Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:17:00 | Win2K-f | 116.6.14.242 (163DATA.COM.CN): CHINANET GUANGDONG PROVINCE NETWORK, BEIJING, BEIJING, CN. |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org US:getmyip.co.uk 208.78.70.70:80 US:65.254.39.170:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:01:25:00 | Win2K-f | 116.120.197.40 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR. |
91.121.221.157:65520 | US:microsoft.com FR:proxim.ircgalaxy.pl CN:gidromash.cn CN:ottopay.cn US:64.235.53.208:80 |
135 | pcap | raw alerts ruleset |
irc http 129 lines |
Yeah : 1.8 profile |
none | summary tarball |
30 of 33 28 of 33 8 of 41 |
533d15b5ce NEW 58c343a8d8 NEW dedb9bcef0 NEW |
c67adf46e2 [0] none [0] 23233d4cd8[0] |
ASM:Graph none:none none:none |
tElock| Armadillo| Xtreme-Pr| |
lines=126 embedded dns lines=91 none |
trace trace trace |
T:01:39:00 | WinXP | 125.233.78.57 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:01:52:00 | WinXP | 71.116.212.170 (VERIZON.NET): VERIZON INTERNET SERVICES INC, LOS ANGELES, CALIFORNIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
02:12:00 | WinXP | 125.233.78.57 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:02:15:00 | Win2K-f | 68.150.146.235 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, LEDUC, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 146 lines |
Yeah : 1.3 profile |
none | summary tarball |
12 of 41 | 23ed3f751a NEW |
none[none] | none:none |
FSG| | none | none | |
T:02:29:00 | WinXP | 114.59.227.40 (-): . |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | b062182bb1 NEW |
1fb7e59bf8 [0] | none:none |
PolyEnE| | none | trace |
T:03:02:00 | Win2K-f | 116.6.14.242 (163DATA.COM.CN): CHINANET GUANGDONG PROVINCE NETWORK, BEIJING, BEIJING, CN. |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:04:00:00 | Win2K-f | 124.241.149.241 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, AICHI, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:04:28:00 | WinXP | 123.52.37.24 (163DATA.COM.CN): CHINANET HENAN PROVINCE NETWORK, HENAN, GUIZHOU, CN. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:05:20:00 | Win2K-f | 69.235.206.227 (PACBELL.NET): RBACK30A.IRVNCA, LOS ANGELES, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:06:48:00 | WinXP | 219.254.116.71 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
91.212.220.156:65520 | FR:proxim.ircgalaxy.pl US:microsoft.com CN:gidromash.cn CN:ottopay.cn US:64.235.53.208:80 FR:91.121.221.157:65520 |
135 | pcap | raw alerts ruleset |
irc http 199 lines |
Yeah : 1.8 profile |
none | summary tarball |
40 of 41 39 of 41 8 of 41 |
1eafd24c64 NEW b5edcbfd2a NEW dedb9bcef0 NEW |
91efa90c65 [none] c30d825691[none] 23233d4cd8[0] |
none:none none:none none:none |
StarForce| Armadillo| Xtreme-Pr| |
none none none |
none none trace |
T:06:57:00 | WinXP | 83.221.84.175 (PRIMACOM.NET): PRIMACOM-HEADENDS, LEIPZIG, SACHSEN, DE. |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | c05290bb06 NEW |
dddfe6a7fe [0] | none:none |
PolyEnE| | none | trace |
T:07:14:00 | WinXP | 70.121.217.141 (RR.COM): ROAD RUNNER HOLDCO LLC, CASSELBERRY, FLORIDA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:49:00 | Win2K-f | 114.58.144.101 (-): . |
n/a | CZ:qtas.net | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
33 of 41 | 2465729178 NEW |
0f6179d7d9 [none] | none:none |
FSG| | none | none |
T:08:15:00 | Win2K-f | 70.66.86.16 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, GABRIOLA, BRITISH COLUMBIA, CA. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
08:56:00 | Win2K-f | 95.25.174.156 (-): . |
n/a | :checkip.dyndns.org US:www.getmyip.org US:getmyip.co.uk US:204.152.184.139:80 208.78.70.70:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:09:33:00 | Win2K-f | 203.90.78.131 (ITC.CO.IN): HCL INFINET LIMITED, IN. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:09:36:00 | WinXP | 165.154.24.84 (ISPNETBILLING.COM): HOOKUP COMMUNICATIONS, COURTICE, ONTARIO, CA. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:09:52:00 | WinXP | 211.20.222.150 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
200.49.145.197:3305 | JP:cx10man.weedns.com JP:fx010413.whyI.org AR:gynoman.weedns.com FI:g.0x20.biz KR:telephone.dd.blueline.be AR:phonewire.dd.blueline.be KR:211.233.45.253:3305 JP:61.120.62.28:3305 |
135 | pcap | raw alerts ruleset |
irc 695 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
09:56:00 | WinXP | 63.151.109.189 (SONIC.COM): ST OF TX - GEUS, ASHLAND, OREGON, US. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | ed96c03ca8 NEW |
c0028e9e98 [0] | none:none |
PolyEnE| | none | trace |
T:10:43:00 | WinXP | 70.182.64.247 (COX.NET): COX COMMUNICATIONS, OKLAHOMA CITY, OKLAHOMA, US. |
91.121.221.157:65520 | FR:proxim.ircgalaxy.pl US:microsoft.com CN:gidromash.cn :nenastiya.cn CN:ottopay.cn CN:dl.guarddog2009.com CN:218.93.205.19:80 US:64.235.53.208:80 |
135 | pcap | raw alerts ruleset |
irc http 134 lines |
Yeah : 1.8 profile |
none | summary tarball |
1 of 40 32 of 36 8 of 41 35 of 36 |
9ba2752f0b NEW bea8cb1865 NEW dedb9bcef0 NEW fac78fde16 NEW |
none[3] 154de51a66[0] 23233d4cd8[0] 882896ab05[0] |
none:none ASM:Graph none:none none:none |
UPX| Armadillo| Xtreme-Pr| tElock| |
none lines=91 none none |
trace trace trace trace |
T:11:01:00 | WinXP | 202.221.175.59 (BMOBILE.NE.JP): JAPAN COMMUNICATION INC, TOKYO, TOKYO, JP. |
n/a | EU:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com GB:new.egg.com :wpad |
445 | pcap | raw alerts ruleset |
http http http 29 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:11:13:00 | WinXP | 166.164.108.71 (MYVZW.COM): SERVICE PROVIDER CORPORATION, BEDMINSTER, NEW JERSEY, US. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:13:03:00 | WinXP | 4.226.225.131 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, BANDERA, TEXAS, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 7 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
13:34:00 | Win2K-f | 93.115.5.167 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | EE:www.starman.ee FI:www.if.ee FI:194.215.38.3:80 US:204.152.184.139:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
14:09:00 | WinXP | 64.33.132.53 (AIRSTREAMCOMM.NET): TRI COUNTY TELEPHONE, WISCONSIN, US. (DIAL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 0cfab99612 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:14:33:00 | WinXP | 62.243.155.13 (ADSL-DHCP.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, COPENHAGEN, COPENHAGEN, DK. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 35 | e9fcd6f257 NEW |
2e05bc2272 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:15:38:00 | Win2K-f | 96.52.238.215 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:50:00 | Win2K-f | 69.193.74.22 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:17:35:00 | Win2K-f | 24.213.224.238 (RR.COM): ROAD RUNNER HOLDCO LLC, AMSTERDAM, NEW YORK, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
19:14:00 | Win2K-f | 79.191.71.242 (TPNET.PL): TPSA, PL. |
n/a | :www.google.com :yqzaitblqbe.biz :crvtvqgpiat.net :wxdodcxl.net US:lzazuibw.org :wndrduc.biz :chuaulmgdzj.com US:xtubkghqx.org US:wwtwr.info :ajoompyi.net :qltzns.biz :trmacsn.com :xydpou.net :zjxfznqddre.biz NL:gzaybjba.info US:wukejfoxg.org :twwaip.net US:bdfahkuo.org :bjregub.biz :htaeqc.biz :ihqpduo.net :aknmciendn.net :dvlox.net :rpytjc.net :cnhorno.biz :yipbtk.biz :ojxqkqcc.biz :mpgmhpjk.com :htlklbwcc.com :bdftewse.com :yhegwhadicw.com US:phazhfdr.info US:xtgnxjzsrc.org US:grgxulu.info :pszulmygmma.org :yjumtzlaf.net NL:erhrvfbewg.info US:dflxuuuj.info :dvaioplww.com :ibeepc.net :bwwsotrg.com US:ragxgxkft.info :xqaazzppza.biz US:tvdqglqjkwp.org :ggknbwan.org :apjhib.net NL:rcecw.info :ygfpqdoys.biz :qrsoq.biz :mlmfkgbmb.net :inessy.net :gjwcbi.biz :sheafkbdi.biz :mngrkm.biz :mvhsoupgi.net US:cnsnjzvu.org :bzzlp.org :gojzgqsqlub.net :azrfoohx.com NL:oubunaykr.org US:nctmoybmije.info US:ztmdp.info :olhqzfplop.com US:iqfgbebqv.org US:jtbbkwxz.org :tlelwpq.net :xnvdxxydud.net :vkquzhkfhu.net US:iwujvxvtoo.info :yhyzn.com :bxlckfjuh.com US:204.152.184.139:80 US:74.208.64.145:80 |
445 | pcap | raw alerts ruleset |
http 7 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:19:50:00 | WinXP | 24.103.188.177 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
19:52:00 | WinXP | 209.250.52.146 (WISPNET.NET): WISPNET LLC, HOPKINSVILLE, KENTUCKY, US. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
36 of 38 | 5865b09945 NEW |
4d99f4784a [0] | none:none |
PolyEnE| | none | trace |
T:20:48:00 | WinXP | 71.68.208.108 (RR.COM): ROAD RUNNER HOLDCO LLC, FLORENCE, SOUTH CAROLINA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:07:00 | WinXP | 4.161.20.10 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, KOKOMO, INDIANA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:21:22:00 | Win2K-f | 114.206.63.166 (-): . |
91.212.220.156:65520 | FR:proxim.ircgalaxy.pl US:microsoft.com CN:gidromash.cn CN:ottopay.cn US:64.235.53.208:80 |
135 | pcap | raw alerts ruleset |
irc http 161 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 41 37 of 41 8 of 41 2 of 41 |
4a73088e09 NEW d69be65220 NEW dedb9bcef0 NEW e99d2fc14f NEW |
45877a3c3c [none] 16d65fd6e9[0] 23233d4cd8[0] 2621d9e2ed[none] |
none:none none:none none:none none:none |
tElock| Armadillo| Xtreme-Pr| none|none |
none none none none |
none trace trace none |
T:21:22:00 | WinXP | 190.51.191.117 (COM.AR): TELEFONICA DE ARGENTINA, BUENOS AIRES, BUENOS AIRES, AR. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 24797e92b8 NEW |
aa29abf6ce [none] | none:none |
PolyEnE| | none | none |
T:22:32:00 | WinXP | 203.91.165.218 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, AICHI, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |