Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:02:27:00 | WinXP | 203.136.81.173 (MESH.AD.JP): NEC CORPORATION, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | ASM:Graph |
none|none | lines=61 | trace | |
T:03:51:00 | WinXP | 4.251.126.94 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, FAIR LAWN, NEW JERSEY, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:04:00:00 | Win2K-f | 124.241.137.45 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, AICHI, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:05:43:00 | Win2K-f | 66.76.165.129 (COX-INTERNET.COM): SUDDENLINK COMMUNICATIONS, TYLER, TEXAS, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:06:14:00 | WinXP | 76.179.117.255 (RR.COM): ROAD RUNNER HOLDCO LLC, TUCSON, ARIZONA, US. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:06:44:00 | WinXP | 67.246.220.245 (-): . |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:06:49:00 | WinXP | 4.182.254.13 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, AUBURN, CALIFORNIA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 85 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
06:57:00 | Win2K-f | 118.232.55.90 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org US:getmyip.co.uk EU:checkip.dyndns.org US:65.254.39.170:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:07:43:00 | Win2K-f | 4.159.86.41 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, CLEVELAND, OHIO, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1006 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 40 | d6b30f250b NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace | |
T:08:22:00 | WinXP | 4.153.201.199 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, BIRMINGHAM, ALABAMA, US. (DIAL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com GB:welcome3.smile.co.uk :wpad GB:195.92.84.198:80 |
445 | pcap | raw alerts ruleset |
http http http 11 lines |
Yeah : 0.8 profile |
none | summary tarball |
32 of 41 | ea71d9bd68 NEW |
none[4] | none:none |
ASPack| | none | trace |
T:08:40:00 | Win2K-f | 120.138.143.182 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:09:31:00 | WinXP | 114.51.7.96 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:09:52:00 | Win2K-f | 67.150.85.147 (MDSG-PACWEST.COM): PAC-WEST MANAGED MODEM NAS POOL, LOS ANGELES, CALIFORNIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:10:03:00 | Win2K-f | 68.148.108.81 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, EDMONTON, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1008 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 41 | 682a384fe9 NEW |
none[3] | none:none |
none|none | none | trace | |
10:36:00 | WinXP | 79.40.180.182 (SRC.ORG): TELECOM ITALIA NET, ROME, LAZIO, IT. |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :www.proxy-socks.net :wpad |
445 | pcap | raw alerts ruleset |
http http http 27 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | ab46ec2f16 NEW |
bc5a7926df [0] | none:none |
ASPack| | none | trace |
T:11:31:00 | Win2K-f | 155.239.199.153 (TELKOM-IPNET.CO.ZA): AFRINIC, SOMERSET WEST, WESTERN CAPE, ZA. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 122 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:34:00 | WinXP | 116.59.150.208 (-): MOBILE BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:12:57:00 | Win2K-f | 24.244.181.90 (CABLEBAHAMAS.NET): CABLE BAHAMAS, NASSAU, NEW PROVIDENCE, BS. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:13:57:00 | WinXP | 118.231.6.194 (-): . |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
33 of 36 | d61760f6a1 NEW |
22542b9b5e [0] | none:none |
PolyEnE| | none | trace |
14:29:00 | WinXP | 93.102.35.106 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | US:www.yahoo.com :www.google.com.au :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 17028f1eda NEW |
none[3] | none:none |
tElock| | none | trace |
T:15:06:00 | WinXP | 66.66.248.162 (RR.COM): ROAD RUNNER HOLDCO LLC, SCHENECTADY, NEW YORK, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 60 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:15:24:00 | WinXP | 71.173.126.152 (VERIZON.NET): VERIZON INTERNET SERVICES INC, US. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:16:50:00 | WinXP | 4.153.200.229 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, BIRMINGHAM, ALABAMA, US. (DIAL) |
82.98.86.170:80 | EU:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com DE:ebookfinaltrash.ru :wpad GB:welcome3.smile.co.uk |
445 | pcap | raw alerts ruleset |
http http http http http 22 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 41 | d3fba5729c NEW |
none[4] | none:none |
ASPack| | none | trace |
T:16:50:00 | WinXP | 89.111.226.222 (TEOL.NET): TELEKOMSRPSKE, BA. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
17:42:00 | Win2K-f | 190.50.119.86 (COM.AR): TELEFONICA DE ARGENTINA, BUENOS AIRES, BUENOS AIRES, AR. |
n/a | US:www.maxmind.com :checkip.dyndns.org US:getmyip.co.uk US:www.getmyip.org US:65.254.39.170:80 US:67.15.94.80:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 37 | 4f88618d4f NEW |
none[3] | none:none |
UPX| | none | trace |
T:17:42:00 | WinXP | 98.141.161.39 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:17:50:00 | Win2K-f | 190.50.119.86 (COM.AR): TELEFONICA DE ARGENTINA, BUENOS AIRES, BUENOS AIRES, AR. |
n/a | US:www.maxmind.com :checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 37 | 4f88618d4f NEW |
none[3] | none:none |
UPX| | none | trace |
T:17:55:00 | Win2K-f | 72.215.32.113 (COX.NET): COX COMMUNICATIONS, NICEVILLE, FLORIDA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:46:00 | WinXP | 115.98.206.197 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:18:56:00 | Win2K-f | 70.71.27.132 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, NEW WESTMINSTER, BRITISH COLUMBIA, CA. (DSL) |
67.43.236.67:10324 | CA:xx.nadnadzz.info :nadsamcabran12.com 67.215.1.206:80 |
135 | pcap | raw alerts ruleset |
irc 386 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 41 | 2bb2053a1d NEW |
9cc02d240b [0] | none:none |
FSG| | none | trace |
T:19:07:00 | WinXP | 113.252.6.183 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 1002 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 41 | 7552be3fb7 NEW |
none[3] | none:none |
none|none | none | trace | |
T:19:13:00 | Win2K-f | 118.217.82.128 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
19:29:00 | Win2K-f | 202.95.74.56 (ALTER.NET): VERIZON COMMUNICATIONS, SG. (100Mbps) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:21:32:00 | WinXP | 4.229.105.24 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DETROIT, MICHIGAN, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 123 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:17:00 | WinXP | 61.215.140.128 (CABLENET.NE.JP): CABLENET SAITAMA CO. LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 394 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 33 | 954a98c971 NEW |
cdd769f7a4 [0] | none:none |
FSG| | none | trace | |
T:23:00:00 | WinXP | 74.214.47.11 (METROCAST.NET): GMP CABLE TV, BERWICK, PENNSYLVANIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |