Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:19:00 | WinXP | 70.44.36.215 (PTD.NET): PENTELEDATA INC. - CABLE, DINGMANS FERRY, PENNSYLVANIA, US. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 35 | 9716d7995a NEW |
c3a5354b6f [0] | none:none |
PolyEnE| | none | trace |
T:01:06:00 | WinXP | 86.154.232.84 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, SWANSEA, WALES, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | ASM:Graph |
none|none | lines=61 | trace | |
T:01:39:00 | WinXP | 70.71.239.225 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SURREY, BRITISH COLUMBIA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 223 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 38 of 41 |
4180c19d91 NEW b6e91e001c NEW |
9f3f2de385 [0] d2275a6cf5[0] |
none:none none:none |
Armadillo| PolyEnE| |
none none |
trace trace |
T:02:43:00 | Win2K-f | 118.161.183.193 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:04:18:00 | WinXP | 61.221.250.18 (HINET.NET): DATA COMMUNICATION BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TW. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 78 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:06:17:00 | Win2K-f | 67.123.204.202 (PACBELL.NET): RICHARD MULHALL, SAN FRANCISCO, CALIFORNIA, US. (DSL) |
67.43.236.67:10324 | CA:xx.nadnadzz.info :nadsamcabran12.com CA:67.43.236.67:10324 |
135 | pcap | raw alerts ruleset |
irc http 622 lines |
Yeah : 1.8 profile |
none | summary tarball |
40 of 41 32 of 38 |
3842e66ff7 NEW 524bc0f75c NEW |
fc7c8aaf10 [0] d3e9510bb3[0] |
none:none none:none |
EXECrypto| PENinja S| |
none none |
trace trace |
T:07:20:00 | WinXP | 122.122.131.65 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | a0139d7ad8 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:07:45:00 | WinXP | 114.48.34.1 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:08:01:00 | WinXP | 72.191.3.19 (RR.COM): ROAD RUNNER HOLDCO LLC, SAN ANTONIO, TEXAS, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:08:25:00 | WinXP | 96.8.235.108 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 23 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 41 | 75e81ffe38 NEW |
none[3] | none:none |
none|none | none | trace | |
T:08:25:00 | WinXP | 98.141.17.48 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 19 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:08:54:00 | WinXP | 92.48.126.130 (IKBCC.COM): EU-ZZ, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:09:09:00 | Win2K-f | 4.161.161.25 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DALLAS, TEXAS, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 38 of 41 |
02674c9a56 NEW 25eae40389 NEW |
0da2cae967 [0] 1e0aae0aeb[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:10:04:00 | Win2K-f | 24.234.68.126 (COX.NET): COX COMMUNICATIONS INC, LAS VEGAS, NEVADA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:01:00 | WinXP | 83.27.115.24 (TPNET.PL): NEOSTRADA PLUS, POZNAN, WIELKOPOLSKIE, PL. (DSL) |
n/a | CN:proxima.ircgalaxy.pl :moscow-advokat.ru CN:221.5.74.39:65520 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
35 of 36 | c392067a90 NEW |
d83160e550 [0] | none:none |
PolyEnE| | none | trace |
T:12:48:00 | WinXP | 63.24.123.154 (UU.NET): UUNET TECHNOLOGIES INC, SPRINGFIELD, MASSACHUSETTS, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:13:08:00 | Win2K-f | 174.0.194.148 (-): . |
61.120.62.28:3305 | GB:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 695 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:13:38:00 | WinXP | 76.8.230.228 (TELAPEX.COM): TELEPAK NETWORKS INC, JACKSON, MISSISSIPPI, US. |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:38:00 | WinXP | 93.102.48.180 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | :www.google.com.au :jbeegvia.ru |
135 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 17028f1eda NEW |
none[3] | none:none |
tElock| | none | trace |
16:07:00 | WinXP | 76.8.230.228 (TELAPEX.COM): TELEPAK NETWORKS INC, JACKSON, MISSISSIPPI, US. |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:16:13:00 | Win2K-f | 96.8.219.143 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:17:04:00 | WinXP | 98.141.160.84 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:17:13:00 | WinXP | 196.3.138.180 (TSTT.NET.TT): WOWNET LTD, TT. |
n/a | 445 | pcap | raw alerts ruleset |
http 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:17:45:00 | Win2K-f | 71.136.17.68 (-): MILANO DESIGN, PLANO, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 85 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 33 33 of 33 |
73ce2b74da NEW 79c01ec060 NEW |
none[0] 1bfd34056c[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=64 embedded dns |
trace trace |
T:18:01:00 | Win2K-f | 68.148.111.164 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, EDMONTON, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1008 lines |
Yeah : 1.3 profile |
none | summary tarball |
9 of 41 | d00dd9cdf0 NEW |
none[3] | none:none |
none|none | none | trace | |
18:04:00 | WinXP | 4.235.93.29 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, HOMOSASSA SPRINGS, FLORIDA, US. (DIAL) |
218.93.205.24:65520 | CN:proxim.ircgalaxy.pl CN:dretis.cn CN:kritq.cn |
445 | pcap | raw alerts ruleset |
http irc 19 lines |
Yeah : 1.3 profile |
none | summary tarball |
7 of 41 10 of 41 37 of 39 |
5354e986cd NEW 938fa818d8 NEW dab4da4e21 NEW |
55eb7e6494 [0] none [4] e63b813015[0] |
none:none none:none ASM:Graph |
PENinja| Mew| PolyEnE| |
none none lines=134 |
trace trace trace |
T:19:12:00 | Win2K-f | 165.154.46.195 (INTERHOP.NET): HOOKUP COMMUNICATIONS, TRURO, NOVA SCOTIA, CA. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 126 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:19:33:00 | WinXP | 219.110.140.34 (CATV02.ITSCOM.JP): ITS COMMUNICATIONS INC, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:19:35:00 | WinXP | 70.184.102.222 (COX.NET): COX COMMUNICATIONS, CHANDLER, ARIZONA, US. |
221.5.74.39:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:dretis.cn CN:kritq.cn |
135 | pcap | raw alerts ruleset |
irc http 147 lines |
Yeah : 1.8 profile |
none | summary tarball |
7 of 41 10 of 41 32 of 36 35 of 36 |
5354e986cd NEW 938fa818d8 NEW bea8cb1865 NEW fac78fde16 NEW |
55eb7e6494 [0] none [4] 154de51a66[0] 882896ab05[0] |
none:none none:none ASM:Graph none:none |
PENinja| Mew| Armadillo| tElock| |
none none lines=91 none |
trace trace trace trace |
T:20:10:00 | WinXP | 12.74.63.249 (ATT.NET): AT&T WORLDNET SERVICES, LOUISVILLE, KENTUCKY, US. (DIAL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com GB:new.egg.com :wpad |
445 | pcap | raw alerts ruleset |
http http http http 48 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:20:42:00 | WinXP | 200.219.70.213 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 694802b8ef NEW |
433eb20eb6 [0] | none:none |
PolyEnE| | none | trace |
T:21:14:00 | Win2K-f | 172.130.171.31 (AOL.COM): AMERICA ONLINE, RESTON, VIRGINIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 39 lines |
Yeah : 1.3 profile |
none | summary tarball |
2 of 41 | da28ff0fb8 NEW |
none[3] | none:none |
FASM| | none | trace | |
T:21:41:00 | WinXP | 115.165.82.115 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:21:52:00 | Win2K-f | 122.2.90.190 (PLDT.NET): IPG, PH. |
n/a | 135 | pcap | raw alerts ruleset |
other 53 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 41 | 18727a186e NEW |
1ea861ccfa [0] | none:none |
Armadillo| | none | trace | |
T:22:40:00 | Win2K-f | 70.75.84.73 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
83.68.16.6:5190 67.43.236.67:10324 | NL:xx.sqlteam.info CA:xx.nadnadzz.info :nadsamcabran12.com |
135 | pcap | raw alerts ruleset |
irc http 203 lines |
Yeah : 1.8 profile |
none | summary tarball |
32 of 38 38 of 41 |
524bc0f75c NEW a894e6640a NEW |
d3e9510bb3 [0] 2a62540340[0] |
none:none none:none |
PENinja
S| PolyEnE| |
none none |
trace trace |
T:23:07:00 | Win2K-f | 173.22.166.56 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 40 |
474acf88e5 NEW 68f0c14692 NEW |
1f53944b24 [0] ccc1b24d53[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |