Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:36:00 | WinXP | 69.85.115.201 (SPEAKEASY.NET): US. |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:03:07:00 | Win2K-f | 110.11.244.233 (-): . |
221.5.74.39:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:put.ghura.pl CN:brenz.pl CN:lometr.pl :onuka.cn CN:www.upononjob.cn :horobl.cn :fireasseye.com **:fuckbriankrebs.com :antisgetout.cn CN:211.95.79.6:80 US:69.162.108.98:80 US:69.162.65.170:80 75.125.238.10:80 92.62.101.118:80 |
135 | pcap | raw alerts ruleset |
irc http 136 lines |
Yeah : 1.8 profile |
none | summary tarball |
19 of 41 7 of 41 12 of 40 29 of 32 28 of 32 14 of 41 26 of 40 |
176f4e0237 NEW 18dfbbc85b NEW 852eec7620 NEW 8a75955033 NEW 9276c8b36b NEW a036b3aec2 NEW c45791e7da NEW |
971b66b4c6 [0] 4f6fcecea3[0] af9f5e5446[0] 2bf3e548b9[0] none [0] none [4] 2ed7e526e3[0] |
none:none none:none none:none ASM:Graph ASM:Graph none:none none:none |
none|none UPX| none|none tElock| Armadillo| none|none Armadillo| |
none none none lines=126 embedded dns lines=81 none none |
trace trace trace trace trace trace trace |
T:03:47:00 | WinXP | 188.129.155.210 (DAVITA.COM): VARIOUS REGISTRIES, UK. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 | 74b3d149e8 NEW |
cef0fa2981 [0] | none:none |
PolyEnE| | none | trace |
T:03:58:00 | WinXP | 93.102.77.193 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | :www.google.com.au US:www.altavista.com :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 17028f1eda NEW |
none[3] | none:none |
tElock| | none | trace |
T:05:04:00 | WinXP | 89.111.226.235 (TEOL.NET): TELEKOMSRPSKE, BA. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | f54691063f NEW |
6039c698cd [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:05:36:00 | WinXP | 190.108.146.247 (-): . |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:05:46:00 | WinXP | 83.185.22.198 (SWIP.NET): SWIPNET, SE. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 924746aba0 NEW |
629aee0783 [0] | none:none |
PolyEnE| | none | trace |
T:07:02:00 | Win2K-f | 118.221.23.98 (-): . |
218.93.205.24:65520 | US:microsoft.com CN:proxim.ircgalaxy.pl CN:put.ghura.pl CN:brenz.pl CN:lometr.pl :onuka.cn |
135 | pcap | raw alerts ruleset |
irc http 166 lines |
Yeah : 1.8 profile |
none | summary tarball |
19 of 41 7 of 41 38 of 40 12 of 40 26 of 41 38 of 40 |
176f4e0237 NEW 18dfbbc85b NEW 66863cfb13 NEW 852eec7620 NEW c626de3159 NEW e8dfca0741 NEW |
971b66b4c6 [0] 4f6fcecea3[0] fca240f318[0] af9f5e5446[0] 3f9ce515b4[0] 20dfd2147c[0] |
none:none none:none none:none none:none none:none none:none |
none|none UPX| Armadillo| none|none Armadillo| tElock| |
none none none none none none |
trace trace trace trace trace trace |
T:07:16:00 | WinXP | 217.68.189.84 (PRIMACOM.NET): PRIMACOM-HEADENDS, LEIPZIG, SACHSEN, DE. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | c05290bb06 NEW |
dddfe6a7fe [0] | none:none |
PolyEnE| | none | trace |
T:07:19:00 | Win2K-f | 59.117.173.218 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
218.93.205.24:65520 | CN:proxim.ircgalaxy.pl CN:put.ghura.pl CN:brenz.pl CN:lometr.pl :fireasseye.com **:fuckbriankrebs.com :antisgetout.cn US:69.162.108.98:80 US:69.162.65.170:80 75.125.238.10:80 92.62.101.118:80 |
445 | pcap | raw alerts ruleset |
irc http 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
19 of 41 14 of 41 16 of 41 |
176f4e0237 NEW a036b3aec2 NEW e5176f95e0 NEW |
971b66b4c6 [0] none [4] none [4] |
none:none none:none none:none |
none|none none|none StarForce| |
none none none |
trace trace trace |
T:07:35:00 | WinXP | 70.125.102.19 (RR.COM): ROAD RUNNER HOLDCO LLC, TAMPA, FLORIDA, US. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 109188d5f8 NEW |
aa7be7c5d9 [0] | none:none |
PolyEnE| | none | trace |
T:07:45:00 | WinXP | 220.208.149.113 (CORALNET.OR.JP): TONAMI TRANSPORTATION CO. LTD, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 57ef739a9e NEW |
fbdf9f6053 [0] | none:none |
none|none | none | trace | |
T:08:21:00 | WinXP | 151.60.127.196 (38-151.NET24.IT): IUNET-BNET, IT. |
n/a | EU:siliconfireware.ru :www.proxy-socks.net :wpad US:searchportal.information.com US:spi.domainsponsor.com DE:212.227.111.29:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http http 11 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 281e0dd6cf NEW |
ffde7291bd [0] | none:none |
ASPack| | none | trace |
T:08:40:00 | WinXP | 216.106.105.71 (STORM.CA): STORM INTERNET SERVICES, PERTH, ONTARIO, CA. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 36 | a4b61fe43f NEW |
826d45a568 [0] | none:none |
PolyEnE| | none | trace |
T:10:08:00 | WinXP | 75.177.14.9 (RR.COM): ROAD RUNNER HOLDCO LLC, GREENSBORO, NORTH CAROLINA, US. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:11:30:00 | WinXP | 4.162.240.101 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 212 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 41 39 of 41 |
4c696b083f NEW a8389c6a05 NEW |
5c0a6cbd1c [0] 3a30c37d4f[0] |
none:none none:none |
tElock| tElock| |
none none |
trace trace |
|
T:14:32:00 | Win2K-f | 96.10.95.90 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:08:00 | Win2K-f | 72.191.0.106 (RR.COM): ROAD RUNNER HOLDCO LLC, SAN ANTONIO, TEXAS, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:38:00 | Win2K-f | 72.64.30.16 (VERIZON.NET): VERIZON INTERNET SERVICES INC, CHARLESTON, WEST VIRGINIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:59:00 | Win2K-f | 172.165.43.84 (AOL.COM): AMERICA ONLINE, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:17:05:00 | WinXP | 206.169.143.219 (-): TIME WARNER TELECOM INC, ZIHUATANEJO, GUERRERO, MX. |
n/a | CN:sys.zief.pl RU:citi-bank.ru CN:218.93.205.24:65520 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
30 of 41 | 78c5ae9bf8 NEW |
e4d8d9e239 [0] | none:none |
PolyEnE| | none | trace |
T:17:17:00 | WinXP | 62.63.208.127 (TYFON.SE): TYFON SVENSKA AB, SE. |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | d175bad0e6 NEW |
none[0] | ASM:Graph |
tElock| | lines=81 embedded dns |
trace |
T:17:47:00 | WinXP | 24.234.108.27 (COX.NET): COX COMMUNICATIONS INC, LAS VEGAS, NEVADA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:19:25:00 | WinXP | 74.214.47.11 (METROCAST.NET): GMP CABLE TV, BERWICK, PENNSYLVANIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:34:00 | Win2K-f | 24.213.224.238 (RR.COM): ROAD RUNNER HOLDCO LLC, AMSTERDAM, NEW YORK, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:59:00 | WinXP | 203.221.126.87 (COMINDICO.COM.AU): COMINDICO AUSTRALIA, PERTH, WESTERN AUSTRALIA, AU. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
21:04:00 | Win2K-f | 113.252.183.125 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org US:getmyip.co.uk :checkip.dyndns.org US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:21:13:00 | Win2K-f | 113.252.183.125 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:21:34:00 | WinXP | 112.110.112.32 (-): . |
213.219.245.212:80 | CN:proxim.ircgalaxy.pl RU:citi-bank.ru CN:221.5.74.39:65520 |
445 | pcap | raw alerts ruleset |
http irc 5 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 36 | 9bb68450cd NEW |
c2d5ac2315 [0] | ASM:Graph |
PolyEnE| | lines=73 embedded dns |
trace |
T:22:00:00 | WinXP | 96.49.41.70 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 36 of 41 |
62e5ae233d NEW a214274930 NEW |
958d6fa77d [0] a281c0c12a[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:22:14:00 | Win2K-f | 70.234.0.67 (VCWEB.ORG): PALOMAR BROADBAND CORP, LOS ANGELES, CALIFORNIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:25:00 | Win2K-f | 4.140.204.131 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, WALTHAM, MASSACHUSETTS, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 86 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:31:00 | Win2K-f | 208.103.158.91 (CORETEL.NET): CORETEL AMERICA INC, ANNAPOLIS, MARYLAND, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 128 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |