Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:37:00 | WinXP | 72.215.32.113 (COX.NET): COX COMMUNICATIONS, NICEVILLE, FLORIDA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:01:24:00 | WinXP | 69.193.74.22 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:21:00 | WinXP | 96.8.219.143 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:50:00 | WinXP | 71.113.142.8 (VERIZON.NET): VERIZON INTERNET SERVICES INC, BLOOMINGTON, ILLINOIS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:05:14:00 | Win2K-f | 116.58.157.246 (CCNETMIE.NE.JP): C-TECH CORPORATION, NAGOYA, AICHI, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=75 embedded dns |
trace trace |
T:06:16:00 | WinXP | 62.11.32.192 (DIALUP.TISCALI.IT): TISCALI ITALIA SPA, NAPOLI, CAMPANIA, IT. (DIAL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :wpad DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http http 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee NEW |
none[0] | none:none |
ASPack| | lines=298 embedded dns |
trace |
T:06:17:00 | WinXP | 119.154.45.57 (-): . |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 | d27d2ee48f NEW |
ce4aee2c76 [0] | none:none |
PolyEnE| | none | trace |
T:07:03:00 | WinXP | 99.188.105.71 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:08:22:00 | Win2K-f | 172.132.218.47 (AOL.COM): AMERICA ONLINE, RESTON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 128 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:08:36:00 | WinXP | 216.195.145.127 (GWI.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 180 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:08:40:00 | Win2K-f | 98.141.9.117 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:08:54:00 | WinXP | 202.163.161.30 (TCNET.NE.JP): TONAMI INTERNET SERVICE(TONAMI TRANSPORTATIONCO. LTD.), JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 57ef739a9e NEW |
fbdf9f6053 [0] | none:none |
none|none | none | trace | |
T:09:00:00 | Win2K-f | 76.89.195.193 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:10:33:00 | WinXP | 4.154.222.104 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, WORCESTER, MASSACHUSETTS, US. (DIAL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com GB:new.egg.com :wpad |
445 | pcap | raw alerts ruleset |
http http http http 44 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:11:29:00 | WinXP | 155.239.165.136 (TELKOM-IPNET.CO.ZA): AFRINIC, ZA. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 | cdbb312d0a NEW |
8050e5ba3e [0] | none:none |
PolyEnE| | none | trace |
T:11:51:00 | Win2K-f | 208.125.40.153 (RR.COM): ROAD RUNNER HOLDCO LLC, BINGHAMTON, NEW YORK, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:56:00 | WinXP | 72.215.42.73 (COX.NET): COX COMMUNICATIONS, ATLANTA, GEORGIA, US. |
218.93.205.24:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:brenz.pl :lometr.pl CN:211.95.79.6:80 |
135 | pcap | raw alerts ruleset |
irc http 143 lines |
Yeah : 1.8 profile |
none | summary tarball |
24 of 41 32 of 36 35 of 36 |
9763a85494 NEW bea8cb1865 NEW fac78fde16 NEW |
ca705de7c9 [0] 154de51a66[0] 882896ab05[0] |
none:none ASM:Graph none:none |
none|none Armadillo| tElock| |
none lines=91 none |
trace trace trace |
T:12:21:00 | WinXP | 96.8.164.132 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:46:00 | WinXP | 83.2.21.88 (NET.PL): P.W. MARTON MARIUSZ TRABCZYNSKI, PL. |
n/a | CN:proxim.ircgalaxy.pl RU:citi-bank.ru RU:213.219.245.212:80 CN:221.5.74.39:65520 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 36 | 9bb68450cd NEW |
c2d5ac2315 [0] | ASM:Graph |
PolyEnE| | lines=73 embedded dns |
trace |
T:13:36:00 | WinXP | 4.234.0.98 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, MIAMI, FLORIDA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1082 lines |
Yeah : 1.3 profile |
none | summary tarball |
6 of 41 | 4e5cff21e2 NEW |
none[3] | none:none |
none|none | none | trace | |
T:13:50:00 | WinXP | 76.83.54.32 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. |
n/a | EU:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com GB:new.egg.com :wpad |
445 | pcap | raw alerts ruleset |
http http http http 52 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 0ada72d805 NEW |
none[0] | ASM:Graph |
ASPack| | lines=281 embedded dns |
trace |
T:14:10:00 | WinXP | 79.132.200.27 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
82.98.86.170:80 | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com DE:ebookfinaltrash.ru :wpad |
445 | pcap | raw alerts ruleset |
http http http http http 31 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 41 | 6c8201441b NEW |
none[4] | none:none |
ASPack| | none | trace |
T:14:36:00 | WinXP | 81.131.12.143 (BTOPENWORLD.COM): BT-WEBPORT, LONDON, ENGLAND, UK. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:14:39:00 | Win2K-f | 68.147.215.96 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 39 of 40 |
4e4d92141d NEW 74054e91dc NEW |
3f24d7d801 [0] 1944368470[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:14:44:00 | WinXP | 4.137.199.227 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, CHARLOTTE, NORTH CAROLINA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 180 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:15:04:00 | Win2K-f | 24.227.252.23 (RR.COM): ROAD RUNNER HOLDCO LLC, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:15:42:00 | WinXP | 60.249.37.247 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 38 35 of 38 |
38ed850a0e NEW b9297745a1 NEW |
46990f37cd [0] 4294884d84[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
17:30:00 | WinXP | 123.195.200.84 (ETHOME.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 35 | 9716d7995a NEW |
c3a5354b6f [0] | none:none |
PolyEnE| | none | trace |
T:17:39:00 | WinXP | 125.58.120.87 (-): . |
n/a | JP:cx10man.weedns.com JP:fx010413.whyI.org AR:gynoman.weedns.com JP:61.120.62.28:3305 |
135 | pcap | raw alerts ruleset |
irc 572 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 | 70ec5c4b3f NEW |
f697adabdd [0] | none:none |
StarForce| | none | trace |
T:17:46:00 | Win2K-f | 4.254.225.232 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, CALDWELL, IDAHO, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:36:00 | WinXP | 173.29.243.154 (-): . |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:19:01:00 | WinXP | 66.217.100.65 (USLEC.NET): USLEC CORP, MIAMI, FLORIDA, US. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 | ad73e89fb8 NEW |
none[4] | none:none |
none|none | none | trace | |
19:09:00 | Win2K-f | 212.1.226.115 (TI.RU): INTERNAL INFRASTRUCTURE, RU. |
n/a | US:www.maxmind.com :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | 223d8089f8 NEW |
none[3] | none:none |
StarForce| | none | trace |
T:20:06:00 | Win2K-f | 208.84.169.56 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 41 |
311050e152 NEW 3569154ead NEW |
a2a034e6b7 [0] 491aa22d23[0] |
none:none none:none |
tElock| tElock| |
none none |
trace trace |
T:21:21:00 | Win2K-f | 209.250.154.9 (PATHCOM.COM): PATHWAY COMMUNICATIONS, TORONTO, ONTARIO, CA. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 161 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:59:00 | WinXP | 66.50.4.102 (PRTC.NET): PRTC RAS, SAN JUAN, PUERTO RICO, PR. |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
35 of 36 | b27d73bfcb NEW |
473c6454ce [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:22:11:00 | WinXP | 63.25.116.133 (UU.NET): UUNET TECHNOLOGIES INC, SHERMAN, TEXAS, US. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | eda3b7766c NEW |
7556343561 [0] | none:none |
PolyEnE| | none | trace |
T:23:05:00 | WinXP | 93.81.35.112 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:23:33:00 | Win2K-f | 98.141.9.117 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:23:44:00 | Win2K-f | 4.176.75.207 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, ALBUQUERQUE, NEW MEXICO, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 189 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |