Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:17:00 | Win2K-f | 221.141.74.250 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 83 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:14:00 | Win2K-f | 76.179.73.51 (RR.COM): ROAD RUNNER HOLDCO LLC, BIDDEFORD, MAINE, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 782 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 3e30dc90de NEW |
d5e7d16040 [0] | none:none |
StarForce| | none | trace | |
T:02:50:00 | WinXP | 115.82.64.206 (-): . |
213.219.245.212:80 | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 74c3429921 NEW |
1265c25f7f [0] | none:none |
PolyEnE| | none | trace |
T:03:39:00 | Win2K-f | 67.123.204.202 (PACBELL.NET): RICHARD MULHALL, SAN FRANCISCO, CALIFORNIA, US. (DSL) |
n/a | CA:xx.ka3ek.com :idfc.info |
135 | pcap | raw alerts ruleset |
irc http 622 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 29 of 41 32 of 38 |
3842e66ff7 NEW 39336e51eb NEW 524bc0f75c NEW |
fc7c8aaf10 [0] 3f5ab71d39[0] d3e9510bb3[0] |
none:none none:none none:none |
EXECrypto| Neolite| PENinja S| |
none none none |
trace trace trace |
T:04:02:00 | WinXP | 88.28.255.221 (RIMA-TDE.NET): TELEFONICA MOVILES ESPANA (NCC#2007041930), ES. |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:04:11:00 | WinXP | 211.20.54.54 (WINSTOCK.COM.TW): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 109 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 38 of 41 |
3f136c55b3 NEW ac394d7d5f NEW |
f4e18974f3 [0] c9a79e75f5[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:04:42:00 | WinXP | 119.234.131.226 (-): . |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 35 | 9716d7995a NEW |
c3a5354b6f [0] | none:none |
PolyEnE| | none | trace |
T:04:51:00 | WinXP | 113.255.99.33 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:06:00:00 | WinXP | 87.122.247.145 (VERSANET.DE): VERSATEL DEUTSCHLAND DYNAMIC POOL, COLOGNE, NORDRHEIN-WESTFALEN, DE. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:06:42:00 | WinXP | 12.28.192.225 (WTVACCESS.COM): WIRE TELE-VIEW CORP, PENNSYLVANIA, US. |
n/a | DE:siliconfireware.ru :wpad :www.proxy-socks.net DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee NEW |
none[0] | none:none |
ASPack| | lines=298 embedded dns |
trace |
T:07:54:00 | WinXP | 217.203.80.150 (-): TELECOM ITALIA MOBILE, IT. |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
35 of 36 | b27d73bfcb NEW |
473c6454ce [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:08:01:00 | WinXP | 75.43.212.74 (SBCGLOBAL.NET): PPPOX POOL - BRAS2.LSAN, LOS ANGELES, CALIFORNIA, US. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com RU:www.bbin.ru RU:www.binbank.ru :wpad US:204.13.161.51:80 DE:212.227.111.29:80 |
445 | pcap | raw alerts ruleset |
http http http http 27 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:08:16:00 | WinXP | 114.137.37.27 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:09:07:00 | Win2K-f | 123.212.227.164 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR. |
91.212.220.75:65520 | EU:proxim.ircgalaxy.pl US:microsoft.com :nenastiya.cn CN:gidromash.cn CN:dl.guarddog2009.com CN:ottopay.cn CN:211.95.79.170:80 US:64.235.53.208:80 EU:91.212.220.75:65520 |
135 | pcap | raw alerts ruleset |
irc http 122 lines |
Yeah : 1.8 profile |
none | summary tarball |
12 of 40 30 of 33 1 of 40 2 of 35 15 of 41 |
38e8f258e7 NEW 6ec2a8994b NEW 9ba2752f0b NEW bcf66a38c8 NEW deca0a71d7 NEW |
871a2e904e [0] 398aab9636[0] none [3] 570133b348[0] 6e7c1a39e4[0] |
none:none none:none none:none none:none none:none |
none|none tElock| UPX| Armadillo| tElock| |
none none none none none |
trace trace trace trace trace |
T:09:36:00 | WinXP | 200.100.248.149 (BRASILTELECOM.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DIAL) |
91.212.220.75:65520 | CN:proxim.ircgalaxy.pl :nenastiya.cn CN:gidromash.cn CN:ottopay.cn US:64.235.53.208:80 |
445 | pcap | raw alerts ruleset |
http irc 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
12 of 40 1 of 40 37 of 39 |
38e8f258e7 NEW 9ba2752f0b NEW dab4da4e21 NEW |
871a2e904e [0] none [3] e63b813015[0] |
none:none none:none ASM:Graph |
none|none UPX| PolyEnE| |
none none lines=134 |
trace trace trace |
T:09:45:00 | Win2K-f | 219.114.245.152 (ZAQ.NE.JP): KITAKAWACHI CABLE NET CO LTD, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:10:33:00 | WinXP | 24.234.68.126 (COX.NET): COX COMMUNICATIONS INC, LAS VEGAS, NEVADA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:10:52:00 | Win2K-f | 76.175.116.243 (RR.COM): ROAD RUNNER HOLDCO LLC, CHINO HILLS, CALIFORNIA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 1008 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 41 | 96511f48b8 NEW |
none[3] | none:none |
none|none | none | trace | |
T:11:34:00 | Win2K-f | 70.241.89.92 (SWBELL.NET): PPPOX POOL - RBACK21 HSTNTX, HOUSTON, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:45:00 | WinXP | 41.202.180.31 (-): . |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 7f38ca84af NEW |
89991cf07f [0] | none:none |
PolyEnE| | none | trace |
T:11:45:00 | WinXP | 74.215.65.114 (FUSE.NET): FUSE INTERNET ACCESS, CINCINNATI, OHIO, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 39 of 41 |
8459377032 NEW 8c3fbe8572 NEW |
2f809ba47f [0] 6d017d228b[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:11:49:00 | Win2K-f | 70.66.68.184 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, NANAIMO, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 54 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | 73f1082158 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:11:52:00 | WinXP | 87.122.197.212 (VERSANET.DE): VERSATEL DEUTSCHLAND DYNAMIC POOL, WUPPERTAL, NORDRHEIN-WESTFALEN, DE. |
n/a | 445 | pcap | raw alerts ruleset |
other 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:53:00 | Win2K-f | 99.68.220.130 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:07:00 | Win2K-f | 96.49.4.72 (-): . |
n/a | TH:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 606 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 616f21b486 NEW |
348063e1c2 [0] | none:none |
StarForce| | none | trace |
T:15:34:00 | WinXP | 216.208.242.72 (GROUPTELECOM.NET): BELL CANADA, TORONTO, ONTARIO, CA. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 185 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 37 of 41 |
c89b154681 NEW d2b40c91a1 NEW |
58d02dbffa [0] fbaa414397[0] |
none:none none:none |
StarForce| Armadillo| |
none none |
trace trace |
T:16:09:00 | Win2K-f | 97.100.55.98 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:41:00 | Win2K-f | 222.234.215.162 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
91.212.220.75:65520 | EU:proxim.ircgalaxy.pl US:microsoft.com CN:dl.guarddog2009.com CN:gidromash.cn CN:ottopay.cn US:64.235.53.208:80 EU:91.212.220.75:65520 |
135 | pcap | raw alerts ruleset |
irc http 140 lines |
Yeah : 1.8 profile |
none | summary tarball |
12 of 40 29 of 32 28 of 32 19 of 41 |
38e8f258e7 NEW 8a75955033 NEW 9276c8b36b NEW 95ca496b37 NEW |
871a2e904e [0] 2bf3e548b9[0] none [0] 9c39a10179[0] |
none:none ASM:Graph ASM:Graph none:none |
none|none tElock| Armadillo| none|none |
none lines=126 embedded dns lines=81 none |
trace trace trace trace |
T:16:45:00 | WinXP | 65.169.172.15 (SPRINTLINK.NET): SPRINT, SOUTHERN PINES, NORTH CAROLINA, US. |
213.219.245.212:80 | CN:proxim.ircgalaxy.pl RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 36 | 9bb68450cd NEW |
c2d5ac2315 [0] | ASM:Graph |
PolyEnE| | lines=73 embedded dns |
trace |
T:17:04:00 | WinXP | 208.100.234.30 (1DIAL.COM): AD-BASE SYSTEMS INC. (DBA GLOBALPOPS), PITTSBURGH, PENNSYLVANIA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:19:17:00 | Win2K-f | 96.49.27.216 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 1008 lines |
Yeah : 1.3 profile |
none | summary tarball |
15 of 41 | 770a04a72c NEW |
none[3] | none:none |
none|none | none | trace | |
T:21:15:00 | WinXP | 12.77.141.87 (ATT.NET): AT&T WORLDNET SERVICES, TAMPA, FLORIDA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:29:00 | WinXP | 75.43.207.112 (SBCGLOBAL.NET): PPPOX POOL - BRAS2.LSAN, PASADENA, CALIFORNIA, US. (DSL) |
82.98.86.170:80 | EU:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com DE:ebookfinaltrash.ru :wpad RU:www.bbin.ru US:204.13.161.51:80 |
445 | pcap | raw alerts ruleset |
http http http http http 9 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:21:32:00 | Win2K-f | 173.171.242.179 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:38:00 | WinXP | 4.153.205.62 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, BIRMINGHAM, ALABAMA, US. (DIAL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:splegacy.information.com US:spi.domainsponsor.com GB:welcome3.smile.co.uk :wpad GB:195.92.84.198:80 US:204.13.161.51:80 DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http http 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:21:46:00 | Win2K-f | 222.236.87.212 (HANANET.NET): HANARO TELECOM INC, KR. |
91.212.220.75:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:gidromash.cn CN:ottopay.cn CN:218.93.205.30:65520 US:64.235.53.208:80 |
135 | pcap | raw alerts ruleset |
irc http 121 lines |
Yeah : 1.8 profile |
none | summary tarball |
12 of 40 30 of 33 28 of 33 |
38e8f258e7 NEW 533d15b5ce NEW 58c343a8d8 NEW |
871a2e904e [0] c67adf46e2[0] none [0] |
none:none ASM:Graph none:none |
none|none tElock| Armadillo| |
none lines=126 embedded dns lines=91 |
trace trace trace |
T:22:40:00 | Win2K-f | 68.149.46.80 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, EDMONTON, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1017 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 41 | 682a384fe9 NEW |
none[3] | none:none |
none|none | none | trace | |
T:22:59:00 | WinXP | 96.8.242.42 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:23:15:00 | WinXP | 114.201.74.45 (-): . |
218.93.205.30:65520 | CN:proxima.ircgalaxy.pl US:microsoft.com CN:dl.guarddog2009.com CN:gidromash.cn CN:ottopay.cn US:64.235.53.208:80 |
135 | pcap | raw alerts ruleset |
irc http 165 lines |
Yeah : 1.8 profile |
none | summary tarball |
12 of 40 40 of 41 19 of 41 40 of 41 |
38e8f258e7 NEW 80a65838c6 NEW 95ca496b37 NEW f82d977dc5 NEW |
871a2e904e [0] 5a961ecaa3[0] 9c39a10179[0] 7e2c966516[0] |
none:none none:none none:none none:none |
none|none tElock| none|none Armadillo| |
none none none none |
trace trace trace trace |
T:23:56:00 | WinXP | 67.125.140.230 (PACBELL.NET): AT&T INTERNET SERVICES, FRESNO, CALIFORNIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
18 of 35 0 of 33 |
218ce30f5c NEW a08f3b74a4 NEW |
none[3] none [0] |
none:none none:none |
none|none Armadillo| |
none lines=90 |
trace trace |