Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:06:00 | Win2K-f | 58.71.45.90 (PLDT.NET): IPG, PH. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 175 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 39 of 41 |
5403724951 NEW 6494cbd582 NEW |
44ee5f83ba [0] adcb56d0cb[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:02:22:00 | WinXP | 78.84.192.182 (MICROLINK.LV): TELEKOM, RIGA, RIGA, LV. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | aab1b56620 NEW |
3b2e1c5b9d [0] | none:none |
PolyEnE| | none | trace |
T:02:36:00 | Win2K-f | 70.78.20.139 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CHILLIWACK, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 06c9e8d638 NEW |
6ec94ef43f [0] | none:none |
none|none | none | trace | |
T:02:48:00 | WinXP | 72.66.8.36 (VERIZON.NET): GAIP INC, VIENNA, VIRGINIA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:37:00 | Win2K-f | 218.220.144.132 (ZAQ.NE.JP): HIGASHI-OSAKA CABLE TELEVISION CO. LTD, OSAKA, OSAKA, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 79 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=75 embedded dns |
trace trace |
T:04:42:00 | WinXP | 61.62.169.106 (SO-NET.NET.TW): SONY NETWORK TAIWAN LIMITED, TAOYUAN, T'AI-WAN, TW. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | eda3b7766c NEW |
7556343561 [0] | none:none |
PolyEnE| | none | trace |
T:05:28:00 | WinXP | 117.55.30.43 (EMOBILE.AD.JP): EMOBILE LTD, TOKYO, TOKYO, JP. |
n/a | CA:xx.ka3ek.com :idfc.info |
445 | pcap | raw alerts ruleset |
shell ftp irc http 26 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 41 32 of 38 41 of 41 |
39336e51eb NEW 524bc0f75c NEW a3dd1d02df NEW |
3f5ab71d39 [0] d3e9510bb3[0] 8803db6928[0] |
none:none none:none none:none |
Neolite| PENinja S| Armadillo| |
none none none |
trace trace trace |
T:05:58:00 | WinXP | 93.81.177.139 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 41 | 67c629c38b NEW |
none[3] | none:none |
none|none | none | trace | |
T:06:12:00 | Win2K-f | 41.206.135.13 (-): VODAFONE EGYPT, EG. |
n/a | CZ:qtas.net | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
6 of 40 | 41fba073ee NEW |
4009c372b6 [0] | none:none |
FASM| | none | trace |
T:07:14:00 | WinXP | 124.66.243.238 (FCH.NE.JP): FUREAI CHANNEL INC, HIROSHIMA, HIROSHIMA, JP. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 35 | 9716d7995a NEW |
c3a5354b6f [0] | none:none |
PolyEnE| | none | trace |
T:08:25:00 | WinXP | 79.163.58.8 (-): IDEA, PL. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 36 | 06a5e31b47 NEW |
25e6e52787 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:10:30:00 | WinXP | 155.239.140.21 (TELKOM-IPNET.CO.ZA): AFRINIC, CAPE TOWN, WESTERN CAPE, ZA. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:11:27:00 | WinXP | 173.22.166.56 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 40 |
474acf88e5 NEW 68f0c14692 NEW |
1f53944b24 [0] ccc1b24d53[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:11:32:00 | WinXP | 124.147.112.90 (DY.BBEXCITE.JP): INTERNET INITIATIVE JAPAN INC, TOKYO, TOKYO, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 41 | b669db7f51 NEW |
none[4] | none:none |
none|none | none | trace | |
T:11:52:00 | WinXP | 87.78.219.198 (NETCOLOGNE.DE): NETCOLOGNE GMBH, COLOGNE, NORDRHEIN-WESTFALEN, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:12:10:00 | Win2K-f | 155.239.57.158 (TELKOM-IPNET.CO.ZA): AFRINIC, JOHANNESBURG, GAUTENG, ZA. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 171 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:13:54:00 | WinXP | 122.29.191.94 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | ASM:Graph |
none|none | lines=61 | trace | |
T:14:29:00 | Win2K-f | 114.74.212.71 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 150 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
56703b9d17 NEW c55e86f7e9 NEW |
de8764ef05 [0] c790c10ad1[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:14:34:00 | WinXP | 114.48.183.44 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:16:05:00 | Win2K-f | 65.191.116.18 (RR.COM): ROAD RUNNER HOLDCO LLC, FAYETTEVILLE, NORTH CAROLINA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 33 of 33 |
4c3df24b32 NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=75 embedded dns |
trace trace |
T:16:14:00 | Win2K-f | 207.5.155.42 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:17:11:00 | WinXP | 70.66.134.44 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, VANCOUVER, BRITISH COLUMBIA, CA. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:17:14:00 | WinXP | 173.20.142.133 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 39 of 41 |
10759405e0 NEW d08e00dfaf NEW |
292d343248 [0] 854c49d8c4[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:17:41:00 | WinXP | 124.241.191.217 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, AICHI, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 93 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:19:07:00 | WinXP | 173.29.140.244 (-): . |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 4d4b114a18 NEW |
2414a15ebd [0] | none:none |
PolyEnE| | none | trace |
T:19:38:00 | Win2K-f | 68.146.34.28 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:47:00 | Win2K-f | 69.232.18.154 (PACBELL.NET): HI STYLES FASHIONS INC, PLANO, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:36:00 | WinXP | 74.214.47.11 (METROCAST.NET): GMP CABLE TV, BERWICK, PENNSYLVANIA, US. |
194.109.11.65:6556 | :0x80.my-secure.name NL:0x80.my1x1.com |
135 | pcap | raw alerts ruleset |
other 214 lines |
Yeah : 1.8 profile |
none | summary tarball |
32 of 33 | fe22b8315f NEW |
bb25603f41 [0] | none:none |
StarForce| | none | trace |
T:23:51:00 | WinXP | 96.49.4.72 (-): . |
92.240.234.164:3305 | AR:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 607 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 41 | 616f21b486 NEW |
348063e1c2 [0] | none:none |
StarForce| | none | trace |