Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
01:07:00 | Win2K-f | 113.88.189.2 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org US:checkip.dyndns.org :getmyip.co.uk US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:01:19:00 | Win2K-f | 122.155.9.123 (CDPM1.COM): CAT TELECOM PUBLIC COMPANY LTD, TH. |
n/a | US:www.maxmind.com US:www.getmyip.org EU:checkip.dyndns.org :getmyip.co.uk 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
01:25:00 | Win2K-f | 58.253.205.58 (CNCNET.NET): CNC GROUP GUANGDONG PROVINCE NETWORK, GUANGZHOU, GUANGDONG, CN. (DSL) |
n/a | US:www.maxmind.com :getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org 208.78.68.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 7587773eea NEW |
none[3] | none:none |
StarForce| | none | trace |
03:01:00 | Win2K-f | 122.126.69.189 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | US:www.maxmind.com :checkip.dyndns.org US:www.getmyip.org :getmyip.co.uk US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
03:45:00 | Win2K-f | 88.65.216.252 (ARCOR-IP.NET): ARCOR-DSL-NET, DE. |
n/a | US:www.maxmind.com :getmyip.co.uk US:www.getmyip.org US:checkip.dyndns.org 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | 917c085aca NEW |
none[3] | none:none |
Armadillo| | none | trace |
T:04:01:00 | Win2K-f | 88.65.216.252 (ARCOR-IP.NET): ARCOR-DSL-NET, DE. |
n/a | US:www.maxmind.com US:www.getmyip.org EU:checkip.dyndns.org :getmyip.co.uk US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | 917c085aca NEW |
none[3] | none:none |
Armadillo| | none | trace |
04:03:00 | Win2K-f | 75.10.64.41 (MDSG-PACWEST.COM): BOND MANUFACTURING, PLANO, TEXAS, US. (100Mbps) |
n/a | US:www.maxmind.com :getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org 208.78.69.70:80 US:67.15.94.80:80 US:75.10.64.41:5062 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
05:24:00 | Win2K-f | 203.150.222.30 (INTER.NET.TH): INTERNET THAILAND PUBLIC COMPANY LIMITED, TH. |
n/a | US:www.maxmind.com :checkip.dyndns.org :getmyip.co.uk US:www.getmyip.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:05:28:00 | Win2K-f | 122.126.69.189 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | US:www.maxmind.com US:checkip.dyndns.org :getmyip.co.uk US:www.getmyip.org 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:05:52:00 | Win2K-f | 190.220.110.238 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org :getmyip.co.uk EU:checkip.dyndns.org 208.78.68.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
06:26:00 | Win2K-f | 116.18.237.37 (163DATA.COM.CN): CHINANET GUANGDONG PROVINCE NETWORK, BEIJING, BEIJING, CN. |
n/a | US:www.maxmind.com :getmyip.co.uk US:www.getmyip.org :checkip.dyndns.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 7587773eea NEW |
none[3] | none:none |
StarForce| | none | trace |
T:06:33:00 | Win2K-f | 190.191.122.176 (-): . |
n/a | US:www.maxmind.com US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
07:11:00 | Win2K-f | 200.6.118.82 (ST01.IIA.CL): IIA INGENIERIA LTDA, SANTIAGO, REGION METROPOLITANA, CL. |
n/a | US:www.maxmind.com US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:07:16:00 | Win2K-f | 116.18.237.37 (163DATA.COM.CN): CHINANET GUANGDONG PROVINCE NETWORK, BEIJING, BEIJING, CN. |
n/a | US:www.maxmind.com :getmyip.co.uk :checkip.dyndns.org 208.78.69.70:80 US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 7587773eea NEW |
none[3] | none:none |
StarForce| | none | trace |
07:30:00 | Win2K-f | 125.21.50.182 (59.AIRTELBROADBAND.IN): BHARTI TELEVENTURES LIMITED A/C ABTS MP, BHOPAL, MADHYA PRADESH, IN. |
n/a | US:www.maxmind.com US:www.getmyip.org :getmyip.co.uk US:checkip.dyndns.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | d60e538e72 NEW |
none[3] | none:none |
UPX| | none | trace |
T:08:17:00 | WinXP | 69.23.151.12 (RR.COM): ROAD RUNNER HOLDCO LLC, RESEDA, CALIFORNIA, US. |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :wpad :www.proxy-socks.net EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http http http 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee NEW |
none[0] | none:none |
ASPack| | lines=298 embedded dns |
trace |
08:25:00 | Win2K-f | 173.45.90.155 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org EU:checkip.dyndns.org :getmyip.co.uk 173.45.90.155:6994 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:09:43:00 | Win2K-f | 200.6.118.82 (ST01.IIA.CL): IIA INGENIERIA LTDA, SANTIAGO, REGION METROPOLITANA, CL. |
n/a | US:www.maxmind.com :checkip.dyndns.org :getmyip.co.uk US:www.getmyip.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
09:45:00 | Win2K-f | 220.136.244.42 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | US:www.maxmind.com :getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
10:04:00 | Win2K-f | 85.104.5.5 (TTNET.NET.TR): TURK TELEKOM ADSL-METEKSAN, ISTANBUL, ISTANBUL, TR. (DSL) |
n/a | US:www.maxmind.com :getmyip.co.uk US:checkip.dyndns.org US:www.getmyip.org 208.78.68.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 7587773eea NEW |
none[3] | none:none |
StarForce| | none | trace |
10:47:00 | Win2K-f | 190.50.117.228 (COM.AR): TELEFONICA DE ARGENTINA, AR. |
n/a | US:www.maxmind.com :getmyip.co.uk EU:checkip.dyndns.org US:www.getmyip.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
4 of 37 | 8ce32ded17 NEW |
none[3] | none:none |
Armadillo| | none | trace |
10:48:00 | Win2K-f | 190.224.135.82 (-): . |
n/a | US:www.maxmind.com :checkip.dyndns.org :getmyip.co.uk US:www.getmyip.org 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:11:25:00 | Win2K-f | 201.172.150.197 (MULTIMEDIOS.NET): TELEVISION INTERNACIONAL S.A. DE C.V, MX. |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org :getmyip.co.uk 208.78.68.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 7587773eea NEW |
none[3] | none:none |
StarForce| | none | trace |
T:14:20:00 | Win2K-f | 84.120.148.192 (ONO.COM): CABLEUROPA - ONO, VALENCIA, VALENCIA, ES. |
n/a | US:www.maxmind.com US:www.getmyip.org US:checkip.dyndns.org US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | 216ec67841 NEW |
none[3] | none:none |
StarForce| | none | trace |
14:35:00 | Win2K-f | 74.222.6.162 (VRTSERVERS.NET): VRTSERVERS INC, SEWICKLEY, PENNSYLVANIA, US. |
n/a | US:www.maxmind.com EU:checkip.dyndns.org US:www.getmyip.org :getmyip.co.uk 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:15:09:00 | Win2K-f | 74.222.6.162 (VRTSERVERS.NET): VRTSERVERS INC, SEWICKLEY, PENNSYLVANIA, US. |
n/a | US:www.maxmind.com :checkip.dyndns.org US:www.getmyip.org :getmyip.co.uk 208.78.68.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
16:39:00 | Win2K-f | 119.45.46.72 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org :getmyip.co.uk US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:17:02:00 | Win2K-f | 94.102.14.37 (-): . |
n/a | US:www.maxmind.com :getmyip.co.uk US:www.getmyip.org US:checkip.dyndns.org 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:17:13:00 | Win2K-f | 119.45.46.72 (-): . |
n/a | US:www.maxmind.com EU:checkip.dyndns.org US:www.getmyip.org :getmyip.co.uk 208.78.68.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:17:29:00 | Win2K-f | 203.144.227.20 (ASIANET.CO.TH): TRUE INTERNET CO. LTD, BANGKOK, KRUNG THEP MAHANAKHON, TH. |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
17:35:00 | Win2K-f | 201.244.213.141 (ETB.NET.CO): ETB - COLOMBIA, SANTAFé DE BOGOTá, DISTRITO CAPITAL, CO. (DSL) |
n/a | US:www.maxmind.com :getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:17:59:00 | Win2K-f | 201.244.213.141 (ETB.NET.CO): ETB - COLOMBIA, SANTAFé DE BOGOTá, DISTRITO CAPITAL, CO. (DSL) |
n/a | US:www.maxmind.com US:checkip.dyndns.org US:www.getmyip.org :getmyip.co.uk US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
18:51:00 | WinXP | 98.148.158.168 (-): . |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:19:33:00 | Win2K-f | 210.233.200.95 (MEDIATTI.NET): MEDIATTI COMMUNICATIONS INC, OKINAWA, OKINAWA, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 87 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 33 33 of 33 |
3ed16ae12d NEW 79c01ec060 NEW |
3ed16ae12d [1] none [4] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=81 none |
trace trace |
T:20:24:00 | Win2K-f | 189.28.177.42 (BRASILTELECOM.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. |
n/a | US:www.maxmind.com US:www.getmyip.org EU:checkip.dyndns.org :getmyip.co.uk US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
20:35:00 | Win2K-f | 200.112.129.72 (NET.AR): BROADBANDTECH S. A, MENDOZA, MENDOZA, AR. |
n/a | US:www.maxmind.com US:www.getmyip.org :getmyip.co.uk :checkip.dyndns.org US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 7587773eea NEW |
none[3] | none:none |
StarForce| | none | trace |
T:22:06:00 | Win2K-f | 74.222.2.113 (VRTSERVERS.NET): VRTSERVERS INC, LOS ANGELES, CALIFORNIA, US. |
n/a | US:www.maxmind.com :getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:22:08:00 | Win2K-f | 78.39.184.25 (-): INFORMATION TECHNOLOGY COMPANY (ITC), IR. |
n/a | US:www.maxmind.com :getmyip.co.uk US:checkip.dyndns.org US:www.getmyip.org 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
22:50:00 | Win2K-f | 122.155.9.40 (CDPM1.COM): CAT TELECOM PUBLIC COMPANY LTD, TH. |
n/a | US:www.maxmind.com :getmyip.co.uk US:www.getmyip.org EU:checkip.dyndns.org 208.78.68.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:23:06:00 | Win2K-f | 124.82.37.35 (TM.NET.MY): TM ADSL SERVICE PROVIDER MALAYSIA, KUCHING, SARAWAK, MY. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org :getmyip.co.uk US:www.getmyip.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
14 of 39 | 11ce83d11a NEW |
none[3] | none:none |
UPX| | none | trace |