Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:19:00 | WinXP | 58.235.121.27 (-): THRUNET-INFRA-BUSAN15, SEOUL, KYONGGI-DO, KR. |
221.5.74.39:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:brenz.pl CN:211.95.79.6:80 CN:221.5.74.39:65520 |
135 | pcap | raw alerts ruleset |
irc 137 lines |
Yeah : 1.8 profile |
none | summary tarball |
30 of 33 28 of 33 |
533d15b5ce NEW 58c343a8d8 NEW |
c67adf46e2 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=126 embedded dns lines=91 |
trace trace |
T:00:58:00 | WinXP | 173.16.240.41 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:01:40:00 | WinXP | 96.49.243.172 (-): . |
61.120.62.28:3305 | :cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 719 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:01:55:00 | WinXP | 82.11.213.158 (NTL.COM): NTL INFRASTRUCTURE - SWANSEA, UK. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
04:36:00 | Win2K-f | 58.38.156.238 (163DATA.COM.CN): CHINANET SHANGHAI PROVINCE NETWORK, SHANGHAI, SHANGHAI, CN. |
n/a | US:www.maxmind.com :checkip.dyndns.org US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | d60e538e72 NEW |
none[3] | none:none |
UPX| | none | trace |
T:04:39:00 | WinXP | 211.179.174.254 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
221.5.74.39:65520 | CN:proxima.ircgalaxy.pl US:microsoft.com CN:put.ghura.pl IL:xt67ur.wwlax.com IL:bugreport.waverevenue.com IL:xul93.pubdomainstr.com CN:brenz.pl CN:211.95.79.6:80 |
135 | pcap | raw alerts ruleset |
irc http 129 lines |
Yeah : 1.8 profile |
none | summary tarball |
31 of 33 28 of 41 31 of 33 27 of 41 |
168aab35a3 NEW 6648e7022b NEW 667f0c59f3 NEW 6f8772fb4c NEW |
60b730b97e [0] 0ad0f97bcc[0] 8fe2be2095[0] 72c4861af2[0] |
ASM:Graph none:none ASM:Graph none:none |
tElock| UPX| Armadillo| UPX| |
lines=120 embedded dns none lines=91 none |
trace trace trace trace |
T:06:11:00 | WinXP | 87.55.74.188 (IP.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, DK. |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | b26ed6eeac NEW |
97c1157bf8 [0] | none:none |
PolyEnE| | none | trace |
T:06:41:00 | Win2K-f | 211.206.225.229 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 33 of 33 |
4c3df24b32 NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=75 embedded dns |
trace trace |
T:09:12:00 | WinXP | 209.42.180.231 (WISPNET.NET): WISPNET LLC, WAYNESBURG, KENTUCKY, US. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:10:02:00 | WinXP | 65.26.51.101 (RR.COM): ROAD RUNNER HOLDCO LLC, KANSAS CITY, MISSOURI, US. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | f502585714 NEW |
none[0] | none:none |
PolyEnE| | lines=63 | trace |
T:10:26:00 | WinXP | 87.55.74.245 (IP.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, DK. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | b26ed6eeac NEW |
97c1157bf8 [0] | none:none |
PolyEnE| | none | trace |
T:10:27:00 | WinXP | 4.141.20.148 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, ROCHESTER, NEW YORK, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 187 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:10:34:00 | Win2K-f | 117.197.122.88 (-): . |
n/a | CZ:qtas.net | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
10 of 41 | fb20b4ed8d NEW |
5e44929940 [0] | none:none |
none|none | none | trace |
T:11:48:00 | Win2K-f | 58.236.167.90 (-): THRUNET-INFRA-INCHEON10, SEOUL, KYONGGI-DO, KR. |
221.5.74.39:65520 | CN:proxima.ircgalaxy.pl US:microsoft.com CN:put.ghura.pl IL:xt67ur.wwlax.com IL:bugreport.waverevenue.com IL:xul93.pubdomainstr.com CN:brenz.pl CN:lometr.pl IL:rec.bestrevenue.net US:b152.bundlext.com CN:221.5.74.39:65520 IL:62.90.134.24:80 |
135 | pcap | raw alerts ruleset |
irc http 126 lines |
Yeah : 1.8 profile |
none | summary tarball |
19 of 41 20 of 41 28 of 41 none 27 of 41 13 of 41 38 of 40 |
176f4e0237 NEW 466472e839 NEW 6648e7022b NEW 6a4845ca11 NEW 6f8772fb4c NEW 9857a367e2 NEW ffafd341d9 NEW |
971b66b4c6 [0] none [4] 0ad0f97bcc[0] c23d00870b[0] 72c4861af2[0] 8d4e5ce4de[0] 294fb27545[0] |
none:none none:none none:none none:none none:none none:none ASM:Graph |
none|none Mew| UPX| tElock| UPX| ASProtect| Armadillo| |
none none none none none none lines=91 |
trace trace trace trace trace trace trace |
T:11:57:00 | WinXP | 88.130.202.149 (VERSANETONLINE.DE): VERSATEL NORD-DEUTSCHLAND GMBH, DORTMUND, NORDRHEIN-WESTFALEN, DE. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:12:56:00 | WinXP | 66.252.84.229 (OMNICITY.NET): OMNICITY INC, INDIANAPOLIS, INDIANA, US. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 1fcc146d70 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:12:58:00 | WinXP | 83.185.23.8 (SWIP.NET): SWIPNET, SE. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 924746aba0 NEW |
629aee0783 [0] | none:none |
PolyEnE| | none | trace |
T:17:19:00 | WinXP | 211.135.44.181 (ZAQ.NE.JP): KEIHAN CABLE TELEVISION CO. LTD, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=75 embedded dns |
trace trace |
T:17:42:00 | Win2K-f | 124.241.189.71 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, AICHI, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:51:00 | WinXP | 66.66.248.162 (RR.COM): ROAD RUNNER HOLDCO LLC, SCHENECTADY, NEW YORK, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:19:14:00 | WinXP | 209.42.179.140 (WISPNET.NET): WISPNET LLC, PADUCAH, KENTUCKY, US. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 36 | b27d73bfcb NEW |
473c6454ce [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:19:18:00 | Win2K-f | 4.229.105.248 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DETROIT, MICHIGAN, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 79 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:39:00 | Win2K-f | 172.130.78.211 (AOL.COM): AMERICA ONLINE, RESTON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 78 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:42:00 | WinXP | 69.121.162.90 (OPTONLINE.NET): OPTIMUM ONLINE (CABLEVISION SYSTEMS), STRATFORD, CONNECTICUT, US. |
194.109.11.65:6556 194.109.11.65:1023 | NL:0x80.online-software.org | 135 | pcap | raw alerts ruleset |
other 270 lines |
Yeah : 1.8 profile |
none | summary tarball |
32 of 32 | 15d4d85dc0 NEW |
4c95ae4b3d [0] | ASM:Graph |
StarForce| | lines=212 embedded dns |
trace |
T:21:51:00 | Win2K-f | 71.111.195.57 (VERIZON.NET): VERIZON INTERNET SERVICES INC, DURHAM, NORTH CAROLINA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:57:00 | WinXP | 76.247.47.56 (PACBELL.NET): AT&T INTERNET SERVICES, US. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:22:32:00 | WinXP | 117.39.104.227 (163DATA.COM.CN): CHINANET SHANXI(SN) PROVINCE NETWORK, BEIJING, BEIJING, CN. |
213.219.245.212:80 | CN:proxim.ircgalaxy.pl RU:citi-bank.ru CN:218.93.205.24:65520 |
445 | pcap | raw alerts ruleset |
http irc 4 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 36 | 9bb68450cd NEW |
c2d5ac2315 [0] | ASM:Graph |
PolyEnE| | lines=73 embedded dns |
trace |
T:23:28:00 | WinXP | 124.241.188.252 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, AICHI, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 37 of 41 |
c7bb39ee2c NEW f49bcb46ba NEW |
07462a9c7b [0] ab0f851c9d[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |