Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:03:44:00 | WinXP | 62.63.208.127 (TYFON.SE): TYFON SVENSKA AB, SE. |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | d175bad0e6 NEW |
none[0] | ASM:Graph |
tElock| | lines=81 embedded dns |
trace |
T:05:54:00 | WinXP | 62.255.104.70 (NTLI.NET): NTL INTERNET - BRENTFORD POP, LONDON, ENGLAND, UK. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:06:24:00 | WinXP | 77.23.230.36 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
66.252.13.214:2081 | US:s.unicat.org US:66.252.13.214:2081 |
445 | pcap | raw alerts ruleset |
ftp irc 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | aaa7d3786e NEW |
f9776cd49e [0] | none:none |
none|none | none | trace |
T:07:12:00 | WinXP | 24.86.88.68 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SURREY, BRITISH COLUMBIA, CA. (DSL) |
61.120.62.28:3305 | JP:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 604 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 41 | 55f3155cd3 NEW |
a6fcdff22d [0] | none:none |
StarForce| | none | trace |
T:08:27:00 | Win2K-f | 24.69.153.35 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
61.120.62.28:3305 | TH:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 607 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 40 | e78c487d0b NEW |
74f7d3ae9c [0] | none:none |
StarForce| | none | trace |
T:08:50:00 | WinXP | 69.232.18.154 (PACBELL.NET): HI STYLES FASHIONS INC, PLANO, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:09:32:00 | Win2K-f | 221.142.43.241 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
221.5.74.39:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:brenz.pl CN:211.95.79.6:80 |
135 | pcap | raw alerts ruleset |
irc 134 lines |
Yeah : 1.8 profile |
none | summary tarball |
29 of 32 28 of 32 |
8a75955033 NEW 9276c8b36b NEW |
2bf3e548b9 [0] none [0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=126 embedded dns lines=81 |
trace trace |
T:09:38:00 | Win2K-f | 70.183.164.236 (COX.NET): COX COMMUNICATIONS, WARWICK, RHODE ISLAND, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:10:29:00 | WinXP | 98.141.163.84 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:10:32:00 | Win2K-f | 75.184.40.132 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:10:49:00 | WinXP | 24.227.62.42 (RR.COM): ROAD RUNNER HOLDCO LLC, CASSELBERRY, FLORIDA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:10:50:00 | WinXP | 114.42.14.200 (-): . |
66.252.13.214:2010 | :adware.rxmods.net US:f.unicat.org |
139 | pcap | raw alerts ruleset |
ftp http irc 41 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 6f6eefac6f NEW |
none[3] | none:none |
ASPack| | none | trace |
T:10:59:00 | WinXP | 71.112.119.114 (VERIZON.NET): VERIZON INTERNET SERVICES INC, BOTHELL, WASHINGTON, US. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 2d16d63f91 NEW |
27cb26ee14 [0] | none:none |
PolyEnE| | none | trace |
T:13:16:00 | WinXP | 98.145.64.180 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:14:13:00 | WinXP | 89.111.226.251 (TEOL.NET): TELEKOMSRPSKE, BA. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
37 of 40 | f54691063f NEW |
6039c698cd [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:14:54:00 | Win2K-f | 70.169.227.210 (COX.NET): COX COMMUNICATIONS, LAS VEGAS, NEVADA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
15:28:00 | Win2K-f | 79.126.43.62 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | US:www.maxmind.com EU:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:16:13:00 | WinXP | 114.48.47.113 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:18:16:00 | Win2K-f | 4.181.155.125 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, W HARTFORD, CONNECTICUT, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:18:16:00 | WinXP | 67.8.56.42 (RR.COM): ROAD RUNNER HOLDCO LLC, NAPLES, FLORIDA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:19:18:00 | Win2K-f | 24.69.153.35 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
61.120.62.28:3305 | :cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 607 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 40 | e78c487d0b NEW |
74f7d3ae9c [0] | none:none |
StarForce| | none | trace |
T:19:47:00 | WinXP | 98.141.161.39 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:19:51:00 | Win2K-f | 114.207.237.175 (-): . |
218.93.205.24:65520 | US:microsoft.com CN:proxim.ircgalaxy.pl CN:brenz.pl CN:211.95.79.6:80 CN:218.93.205.24:65520 |
135 | pcap | raw alerts ruleset |
irc 122 lines |
Yeah : 1.8 profile |
none | summary tarball |
30 of 33 28 of 33 |
533d15b5ce NEW 58c343a8d8 NEW |
c67adf46e2 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=126 embedded dns lines=91 |
trace trace |
T:21:04:00 | WinXP | 74.75.26.41 (RR.COM): ROAD RUNNER HOLDCO LLC, PITTSFIELD, MASSACHUSETTS, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 33 of 33 |
4c3df24b32 NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=75 embedded dns |
trace trace |
22:40:00 | Win2K-f | 122.124.2.217 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | US:www.maxmind.com US:www.getmyip.org US:getmyip.co.uk :checkip.dyndns.org US:65.254.39.170:80 US:67.15.94.80:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | d60e538e72 NEW |
none[3] | none:none |
UPX| | none | trace |
T:22:50:00 | Win2K-f | 122.124.2.217 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | US:www.maxmind.com US:getmyip.co.uk US:www.getmyip.org :checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 7 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | d60e538e72 NEW |
none[3] | none:none |
UPX| | none | trace |
T:23:20:00 | WinXP | 173.25.98.116 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |