Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:33:00 | WinXP | 86.155.21.8 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | ASM:Graph |
none|none | lines=61 | trace | |
T:03:37:00 | WinXP | 118.220.243.42 (-): . |
221.5.74.39:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:put.ghura.pl CN:brenz.pl CN:211.95.79.6:80 CN:218.93.205.24:65520 CN:221.5.74.39:65520 |
135 | pcap | raw alerts ruleset |
irc http 118 lines |
Yeah : 1.8 profile |
none | summary tarball |
15 of 41 30 of 33 28 of 33 |
298243013a NEW 533d15b5ce NEW 58c343a8d8 NEW |
b8c969e769 [0] c67adf46e2[0] none [0] |
none:none ASM:Graph none:none |
PEQuake| tElock| Armadillo| |
none lines=126 embedded dns lines=91 |
trace trace trace |
T:03:47:00 | Win2K-f | 125.58.90.19 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:05:17:00 | Win2K-f | 118.216.188.45 (-): . |
218.93.205.24:65520 | CN:proxima.ircgalaxy.pl US:microsoft.com CN:brenz.pl CN:211.95.79.6:80 CN:218.93.205.24:65520 |
135 | pcap | raw alerts ruleset |
irc 170 lines |
Yeah : 1.8 profile |
none | summary tarball |
40 of 41 39 of 40 |
a50c054e50 NEW f28964bd2f NEW |
d5f51c70ad [0] a85e4a26c3[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:05:26:00 | WinXP | 194.12.228.165 (LIREX.NET): CENTRUM GROUP, BG. |
n/a | DE:siliconfireware.ru GB:welcome3.smile.co.uk :wpad US:searchportal.information.com US:spi.domainsponsor.com GB:195.92.84.198:80 DE:212.227.111.29:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http http 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:05:35:00 | WinXP | 114.48.5.231 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:05:44:00 | Win2K-f | 98.141.9.117 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:08:08:00 | WinXP | 70.183.169.22 (COX.NET): COX COMMUNICATIONS, WOONSOCKET, RHODE ISLAND, US. |
221.5.74.39:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:brenz.pl CN:211.95.79.6:80 |
135 | pcap | raw alerts ruleset |
irc 132 lines |
Yeah : 1.8 profile |
none | summary tarball |
32 of 33 29 of 33 |
87e1117f2a NEW b4fe4581c3 NEW |
3ff643aae6 [0] 599b835896[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:08:08:00 | WinXP | 4.246.209.177 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, FRESNO, CALIFORNIA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 211 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | 73f1082158 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:08:33:00 | WinXP | 4.152.180.208 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, NASHVILLE, TENNESSEE, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 234 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | 73f1082158 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:09:24:00 | Win2K-f | 96.53.230.19 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 1008 lines |
Yeah : 1.3 profile |
none | summary tarball |
15 of 41 | 770a04a72c NEW |
none[3] | none:none |
none|none | none | trace | |
T:10:27:00 | WinXP | 116.125.9.108 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR. |
221.5.74.39:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:put.ghura.pl IL:xt67ur.wwlax.com IL:bugreport.waverevenue.com IL:xul93.pubdomainstr.com CN:brenz.pl IL:rec.bestrevenue.net US:b152.bundlext.com CN:211.95.79.6:80 IL:62.90.134.29:80 |
135 | pcap | raw alerts ruleset |
irc http 152 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 30 of 33 13 of 41 31 of 33 |
6648e7022b NEW 87bd0a062f NEW 9857a367e2 NEW c7d6018f97 NEW |
0ad0f97bcc [0] dc70d9623a[0] 8d4e5ce4de[0] 5c1d8bbd5b[0] |
none:none none:none none:none none:none |
UPX| Armadillo| ASProtect| tElock| |
none none none none |
trace trace trace trace |
T:10:33:00 | Win2K-f | 61.218.193.250 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:21:00 | WinXP | 151.81.56.238 (38-151.NET24.IT): IUNET-BNET, IT. |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:11:38:00 | WinXP | 202.137.123.133 (DCTECH.COM.PH): DCTECH MICRO SERVICES INC, PH. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:42:00 | Win2K-f | 70.183.161.253 (COX.NET): COX COMMUNICATIONS, WOONSOCKET, RHODE ISLAND, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 89 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 33 of 33 |
36d16c0a7b NEW 53bfe15e91 NEW |
5438f81d23 [0] 1473091351[0] |
none:none ASM:Graph |
Armadillo| tElock| |
none lines=75 embedded dns |
trace trace |
T:11:51:00 | Win2K-f | 173.21.231.50 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:54:00 | WinXP | 124.123.81.223 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:12:02:00 | Win2K-f | 189.119.216.163 (-): . |
n/a | CZ:qtas.net | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
16 of 38 | d5360662f2 NEW |
058308c0f7 [0] | none:none |
none|none | none | trace |
T:12:32:00 | Win2K-f | 4.161.144.245 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, CINCINNATI, OHIO, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 155 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:46:00 | WinXP | 63.17.217.44 (UU.NET): UUNET TECHNOLOGIES INC, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 147 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:13:01:00 | WinXP | 208.105.186.90 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:13:25:00 | WinXP | 72.251.75.252 (1DIAL.COM): AD-BASE SYSTEMS INC. (DBA GLOBALPOPS), PITTSBURGH, PENNSYLVANIA, US. (DIAL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 3b569cd1c6 NEW |
a81c9e968a [0] | none:none |
PolyEnE| | none | trace |
T:15:24:00 | Win2K-f | 4.156.72.168 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, BOSTON, MASSACHUSETTS, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:16:23:00 | WinXP | 122.30.226.189 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:17:32:00 | WinXP | 67.58.145.43 (MINDSPRING.COM): EARTHLINK INC, HONOLULU, HAWAII, US. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 3ae357d17b NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:17:49:00 | WinXP | 70.247.165.191 (SWBELL.NET): PPPOX POOL - BRAS17 RCSNTX, FT. WORTH, TEXAS, US. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:18:03:00 | Win2K-f | 69.19.183.192 (O1.COM): O1 DIALUP SERVICES, SANTA ANA, CALIFORNIA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:08:00 | WinXP | 99.34.236.15 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:17:00 | WinXP | 79.178.19.193 (BEZEQINT.NET): ADSL-CUSTOMER-CONNECTION, IL. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | none:none |
PolyEnE| | none | trace |
18:37:00 | WinXP | 79.178.19.193 (BEZEQINT.NET): ADSL-CUSTOMER-CONNECTION, IL. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | none:none |
PolyEnE| | none | trace |
T:19:02:00 | WinXP | 209.250.50.4 (WISPNET.NET): WISPNET LLC, PADUCAH, KENTUCKY, US. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 0b0f371be8 NEW |
330a08d34f [0] | none:none |
PolyEnE| | none | trace |
T:19:11:00 | WinXP | 166.230.7.67 (MYVZW.COM): SERVICE PROVIDER CORPORATION, BEDMINSTER, NEW JERSEY, US. |
n/a | 445 | pcap | raw alerts ruleset |
other 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:20:56:00 | Win2K-f | 117.242.80.13 (-): . |
n/a | CZ:qtas.net | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
16 of 38 | d5360662f2 NEW |
058308c0f7 [0] | none:none |
none|none | none | trace |
T:21:09:00 | WinXP | 71.111.196.150 (VERIZON.NET): VERIZON INTERNET SERVICES INC, DURHAM, NORTH CAROLINA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:23:00 | WinXP | 99.181.225.242 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:21:37:00 | WinXP | 66.63.109.240 (GWI.NET): GREAT WORKS INTERNET, SHAPLEIGH, MAINE, US. |
61.120.62.28:3305 | GB:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 695 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:22:18:00 | WinXP | 41.202.179.165 (-): . |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 0505ea7e51 NEW |
6fde8a0b6c [0] | none:none |
PolyEnE| | none | trace |
T:22:40:00 | WinXP | 117.61.127.219 (163DATA.COM.CN): CHINANET JIANGSU PROVINCE NETWORK, BEIJING, BEIJING, CN. |
221.5.74.39:65520 | CN:proxim.ircgalaxy.pl CN:put.ghura.pl IL:xt67ur.wwlax.com IL:bugreport.waverevenue.com IL:xul93.pubdomainstr.com CN:brenz.pl IL:rec.bestrevenue.net US:b156.bundlext.com IL:ftp6.spirograd.com IL:digi-fast.com CN:211.95.79.6:80 IL:212.150.130.183:80 |
445 | pcap | raw alerts ruleset |
http irc 25 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 15 of 41 28 of 41 27 of 41 35 of 41 26 of 40 |
0658d04f28 NEW 298243013a NEW 6648e7022b NEW 6f8772fb4c NEW 9fa31ab3b7 NEW b6d8c740ba NEW |
07f788a60e [0] b8c969e769[0] 0ad0f97bcc[0] 72c4861af2[0] 9216033ec0[0] 2f4bf683ce[0] |
none:none none:none none:none none:none none:none none:none |
PolyEnE| PEQuake| UPX| UPX| StarForce| Crypto-Lo| |
none none none none none none |
trace trace trace trace trace trace |
T:22:41:00 | WinXP | 76.93.205.122 (-): . |
n/a | EU:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com GB:welcome3.smile.co.uk :wpad GB:195.92.84.198:80 |
445 | pcap | raw alerts ruleset |
http http http 20 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:23:38:00 | Win2K-f | 24.84.201.131 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SURREY, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 157 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | 51a03793ab NEW |
429f7618d3 [0] | none:none |
none|none | none | trace | |
T:23:39:00 | WinXP | 119.230.94.64 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | 03f912899b NEW |
none[0] | none:none |
none|none | lines=64 | trace | |
T:23:53:00 | WinXP | 217.12.84.82 (BCC.COM.UZ): ISP AMALIY ALOQALAR BIZNESI LTD, TASHKENT, TOSHKENT, UZ. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace |