Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:05:00 | Win2K-f | 216.74.194.90 (ILAND.NET): IMAGINATION INC, KNOB NOSTER, MISSOURI, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 38 of 41 |
c3940285fd NEW f69c164193 NEW |
de206a939d [0] 404635142d[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:01:37:00 | WinXP | 124.66.248.249 (FCH.NE.JP): FUREAI CHANNEL INC, HIROSHIMA, HIROSHIMA, JP. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | a769511504 NEW |
7ecd054f18 [0] | none:none |
PolyEnE| | none | trace |
T:01:48:00 | Win2K-f | 24.164.58.84 (RR.COM): ROAD RUNNER HOLDCO LLC, LAKELAND, FLORIDA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:01:57:00 | WinXP | 62.253.84.45 (NTLI.NET): NTL INTERNET, LONDON, ENGLAND, UK. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:02:12:00 | WinXP | 66.63.109.240 (GWI.NET): GREAT WORKS INTERNET, SHAPLEIGH, MAINE, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:02:20:00 | WinXP | 93.81.205.64 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:02:43:00 | WinXP | 71.120.69.120 (VERIZON.NET): VERIZON INTERNET SERVICES INC, BLOOMINGTON, ILLINOIS, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
02:43:00 | Win2K-f | 195.22.21.71 (CLARA.NET): VIA NET.WORKS PORTUGAL - TECNOLOGIAS DE INFORMA CAO SA, PT. |
n/a | US:www.maxmind.com US:getmyip.co.uk US:www.getmyip.org EU:checkip.dyndns.org 208.78.69.70:80 US:65.254.39.170:80 US:67.15.94.80:80 US:75.126.138.202:80 |
139 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:02:47:00 | Win2K-f | 195.22.21.71 (CLARA.NET): VIA NET.WORKS PORTUGAL - TECNOLOGIAS DE INFORMA CAO SA, PT. |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:03:07:00 | Win2K-f | 4.152.159.31 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, NASHVILLE, TENNESSEE, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 603 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 | 83f6cb959d NEW |
445f56b6dd [0] | none:none |
StarForce| | none | trace | |
T:04:45:00 | WinXP | 119.230.42.29 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | 03f912899b NEW |
none[0] | none:none |
none|none | lines=64 | trace | |
T:04:53:00 | Win2K-f | 70.187.6.37 (COX.NET): COX COMMUNICATIONS, OMAHA, NEBRASKA, US. |
218.93.205.24:65520 | US:microsoft.com CN:proxim.ircgalaxy.pl CN:put.ghura.pl CN:brenz.pl CN:211.95.79.6:80 |
135 | pcap | raw alerts ruleset |
irc http 120 lines |
Yeah : 1.8 profile |
none | summary tarball |
15 of 41 32 of 36 35 of 36 |
298243013a NEW bea8cb1865 NEW fac78fde16 NEW |
b8c969e769 [0] 154de51a66[0] 882896ab05[0] |
none:none ASM:Graph none:none |
PEQuake| Armadillo| tElock| |
none lines=91 none |
trace trace trace |
T:05:02:00 | WinXP | 41.202.180.20 (-): . |
n/a | :moscow-advokat.ru SE:vancouver.dal.net SE:coins.dal.net :brussels.be.eu.undernet.org SE:broadway.ny.us.dal.net :los-angeles.ca.us.undernet.org SE:viking.dal.net AT:graz.at.eu.undernet.org |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 7f7647d18e NEW |
a81fd64562 [0] | none:none |
PolyEnE| | none | trace |
T:10:00:00 | WinXP | 24.175.157.178 (RR.COM): ROAD RUNNER HOLDCO LLC, DEATSVILLE, ALABAMA, US. |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:10:03:00 | WinXP | 4.177.18.252 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, SAN DIEGO, CALIFORNIA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 36 of 40 |
47d3548e36 NEW d8722af110 NEW |
ab13346633 [0] ab30a55931[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
10:27:00 | Win2K-f | 186.100.171.41 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org US:getmyip.co.uk :checkip.dyndns.org DE:131.220.6.26:80 US:65.254.39.170:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:10:36:00 | Win2K-f | 186.100.171.41 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org US:checkip.dyndns.org US:getmyip.co.uk 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:11:41:00 | Win2K-f | 63.246.121.32 (SPEAKEASY.NET): US. |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:11:53:00 | Win2K-f | 208.113.27.206 (NTDAPPAREL.COM): ACCELERATED CONNECTIONS, ONTARIO, CA. |
n/a | 135 | pcap | raw alerts ruleset |
other 1001 lines |
Yeah : 1.3 profile |
none | summary tarball |
12 of 40 | 7adb0e118d NEW |
none[3] | none:none |
StarForce| | none | trace | |
T:13:44:00 | Win2K-f | 68.144.29.181 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. |
n/a | 135 | pcap | raw alerts ruleset |
other 1014 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 35 | f2cfdc83a8 NEW |
none[3] | none:none |
none|none | none | trace | |
T:14:28:00 | WinXP | 211.211.153.167 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
221.5.74.39:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:put.ghura.pl CN:brenz.pl CN:211.95.79.6:80 |
135 | pcap | raw alerts ruleset |
irc http 135 lines |
Yeah : 1.8 profile |
none | summary tarball |
15 of 41 30 of 33 28 of 33 |
298243013a NEW 533d15b5ce NEW 58c343a8d8 NEW |
b8c969e769 [0] c67adf46e2[0] none [0] |
none:none ASM:Graph none:none |
PEQuake| tElock| Armadillo| |
none lines=126 embedded dns lines=91 |
trace trace trace |
T:15:07:00 | Win2K-f | 124.241.190.162 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, AICHI, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
15:15:00 | WinXP | 83.97.237.246 (CM-83-97-128-10.TELECABLE.ES): TELECABLE, GIJON, ASTURIAS, ES. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1fcc146d70 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:15:35:00 | WinXP | 82.24.29.200 (NTL.COM): NTL INFRASTRUCTURE - LEWISHAM, LONDON, ENGLAND, UK. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 21 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:15:35:00 | WinXP | 93.102.53.100 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | :www.google.com.au US:www.yahoo.com :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 17028f1eda NEW |
none[3] | none:none |
tElock| | none | trace |
T:15:35:00 | Win2K-f | 4.231.148.27 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DEER PARK, TEXAS, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 675 lines |
Yeah : 1.3 profile |
none | summary tarball |
7 of 41 | f5dd9f1f9d NEW |
none[3] | none:none |
none|none | none | trace | |
17:14:00 | Win2K-f | 190.220.223.143 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org EU:checkip.dyndns.org US:getmyip.co.uk DE:131.220.6.26:80 US:65.254.39.170:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:17:28:00 | WinXP | 4.155.33.111 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, OWINGS MILLS, MARYLAND, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1020 lines |
Yeah : 1.3 profile |
none | summary tarball |
5 of 41 | 148b3ff351 NEW |
none[3] | none:none |
StarForce| | none | trace | |
T:18:31:00 | Win2K-f | 210.244.13.51 (SEED.NET.TW): DIGITAL UNITED INC, TAINAN, KAO-HSIUNG, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 36 of 41 |
2294edfc36 NEW 3959e0ddf3 NEW |
1b0799e7b2 [0] 60ba459f82[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:20:02:00 | Win2K-f | 63.17.130.6 (UU.NET): UUNET TECHNOLOGIES INC, NEW YORK, NEW YORK, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:04:00 | WinXP | 122.18.28.108 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:21:51:00 | WinXP | 61.218.193.250 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 81 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |