Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:28:00 | Win2K-f | 115.130.50.44 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:00:37:00 | WinXP | 67.123.204.202 (PACBELL.NET): RICHARD MULHALL, SAN FRANCISCO, CALIFORNIA, US. (DSL) |
67.43.236.66:10324 | CA:xx.nadnadzz.info :nadsamcabran12.com 67.215.1.206:80 |
135 | pcap | raw alerts ruleset |
irc 638 lines |
Yeah : 1.8 profile |
none | summary tarball |
40 of 41 | 3842e66ff7 NEW |
fc7c8aaf10 [0] | none:none |
EXECrypto| | none | trace |
T:04:49:00 | Win2K-f | 63.23.38.56 (UU.NET): UUNET TECHNOLOGIES INC, SAN FRANCISCO, CALIFORNIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:05:25:00 | WinXP | 210.79.135.161 (MEDIATTI.NET): MEDIATTI COMMUNICATIONS INC, TOKYO, TOKYO, JP. |
n/a | CA:xx.ka3ek.com :nadsamcabran12.com 67.215.1.206:80 |
445 | pcap | raw alerts ruleset |
shell ftp irc 24 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 85aa779737 NEW |
ccdaedd45c [0] | none:none |
PeCompact| | none | trace |
06:08:00 | Win2K-f | 59.125.210.63 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | US:www.maxmind.com US:getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org US:65.254.39.170:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:07:54:00 | WinXP | 75.177.173.190 (RR.COM): ROAD RUNNER HOLDCO LLC, RALEIGH, NORTH CAROLINA, US. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 986b59708d NEW |
none[0] | none:none |
PolyEnE| | lines=57 | trace |
T:10:29:00 | WinXP | 70.77.232.143 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
218.93.205.24:65520 | CN:proxim.ircgalaxy.pl CN:brenz.pl CN:211.95.79.6:80 |
445 | pcap | raw alerts ruleset |
http irc 28 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 | 0658d04f28 NEW |
07f788a60e [0] | none:none |
PolyEnE| | none | trace |
T:10:33:00 | WinXP | 75.83.58.54 (RR.COM): ROAD RUNNER HOLDCO LLC, SAN DIMAS, CALIFORNIA, US. |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com SE:kavkazcenter.com SE:kavkazcenter.net FI:kavkazchat.com US:chechenpress.info GB:chechenpress.co.uk :shaheeds.org :daymohk.info :chripress.org :marsho.dk GB:www.chechenpress.co.uk FI:imgs2.kavkazcenter.com :www.google.com :www.google-analytics.com :widget-c6.slide.com :blip.tv :www.youtube.com GB:217.194.210.198:80 US:72.29.65.216:80 FI:80.81.183.162:80 SE:88.80.5.15:80 |
445 | pcap | raw alerts ruleset |
http http 98 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | ab5e47bf8d NEW |
67fb5eff61 [0] | none:none |
ASPack| | none | trace |
T:10:46:00 | WinXP | 95.24.246.26 (-): . |
n/a | RU:www.binbank.ru :daymohk.info :marsho.dk GB:www.chechenpress.co.uk FI:imgs2.kavkazcenter.com :www.google.com :www.google-analytics.com :widget-c6.slide.com :blip.tv :www.youtube.com :e.blip.tv CA:www.cibc.com CA:159.231.80.200:80 |
445 | pcap | raw alerts ruleset |
http http 362 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:11:01:00 | Win2K-f | 66.91.120.44 (RR.COM): ROAD RUNNER HOLDCO LLC, HONOLULU, HAWAII, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:24:00 | Win2K-f | 70.183.234.202 (COX.NET): COX COMMUNICATIONS, PENSACOLA, FLORIDA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:13:04:00 | WinXP | 70.77.210.7 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 39 of 41 |
289f5b8ec0 NEW 6bb0a5c719 NEW |
f9eb6c381d [0] 022947ce3d[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:13:26:00 | WinXP | 4.171.177.207 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, MADISON, FLORIDA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 3 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:14:02:00 | Win2K-f | 70.21.124.79 (VERIZON.NET): VERIZON INTERNET SERVICES INC, WASHINGTON, DISTRICT OF COLUMBIA, US. |
n/a | NL:wow.blackirc.us | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:14:07:00 | Win2K-f | 117.19.5.229 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. |
218.93.205.24:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:put.ghura.pl CN:brenz.pl CN:www.guarddog2009.com CN:211.95.79.6:80 CN:218.93.205.19:80 |
135 | pcap | raw alerts ruleset |
irc http 238 lines |
Yeah : 1.8 profile |
none | summary tarball |
34 of 36 32 of 36 8 of 41 |
1fa62445aa NEW 963d5f92ac NEW f839bf64f0 NEW |
1fe0ba5b26 [0] b851ccde4f[0] 8716afcbbb[0] |
none:none none:none none:none |
tElock| FASM| ASProtect| |
none none none |
trace trace trace |
14:14:00 | WinXP | 114.137.57.19 (-): . |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:14:32:00 | Win2K-f | 130.13.15.171 (QWEST.NET): QWEST BROADBAND SERVICES INC, PHOENIX, ARIZONA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:16:16:00 | WinXP | 60.234.103.47 (ORCON.NET.NZ): ORCON INTERNET LTD SUPPORT, AUCKLAND, AUCKLAND, NZ. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:16:37:00 | WinXP | 114.48.29.51 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
18:02:00 | Win2K-f | 190.105.32.94 (-): . |
n/a | US:www.maxmind.com US:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:19:07:00 | Win2K-f | 74.211.53.122 (BEYONDBB.COM): ORANGE BROADBAND, CHARLOTTE, NORTH CAROLINA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 1007 lines |
Yeah : 1.3 profile |
none | summary tarball |
4 of 41 | a8c1c0e956 NEW |
df796d44f5 [0] | none:none |
StarForce| | none | trace | |
T:19:13:00 | WinXP | 114.255.145.49 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 121 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 40 37 of 40 |
1a76ee47c1 NEW 78834f5ab6 NEW |
8ef942208b [0] 2e416b0e36[0] |
none:none ASM:Graph |
Armadillo| tElock| |
none lines=64 embedded dns |
trace trace |
T:20:12:00 | WinXP | 207.5.154.248 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BIDDEFORD, MAINE, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:17:00 | Win2K-f | 203.180.132.203 (IIJ4U.OR.JP): IIJ INTERNET, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:22:00 | WinXP | 24.80.42.5 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SURREY, BRITISH COLUMBIA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 124 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 38 of 41 |
34cbe7a593 NEW 3e83a2d4d7 NEW |
d38cb78003 [0] b97fd63d29[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:21:17:00 | Win2K-f | 70.60.117.169 (RR.COM): ROAD RUNNER HOLDCO LLC, CHARLOTTE, NORTH CAROLINA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:43:00 | WinXP | 114.207.150.21 (-): . |
221.5.74.39:65520 | CN:proxima.ircgalaxy.pl US:microsoft.com EU:dfeuvyoage.net :cmdmand.info :mcsset.org CN:brenz.pl :inporter.info NL:thcway.info :moreverde.com :mounth.biz :gethtmlhelp.com :rabetis.net EU:thestatsdata.com :www.searchmagnets.net US:online-fabrics-store.info CN:211.95.79.6:80 US:68.178.254.169:80 |
135 | pcap | raw alerts ruleset |
irc http 126 lines |
Yeah : 1.8 profile |
none | summary tarball |
31 of 33 9 of 41 31 of 33 |
168aab35a3 NEW 1c3b65d074 NEW 667f0c59f3 NEW |
60b730b97e [0] 9b65f560ef[0] 8fe2be2095[0] |
ASM:Graph none:none ASM:Graph |
tElock| none|none Armadillo| |
lines=120 embedded dns none lines=91 |
trace trace trace |
T:21:46:00 | Win2K-f | 173.25.98.116 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 83 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:50:00 | WinXP | 4.131.142.40 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, LOS ANGELES, CALIFORNIA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1000 lines |
Yeah : 1.3 profile |
none | summary tarball |
9 of 41 | b46af1d7bc NEW |
none[3] | none:none |
none|none | none | trace |