |
00:33:00 | Win2K-f | 190.137.195.131 (NET.AR): TELECOM ARGENTINA S.A, AR. |
n/a | US:www.maxmind.com :getmyip.co.uk :checkip.dyndns.org US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
00:37:00 | Win2K-f | 125.224.83.194 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | US:www.maxmind.com US:checkip.dyndns.org :getmyip.co.uk US:www.getmyip.org 208.78.68.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
00:51:00 | Win2K-f | 115.165.212.253 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org EU:checkip.dyndns.org :getmyip.co.uk US:204.13.249.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
01:00:00 | Win2K-f | 119.228.128.73 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org :getmyip.co.uk US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
01:08:00 | Win2K-f | 122.125.129.110 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
01:15:00 | Win2K-f | 115.194.51.145 (-): . |
n/a | US:www.maxmind.com :getmyip.co.uk US:www.getmyip.org US:checkip.dyndns.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
02:30:00 | Win2K-f | 62.33.183.44 (-): (KR000067) MODERN TECHNOLOGIES OF COMMUNICATION, KRASNOYARSK, KRASNOYARSKIY KRAY, RU. |
n/a | US:www.maxmind.com :getmyip.co.uk EU:checkip.dyndns.org US:www.getmyip.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
02:43:00 | Win2K-f | 201.16.236.183 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | US:www.maxmind.com :getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
02:44:00 | Win2K-f | 119.92.222.229 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org :getmyip.co.uk :checkip.dyndns.org 208.78.68.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | 71afca1665 NEW |
none[3] | none:none |
StarForce| | none | trace |
03:29:00 | Win2K-f | 221.125.213.8 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HK. |
n/a | US:www.maxmind.com :getmyip.co.uk US:www.getmyip.org US:checkip.dyndns.org US:204.13.249.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
04:03:00 | Win2K-f | 122.121.226.208 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | US:www.maxmind.com :getmyip.co.uk EU:checkip.dyndns.org US:www.getmyip.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
04:12:00 | Win2K-f | 58.27.238.110 (-): NATIONAL WIMAX/IMS ENVIRONMENT, PK. |
n/a | US:www.maxmind.com US:www.getmyip.org :getmyip.co.uk :checkip.dyndns.org US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | d60e538e72 NEW |
none[3] | none:none |
UPX| | none | trace |
04:30:00 | Win2K-f | 119.92.161.246 (-): . |
n/a | US:www.maxmind.com :checkip.dyndns.org :getmyip.co.uk US:www.getmyip.org 208.78.68.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
04:30:00 | Win2K-f | 78.139.164.229 (-): CAUCASUS NETWORK LTD, GE. |
n/a | US:www.maxmind.com US:checkip.dyndns.org :getmyip.co.uk US:www.getmyip.org US:204.13.249.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
05:21:00 | Win2K-f | 210.7.73.167 (PRIMUS-INDIA.NET): DIRECT INTERNET LTD, GURGAON, HARYANA, IN. (100Mbps) |
n/a | US:www.maxmind.com EU:checkip.dyndns.org :getmyip.co.uk US:www.getmyip.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
05:43:00 | Win2K-f | 125.224.32.146 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | US:www.maxmind.com US:www.getmyip.org :getmyip.co.uk :checkip.dyndns.org 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
05:58:00 | Win2K-f | 190.188.186.124 (NET.AR): PRIMA S.A, AR. |
n/a | US:www.maxmind.com :getmyip.co.uk US:www.getmyip.org :checkip.dyndns.org 208.78.68.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
06:01:00 | Win2K-f | 190.3.53.62 (TECHTELNET.NET): TECHTEL LMDS COMUNICACIONES INTERACTIVAS S.A, AR. |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
06:12:00 | Win2K-f | 82.64.119.156 (PROXAD.NET): PROXAD / FREE SAS, FR. (DSL) |
n/a | US:www.maxmind.com US:checkip.dyndns.org :getmyip.co.uk US:www.getmyip.org US:204.13.249.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
06:43:00 | Win2K-f | 84.15.124.10 (VKT.LT): PROVIDER LOCAL REGISTRY, VILNIUS, VILNIAUS APSKRITIS, LT. |
n/a | US:www.maxmind.com US:www.getmyip.org EU:checkip.dyndns.org :getmyip.co.uk US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
08:01:00 | Win2K-f | 211.74.112.136 (SEED.NET.TW): DIGITAL UNITED INC, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:www.maxmind.com :getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
09:04:00 | Win2K-f | 118.161.215.144 (-): . |
n/a | US:www.maxmind.com :getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
09:19:00 | Win2K-f | 78.83.138.29 (SPNET.NET): SPNET, BG. |
n/a | US:www.maxmind.com :getmyip.co.uk US:checkip.dyndns.org US:www.getmyip.org 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
09:31:00 | Win2K-f | 124.8.224.34 (TFN.NET.TW): TAIWAN FIXED NETWORK CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | US:www.maxmind.com US:www.getmyip.org :getmyip.co.uk EU:checkip.dyndns.org 208.78.68.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | 917c085aca NEW |
none[3] | none:none |
Armadillo| | none | trace |
09:31:00 | Win2K-f | 125.224.40.117 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | US:www.maxmind.com :getmyip.co.uk US:www.getmyip.org :checkip.dyndns.org US:204.13.249.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
09:43:00 | Win2K-f | 87.14.204.172 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A. TIN EASY LITE, TORINO, PIEMONTE, IT. |
n/a | US:www.maxmind.com :getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
10:02:00 | Win2K-f | 190.55.181.161 (-): . |
n/a | US:www.maxmind.com :getmyip.co.uk US:www.getmyip.org US:checkip.dyndns.org 190.55.181.161:5534 US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | d60e538e72 NEW |
none[3] | none:none |
UPX| | none | trace |
10:22:00 | Win2K-f | 190.188.218.89 (NET.AR): PRIMA S.A, AR. |
n/a | US:www.maxmind.com :getmyip.co.uk EU:checkip.dyndns.org US:www.getmyip.org 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
10:26:00 | Win2K-f | 59.112.163.121 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org :getmyip.co.uk 208.78.68.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
21 of 39 | 249bd2a467 NEW |
none[none] | none:none |
none|none | none | none |
10:33:00 | Win2K-f | 69.12.92.32 (FIRELAB.NET): A346 - NAGT, CHICAGO, ILLINOIS, US. |
n/a | US:www.maxmind.com :getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org US:204.13.249.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
22:46:00 | Win2K-f | 119.77.172.38 (-): . |
n/a | US:www.maxmind.com :getmyip.co.uk US:www.getmyip.org US:checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 11 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
22:46:00 | Win2K-f | 95.189.147.81 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org EU:checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 9 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:22:47:00 | Win2K-f | 212.175.149.20 (USSINVEST.COM): NETHOUSE BILGI ISLEM MERKEZI, TR. (100Mbps) |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 11 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:22:47:00 | Win2K-f | 95.189.147.81 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 9 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
23:09:00 | Win2K-f | 203.70.254.82 (SEED.NET.TW): DIGITAL UNITED INC, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org :getmyip.co.uk US:checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 9 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:23:10:00 | Win2K-f | 78.38.123.19 (-): INFORMATION TECHNOLOGY COMPANY (ITC), IR. |
n/a | US:www.maxmind.com :getmyip.co.uk US:www.getmyip.org EU:checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 9 lines |
Yeah : 0.8 profile |
none | summary tarball |
18 of 38 | bfda9b8926 NEW |
none[3] | none:none |
StarForce| | none | trace |
23:21:00 | Win2K-f | 212.175.149.20 (USSINVEST.COM): NETHOUSE BILGI ISLEM MERKEZI, TR. (100Mbps) |
n/a | US:www.maxmind.com :getmyip.co.uk :checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 8 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:23:23:00 | Win2K-f | 80.77.146.50 (-): NEOTEL INTERNET WIMAX, MK. |
n/a | US:www.maxmind.com :getmyip.co.uk :checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 8 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
23:36:00 | Win2K-f | 200.71.103.45 (TELESAT.COM.CO): COLDECON, CALI, VALLE DEL CAUCA, CO. |
n/a | US:www.maxmind.com US:checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 8 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
23:38:00 | Win2K-f | 78.38.123.19 (-): INFORMATION TECHNOLOGY COMPANY (ITC), IR. |
n/a | US:www.maxmind.com EU:checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 8 lines |
Yeah : 0.8 profile |
none | summary tarball |
18 of 38 | bfda9b8926 NEW |
none[3] | none:none |
StarForce| | none | trace |
23:42:00 | Win2K-f | 121.12.250.146 (163DATA.COM.CN): CHINANET GUANGDONG PROVINCE NETWORK, GUANGZHOU, GUANGDONG, CN. |
n/a | US:www.maxmind.com :checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 8 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
23:59:00 | Win2K-f | 219.86.193.23 (TFN.NET.TW): TAIWAN FIXED NETWORK CO. LTD, TW. |
n/a | US:www.maxmind.com :checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 8 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |