Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:13:00 | WinXP | 91.66.57.154 (SUPERKABEL.DE): KABEL DEUTSCHLAND BREITBAND SERVICE GMBH, DE. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
00:47:00 | Win2K-f | 119.36.154.244 (-): . |
n/a | US:www.maxmind.com US:getmyip.co.uk US:www.getmyip.org US:checkip.dyndns.org US:65.254.39.170:80 US:67.15.94.80:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:00:57:00 | Win2K-f | 119.36.154.244 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org EU:checkip.dyndns.org US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:01:31:00 | Win2K-f | 96.225.81.61 (VERIZON.NET): VERIZON INTERNET SERVICES INC, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:15:00 | WinXP | 155.239.58.144 (TELKOM-IPNET.CO.ZA): AFRINIC, JOHANNESBURG, GAUTENG, ZA. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
31 of 41 | 6a49427d15 NEW |
996a673e00 [0] | none:none |
FASM| | none | trace | |
T:05:07:00 | WinXP | 207.5.236.176 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:06:29:00 | Win2K-f | 211.209.212.61 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
221.5.74.39:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:www.zief.pl CN:dretis.cn CN:kritq.cn :onuka.cn CN:221.5.74.39:65520 |
135 | pcap | raw alerts ruleset |
irc http 144 lines |
Yeah : 1.8 profile |
none | summary tarball |
32 of 36 7 of 41 7 of 41 34 of 36 11 of 41 36 of 41 |
0c3d1ec2df NEW 18dfbbc85b NEW 5354e986cd NEW 8de905030e NEW 9e77bec9ac NEW e442e89eb6 NEW |
c9008e9a12 [0] 4f6fcecea3[0] 55eb7e6494[0] f601bdf68b[0] 83ba908fa0[0] 8cfa5407d6[0] |
none:none none:none none:none none:none none:none none:none |
Armadillo| UPX| PENinja| tElock| Armadillo| ASPack| |
none none none none none none |
trace trace trace trace trace trace |
T:08:41:00 | WinXP | 79.163.112.152 (-): IDEA, PL. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 270eb53c1d NEW |
af0fccd631 [0] | none:none |
PolyEnE| | none | trace |
T:08:48:00 | WinXP | 114.48.161.152 (-): . |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | f3a3c3f744 NEW |
a3445bab37 [0] | none:none |
PolyEnE| | none | trace |
T:09:37:00 | Win2K-f | 24.78.178.22 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, NORTH VANCOUVER, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1002 lines |
Yeah : 1.3 profile |
none | summary tarball |
8 of 41 | d27d63c9b7 NEW |
none[3] | none:none |
none|none | none | trace | |
T:10:04:00 | WinXP | 87.173.120.167 (T-IPCONNECT.DE): DEUTSCHE TELEKOM AG, DE. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:11:05:00 | Win2K-f | 76.174.96.4 (RR.COM): ROAD RUNNER HOLDCO LLC, LOS ANGELES, CALIFORNIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:07:00 | Win2K-f | 96.8.220.143 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 11 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:12:32:00 | Win2K-f | 130.13.40.216 (QWEST.NET): QWEST BROADBAND SERVICES INC, PHOENIX, ARIZONA, US. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 | 894e794b2b NEW |
aeb41eb7b9 [0] | none:none |
Obsidium| | none | trace | |
T:13:02:00 | WinXP | 41.210.211.74 (-): . |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 109188d5f8 NEW |
aa7be7c5d9 [0] | none:none |
PolyEnE| | none | trace |
13:03:00 | Win2K-f | 89.42.211.248 (-): SC TELEMONT SRL, RO. |
n/a | US:www.msn.com US:ads1.msn.com US:col.stj.s-msn.com US:col.stc.s-msn.com US:analytics.live.com US:www.bing.com US:rad.msn.com US:st.msn.com US:col.stb.s-msn.com :msnportal.112.2o7.net US:c.msn.com US:c.atdmt.com US:a.rad.msn.com US:b.rad.msn.com US:a.ads2.msn.com US:b.ads2.msn.com US:view.atdmt.com US:ad.doubleclick.net US:b.ads1.msn.com US:m1.2mdn.net US:128.241.217.112:80 |
445 | pcap | raw alerts ruleset |
http 87 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:13:09:00 | WinXP | 62.38.188.141 (-): MEDNET HELLAS, ATHENS, ATTIKI, GR. (100Mbps) |
n/a | US:www.microsoft.com :wpad US:www.slashdot.org US:c.fsdn.com :www.google-analytics.com US:data.coremetrics.com |
445 | pcap | raw alerts ruleset |
http 393 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:13:14:00 | Win2K-f | 173.20.140.66 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 39 of 41 |
5e3a9c2d9d NEW 630308d06b NEW |
dbc48b815a [0] 847d302e37[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
13:20:00 | WinXP | 190.178.203.84 (-): . |
n/a | US:www.microsoft.com :wpad HK:www.jazzhigh.com |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:14:59:00 | Win2K-f | 4.248.255.78 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, FRONT ROYAL, VIRGINIA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 212 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:15:48:00 | WinXP | 76.200.156.84 (SBCGLOBAL.NET): BRAS44.PLTNCA, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:16:01:00 | WinXP | 67.242.136.38 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:16:22:00 | WinXP | 96.50.227.186 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:26:00 | Win2K-f | 24.69.154.67 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
61.120.62.28:3305 | TH:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 607 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 40 | e78c487d0b NEW |
74f7d3ae9c [0] | none:none |
StarForce| | none | trace |
T:17:02:00 | Win2K-f | 123.50.229.108 (KCN-TV.NE.JP): KUMAMOTO CABLE NETWORK CORPORATION, KUMAMOTO, KUMAMOTO, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:17:43:00 | Win2K-f | 4.224.141.233 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, INDIANAPOLIS, INDIANA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:19:19:00 | WinXP | 4.238.91.177 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, PROVIDENCE, RHODE ISLAND, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:19:34:00 | WinXP | 74.214.235.188 (ETV.NET): EMERY TELCOM, ORANGEVILLE, UTAH, US. |
n/a | :gg.arrancar.org | 135 | pcap | raw alerts ruleset |
other 144 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 | 10980f4df2 NEW |
1fd3385a95 [0] | ASM:Graph |
none|none | lines=556 | trace |
T:21:14:00 | WinXP | 186.9.77.188 (-): . |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
21:50:00 | WinXP | 74.138.53.79 (INSIGHTBB.COM): INSIGHT COMMUNICATIONS COMPANY L.P, LOUISVILLE, KENTUCKY, US. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | eda3b7766c NEW |
7556343561 [0] | none:none |
PolyEnE| | none | trace |
T:22:07:00 | WinXP | 74.65.164.131 (RR.COM): ROAD RUNNER HOLDCO LLC, PORTLAND, MAINE, US. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:22:52:00 | WinXP | 72.224.73.121 (RR.COM): ROAD RUNNER HOLDCO LLC, ALBANY, NEW YORK, US. |
82.98.86.170:80 | EU:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com DE:ebookfinaltrash.ru :wpad |
445 | pcap | raw alerts ruleset |
http http http http 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:23:47:00 | Win2K-f | 71.68.212.172 (RR.COM): ROAD RUNNER HOLDCO LLC, FLORENCE, SOUTH CAROLINA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 79 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |