Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:30:00 | WinXP | 91.66.57.203 (SUPERKABEL.DE): KABEL DEUTSCHLAND BREITBAND SERVICE GMBH, DE. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:03:11:00 | WinXP | 122.118.81.37 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | f502585714 NEW |
none[0] | none:none |
PolyEnE| | lines=63 | trace |
T:03:51:00 | WinXP | 116.59.24.91 (-): MOBILE BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | eda3b7766c NEW |
7556343561 [0] | none:none |
PolyEnE| | none | trace |
T:04:01:00 | WinXP | 174.101.240.118 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 118 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:05:02:00 | Win2K-f | 203.91.184.97 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, AICHI, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 82 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:05:16:00 | WinXP | 85.152.137.163 (CM-85-152-150-10.TELECABLE.ES): TELECABLE, GIJON, ASTURIAS, ES. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | eda3b7766c NEW |
7556343561 [0] | none:none |
PolyEnE| | none | trace |
T:05:22:00 | WinXP | 114.48.31.230 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:06:13:00 | Win2K-f | 114.201.64.136 (-): . |
91.212.220.75:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:dl.guarddog2009.com CN:gidromash.cn CN:ottopay.cn |
135 | pcap | raw alerts ruleset |
irc http 135 lines |
Yeah : 1.8 profile |
none | summary tarball |
12 of 40 37 of 41 23 of 41 38 of 41 |
38e8f258e7 NEW 598636aa73 NEW 5d721a4dee NEW a57ddcdef0 NEW |
871a2e904e [0] 613af3f9a2[0] 6afc8cafab[0] none [4] |
none:none none:none none:none none:none |
none|none Armadillo| UPX| PolyEnE| |
none none none none |
trace trace trace trace |
T:06:26:00 | Win2K-f | 67.123.204.202 (PACBELL.NET): RICHARD MULHALL, SAN FRANCISCO, CALIFORNIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
irc 11 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:07:56:00 | Win2K-f | 188.98.162.98 (DAVITA.COM): VARIOUS REGISTRIES, UK. |
n/a | CZ:qtas.net | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
13 of 41 | e4612abb50 NEW |
a4a4192023 [0] | none:none |
FASM| | none | trace |
T:08:19:00 | WinXP | 71.108.152.194 (VERIZON.NET): VERIZON INTERNET SERVICES INC, LONG BEACH, CALIFORNIA, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 320195e2d3 NEW |
ce4cf37946 [0] | none:none |
none|none | none | trace | |
T:09:19:00 | WinXP | 211.211.69.226 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
91.212.220.75:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:www.brans.pl CN:dl.guarddog2009.com CN:gidromash.cn CN:211.95.79.170:80 |
135 | pcap | raw alerts ruleset |
irc http 136 lines |
Yeah : 1.8 profile |
none | summary tarball |
7 of 41 30 of 33 28 of 33 23 of 41 |
18dfbbc85b NEW 533d15b5ce NEW 58c343a8d8 NEW 5d721a4dee NEW |
4f6fcecea3 [0] c67adf46e2[0] none [0] 6afc8cafab[0] |
none:none ASM:Graph none:none none:none |
UPX| tElock| Armadillo| UPX| |
none lines=126 embedded dns lines=91 none |
trace trace trace trace |
T:10:13:00 | WinXP | 86.105.216.12 (PANEVO.RO): SC PAN ELECTRO SRL, RO. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | ed96c03ca8 NEW |
c0028e9e98 [0] | none:none |
PolyEnE| | none | trace |
T:10:19:00 | WinXP | 91.141.109.135 (I-ONE.AT): NETWORK OF ONE GMBH, VIENNA, WIEN, AT. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 74c3429921 NEW |
1265c25f7f [0] | none:none |
PolyEnE| | none | trace |
T:10:50:00 | WinXP | 84.183.214.19 (T-DIALIN.NET): DEUTSCHE TELEKOM AG, QUEDLINBURG, SACHSEN-ANHALT, DE. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:11:18:00 | WinXP | 115.83.141.163 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:11:48:00 | WinXP | 70.184.13.147 (COX.NET): COX COMMUNICATIONS, NEWPORT, RHODE ISLAND, US. |
218.93.205.30:65520 91.212.220.75:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:www.brans.pl CN:gidromash.cn CN:dl.guarddog2009.com CN:211.95.79.170:80 |
135 | pcap | raw alerts ruleset |
irc http 142 lines |
Yeah : 1.8 profile |
none | summary tarball |
7 of 41 23 of 41 32 of 33 29 of 33 |
18dfbbc85b NEW 5d721a4dee NEW 87e1117f2a NEW b4fe4581c3 NEW |
4f6fcecea3 [0] 6afc8cafab[0] 3ff643aae6[0] 599b835896[0] |
none:none none:none none:none none:none |
UPX| UPX| tElock| Armadillo| |
none none none none |
trace trace trace trace |
T:12:23:00 | WinXP | 203.88.183.172 (CTT.NE.JP): CABLE TELEVISION TOYAMA INCORPORETED, TOKYO, TOKYO, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 263 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 39 of 41 |
4f19859f92 NEW 906c8640c2 NEW |
b604aee23c [0] 3de348ad6f[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:12:27:00 | Win2K-f | 71.116.212.170 (VERIZON.NET): VERIZON INTERNET SERVICES INC, LOS ANGELES, CALIFORNIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:51:00 | WinXP | 98.175.152.9 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:13:53:00 | WinXP | 72.185.220.40 (RR.COM): ROAD RUNNER HOLDCO LLC, KISSIMMEE, FLORIDA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 1002 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 41 | 43b8f21924 NEW |
none[3] | none:none |
none|none | none | trace | |
T:14:13:00 | Win2K-f | 174.3.47.119 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:52:00 | WinXP | 116.59.169.171 (-): MOBILE BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | eda3b7766c NEW |
7556343561 [0] | none:none |
PolyEnE| | none | trace |
T:17:10:00 | WinXP | 209.30.128.62 (SWBELL.NET): PPPOX POOL - RBACK7 AUSTTX, AUSTIN, TEXAS, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:21:25:00 | WinXP | 130.13.96.83 (QWEST.NET): QWEST BROADBAND SERVICES INC, PHOENIX, ARIZONA, US. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | f2a8dafb30 NEW |
1d0f660523 [0] | none:none |
PolyEnE| | none | trace |
T:22:40:00 | WinXP | 59.104.54.206 (SEED.NET.TW): DIGITAL UNITED I, TAIPEI, T'AI-PEI, TW. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 3ae357d17b NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:23:20:00 | WinXP | 98.141.9.117 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |