Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:02:22:00 | WinXP | 4.227.240.43 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, PARKER, COLORADO, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 97 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:01:00 | Win2K-f | 114.206.63.153 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 100 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | d69be65220 NEW |
16d65fd6e9 [0] | none:none |
Armadillo| | none | trace | |
T:03:46:00 | Win2K-f | 124.195.155.251 (-): . |
61.120.62.28:3305 | :cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 577 lines |
Yeah : 1.8 profile |
none | summary tarball |
37 of 41 | aafd96fe57 NEW |
9d4029abac [0] | none:none |
StarForce| | none | trace |
T:03:46:00 | WinXP | 74.75.26.41 (RR.COM): ROAD RUNNER HOLDCO LLC, PITTSFIELD, MASSACHUSETTS, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 33 of 33 |
4c3df24b32 NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=75 embedded dns |
trace trace |
T:03:48:00 | WinXP | 67.246.220.245 (-): . |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:05:13:00 | WinXP | 4.224.186.68 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:06:46:00 | WinXP | 211.211.74.109 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
221.5.74.39:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:brenz.pl CN:211.95.79.6:80 |
135 | pcap | raw alerts ruleset |
irc 140 lines |
Yeah : 1.8 profile |
none | summary tarball |
30 of 33 28 of 33 |
533d15b5ce NEW 58c343a8d8 NEW |
c67adf46e2 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=126 embedded dns lines=91 |
trace trace |
T:06:56:00 | Win2K-f | 172.130.117.116 (AOL.COM): AMERICA ONLINE, RESTON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
07:13:00 | Win2K-f | 189.109.26.140 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:07:29:00 | WinXP | 77.20.11.78 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 4530fc0b7f NEW |
1ce549df2a [0] | none:none |
none|none | none | trace | |
T:08:06:00 | WinXP | 91.82.63.158 (-): BOLY POLGARMESTERI HIVATAL, HU. |
n/a | EU:gaz-prom.ru | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 7623c942a9 NEW |
1e7e1e0e5d [0] | none:none |
tElock| | none | trace |
T:09:12:00 | WinXP | 203.73.57.32 (SEED.NET.TW): DIGITAL UNITED INC, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | e70e195b77 NEW |
3d277747d3 [0] | none:none |
PolyEnE| | none | trace |
T:09:36:00 | WinXP | 210.79.180.35 (MEDIATTI.NET): MEDIATTI COMMUNICATIONS INC, OKINAWA, OKINAWA, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 87 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 33 33 of 33 |
3ed16ae12d NEW 79c01ec060 NEW |
none[0] 1bfd34056c[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=64 embedded dns |
trace trace |
T:10:18:00 | WinXP | 125.58.94.139 (-): . |
61.120.62.28:3305 | :cx10man.weedns.com GB:fx010413.whyI.org NL:gynoman.weedns.com JP:61.120.62.28:3305 |
135 | pcap | raw alerts ruleset |
irc 603 lines |
Yeah : 1.8 profile |
none | summary tarball |
none | dba298277c NEW |
e499a208a6 [0] | none:none |
StarForce| | none | trace |
T:10:56:00 | WinXP | 64.130.169.218 (SCRTC.COM): SOUTH CENTRAL RURAL TELEPHONE CO, SAN JOSE, CALIFORNIA, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 119ec42aa0 NEW |
fd3c61c261 [0] | none:none |
PolyEnE| | none | trace |
T:11:23:00 | Win2K-f | 174.1.105.102 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:49:00 | WinXP | 75.44.50.124 (SBCGLOBAL.NET): RBACK6B.MILWWI.20060913, MILWAUKEE, WISCONSIN, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | 03f912899b NEW |
none[0] | none:none |
none|none | lines=64 | trace | |
T:12:27:00 | WinXP | 63.28.60.30 (UU.NET): UUNET TECHNOLOGIES INC, CHICAGO, ILLINOIS, US. |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com GB:new.egg.com :wpad |
445 | pcap | raw alerts ruleset |
http http http http 52 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:12:49:00 | WinXP | 118.231.6.99 (-): . |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
33 of 36 | d61760f6a1 NEW |
22542b9b5e [0] | none:none |
PolyEnE| | none | trace |
T:13:47:00 | WinXP | 59.103.11.8 (-): . |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:14:17:00 | WinXP | 24.103.196.250 (-): . |
67.43.236.67:10324 | CA:xx.nadnadzz.info CA:xx.ka3ek.com :nadsamcabran12.com CA:67.43.236.67:10324 |
135 | pcap | raw alerts ruleset |
irc http 343 lines |
Yeah : 1.8 profile |
none | summary tarball |
25 of 41 32 of 38 37 of 40 |
47d76e8dce NEW 524bc0f75c NEW a0a15f5ebf NEW |
457779e597 [0] d3e9510bb3[0] c506c7cc86[0] |
none:none none:none none:none |
Neolite| PENinja S| Mew| |
none none none |
trace trace trace |
T:14:40:00 | WinXP | 93.102.74.82 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | :www.google.com.au US:www.yahoo.com :jbeegvia.ru EU:crutop.nu US:www.worldbank.org :yoiayoi.ru :wcqahzhzn.ru :iirpryry.ru :rihafvu.ru :wpad :ryryodokm.ru :uvjiis.ru :gwvwka.ru :jqsbnyzkp.ru :pvygdo.ru :fxkyagpnw.ru :knclvdz.ru :trsqeigw.ru :odokeqy.ru :kelmpsjp.ru :edjiesp.ru :vllcdvv.ru :nuksdln.ru :tmmeno.ru :zoxdgqx.ru :pwvbfz.ru :nuzbcp.ru :bqpuqt.ru DE:kavkaz.co.uk |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 17028f1eda NEW |
none[3] | none:none |
tElock| | none | trace |
T:14:42:00 | Win2K-f | 118.87.18.132 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 122 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 36 34 of 36 |
0b951c2832 NEW e4ed4df0f0 NEW |
5fe761661a [0] de471fc380[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:15:12:00 | WinXP | 64.126.174.205 (FSR.NET): FIRST STEP INTERNET, MOSCOW, IDAHO, US. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 36 | 6b3beaea1a NEW |
154f174df6 [0] | none:none |
PolyEnE| | none | trace |
T:15:16:00 | WinXP | 217.203.208.175 (-): TELECOM ITALIA MOBILE, IT. |
n/a | US:www.yahoo.com US:www.altavista.com :jbeegvia.ru SE:www.kavkazcenter.com US:www.worldbank.org :yoiayoi.ru :wcqahzhzn.ru :iirpryry.ru :rihafvu.ru :ryryodokm.ru :uvjiis.ru :wpad :gwvwka.ru :jqsbnyzkp.ru :pvygdo.ru :fxkyagpnw.ru :knclvdz.ru :trsqeigw.ru :odokeqy.ru :kelmpsjp.ru :edjiesp.ru :vllcdvv.ru :nuksdln.ru :tmmeno.ru :zoxdgqx.ru :pwvbfz.ru :nuzbcp.ru :bqpuqt.ru :okskyyn.ru :pnlkria.ru :kargai.ru RU:prodexteam.net :kfwfceki.ru :nhuwxyuw.ru RU:alfabank.ru :udluzuq.ru :fiazpvnne.ru :ppxuub.ru :lvwgdhwlj.ru :raxeqajrf.ru GB:www.candidateverifier.com :crime-research.ru :dhagunb.ru :zpwmktjv.ru :aadqca.ru :ygnrqi.ru RU:www.cbr.ru :ycgnbe.ru :yeqsuem.ru :aiizkak.ru :dupeloz.ru :dodgscv.ru RU:www.mmbank.ru :lodrzze.ru :nkuoonxuz.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 17028f1eda NEW |
none[3] | none:none |
tElock| | none | trace |
T:16:18:00 | WinXP | 96.225.81.54 (VERIZON.NET): VERIZON INTERNET SERVICES INC, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:26:00 | WinXP | 68.203.231.61 (RR.COM): ROAD RUNNER HOLDCO LLC, ORANGE, TEXAS, US. |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | none:none |
PolyEnE| | none | trace | |
16:55:00 | WinXP | 68.203.231.61 (RR.COM): ROAD RUNNER HOLDCO LLC, ORANGE, TEXAS, US. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | none:none |
PolyEnE| | none | trace |
T:16:57:00 | WinXP | 114.48.34.210 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:17:13:00 | WinXP | 76.175.123.142 (RR.COM): ROAD RUNNER HOLDCO LLC, CHINO HILLS, CALIFORNIA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 1008 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 0f8abb24d9 NEW |
none[3] | none:none |
none|none | none | trace | |
T:17:35:00 | WinXP | 24.143.242.247 (SANBRUNOCABLE.COM): SAN BRUNO CABLE, CONWAY, ARKANSAS, US. (DSL) |
n/a | EU:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :wpad |
445 | pcap | raw alerts ruleset |
http http http 16 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee NEW |
none[0] | none:none |
ASPack| | lines=298 embedded dns |
trace |
T:18:21:00 | Win2K-f | 63.21.55.188 (UU.NET): UUNET TECHNOLOGIES INC, LOUISVILLE, KENTUCKY, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 150 lines |
Yeah : 1.3 profile |
none | summary tarball |
none 33 of 33 |
32426281df NEW 53bfe15e91 NEW |
f932394e48 [0] 1473091351[0] |
none:none ASM:Graph |
Armadillo| tElock| |
none lines=75 embedded dns |
trace trace |
18:25:00 | WinXP | 58.122.92.84 (HANANET.NET): HANARO TELECOM INC, KR. |
221.5.74.39:65520 | CN:brenz.pl CN:lometr.pl CN:www.upononjob.cn :horobl.cn 67.215.233.58:3088 |
139 | pcap | raw alerts ruleset |
irc http 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
19 of 41 none |
176f4e0237 NEW 852eec7620 NEW |
971b66b4c6 [0] af9f5e5446[0] |
none:none none:none |
none|none none|none |
none none |
trace trace |
T:19:52:00 | Win2K-f | 70.182.172.62 (COX.NET): COX COMMUNICATIONS, ATLANTA, GEORGIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:15:00 | Win2K-f | 71.112.121.42 (VERIZON.NET): VERIZON INTERNET SERVICES INC, BOTHELL, WASHINGTON, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1007 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 382bc4ac64 NEW |
none[3] | none:none |
none|none | none | trace | |
T:20:23:00 | Win2K-f | 98.141.17.72 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:20:31:00 | Win2K-f | 96.49.243.172 (-): . |
61.120.62.28:3305 | DE:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 696 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:20:35:00 | WinXP | 114.48.12.67 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
21:21:00 | Win2K-f | 66.90.104.50 (MM-NEWS.NET): FDC SERVERS.NET LLC, RALEIGH, NORTH CAROLINA, US. |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:21:30:00 | Win2K-f | 66.90.104.50 (MM-NEWS.NET): FDC SERVERS.NET LLC, RALEIGH, NORTH CAROLINA, US. |
n/a | US:www.maxmind.com US:checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:21:48:00 | WinXP | 4.247.152.112 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, ST. PETERSBURG, FLORIDA, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 19 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:22:14:00 | WinXP | 196.211.36.36 (TELKOM-IPNET.CO.ZA): AFRINIC, ZA. |
n/a | 135 | pcap | raw alerts ruleset |
other 576 lines |
Yeah : 1.3 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace | |
T:22:48:00 | Win2K-f | 218.210.65.21 (SPARQNET.NET): NEW CENTURY INFOCOMM TECH CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:48:00 | WinXP | 65.34.30.26 (RR.COM): ROAD RUNNER HOLDCO LLC, ORLANDO, FLORIDA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:23:17:00 | WinXP | 218.220.156.22 (ZAQ.NE.JP): HIGASHI-OSAKA CABLE TELEVISION CO. LTD, OSAKA, OSAKA, JP. |
61.120.62.28:3305 | GB:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 696 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:23:33:00 | WinXP | 76.93.204.52 (-): . |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | e321efdb3f NEW |
97101a3473 [0] | none:none |
PolyEnE| | none | trace |
23:34:00 | WinXP | 202.179.239.82 (CABLENET.NE.JP): CABLENET SAITAMA CO. LTD, JP. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 198 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 8a0ba42477 NEW |
none[4] | none:none |
PolyEnE| | none | trace |