Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:06:00 | WinXP | 119.11.26.56 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:02:07:00 | WinXP | 208.125.40.153 (RR.COM): ROAD RUNNER HOLDCO LLC, BINGHAMTON, NEW YORK, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:49:00 | Win2K-f | 24.213.224.238 (RR.COM): ROAD RUNNER HOLDCO LLC, AMSTERDAM, NEW YORK, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:49:00 | WinXP | 83.68.70.41 (TNP.PL): TELENETCENTRUM-NET, PL. |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | 5818023061 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:04:14:00 | WinXP | 114.48.184.106 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:04:19:00 | Win2K-f | 174.100.143.43 (-): . |
92.240.234.164:3305 | FI:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 695 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:06:10:00 | WinXP | 69.85.123.4 (SPEAKEASY.NET): US. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
35 of 35 | 9716d7995a NEW |
c3a5354b6f [0] | none:none |
PolyEnE| | none | trace |
T:06:35:00 | WinXP | 207.5.200.31 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:07:00 | Win2K-f | 218.32.97.21 (SPARQNET.NET): NEW CENTRY INFOCOMM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 115 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 37 of 41 |
a205366bef NEW efaef2451a NEW |
82bbbe4789 [0] 5382f9a037[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:07:13:00 | WinXP | 124.147.70.74 (DY.BBEXCITE.JP): INTERNET INITIATIVE JAPAN INC, TOKYO, TOKYO, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:10:04:00 | WinXP | 62.183.113.59 (ASTRANET.RU): ISP ASTRANET, RU. (DIAL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | none:none |
PolyEnE| | none | trace |
T:10:06:00 | WinXP | 76.198.236.234 (SBCGLOBAL.NET): PPPOX POOL - BRAS6.STLSMO, DALLAS, TEXAS, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 36 | b27d73bfcb NEW |
473c6454ce [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:10:16:00 | Win2K-f | 211.200.26.78 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
218.93.205.30:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:www.brans.pl CN:dl.guarddog2009.com CN:gidromash.cn CN:ottopay.cn :www.petdoso.com 174.36.176.242:81 |
135 | pcap | raw alerts ruleset |
irc http 136 lines |
Yeah : 1.8 profile |
none | summary tarball |
7 of 41 21 of 41 12 of 40 30 of 33 28 of 33 23 of 41 |
18dfbbc85b NEW 1b7635d92c NEW 38e8f258e7 NEW 533d15b5ce NEW 58c343a8d8 NEW 5d721a4dee NEW |
4f6fcecea3 [0] 28cf6965a6[0] 871a2e904e[0] c67adf46e2[0] none [0] 6afc8cafab[0] |
none:none none:none none:none ASM:Graph none:none none:none |
UPX| MEW| none|none tElock| Armadillo| UPX| |
none none none lines=126 embedded dns lines=91 none |
trace trace trace trace trace trace |
T:10:51:00 | WinXP | 114.137.47.246 (-): . |
213.219.245.212:80 | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | eda3b7766c NEW |
7556343561 [0] | none:none |
PolyEnE| | none | trace |
T:11:20:00 | WinXP | 189.100.225.245 (-): . |
n/a | :teek.ihshsd8.com :japan.youngpeyatech.info CN:italian.swiifatecihno.com |
135 | pcap | raw alerts ruleset |
irc http 324 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 23 of 41 |
3187c04a81 NEW 3c77533bf6 NEW |
a957ba14f1 [0] 389c06c67e[0] |
none:none none:none |
StarForce| StarForce| |
none none |
trace trace |
T:12:39:00 | WinXP | 24.79.232.95 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, EDMONTON, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 415 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | d1255d0f2b NEW |
e71a1b3698 [0] | none:none |
ASPack| | none | trace | |
T:13:26:00 | Win2K-f | 172.190.138.231 (AOL.COM): AMERICA ONLINE, RESTON, VIRGINIA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 173 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 41 38 of 41 |
7b80e9ed5e NEW ab23041bf9 NEW |
5a7df285a0 [0] ea38647e80[0] |
none:none none:none |
FASM| tElock| |
none none |
trace trace |
T:15:04:00 | WinXP | 203.114.106.147 (-): TOT IP NETWORK IP ADDRESS POOL IN BRAS FOR ADSL SERVICES AT LADYA POP, TH. |
n/a | 135 | pcap | raw alerts ruleset |
other 369 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 088b8886e9 NEW |
8f6217c3a5 [0] | none:none |
none|none | none | trace | |
T:15:29:00 | WinXP | 66.53.81.237 (MDSG-PACWEST.COM): PAC-WEST MANAGED MODEM NAS POOL, PHOENIX, ARIZONA, US. |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:16:42:00 | WinXP | 83.97.217.87 (CM-83-97-128-10.TELECABLE.ES): TELECABLE, GIJON, ASTURIAS, ES. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1fcc146d70 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:17:10:00 | WinXP | 61.218.193.250 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 87 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:17:22:00 | WinXP | 211.206.133.90 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:17:32:00 | WinXP | 68.146.210.170 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1008 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 41 | 682a384fe9 NEW |
none[3] | none:none |
none|none | none | trace | |
T:17:41:00 | WinXP | 67.242.129.65 (-): . |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:17:57:00 | Win2K-f | 64.144.35.70 (LADDFINANCIAL.COM): DSL.NET INC, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:02:00 | Win2K-f | 211.20.222.150 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
92.240.234.164:3305 | JP:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 695 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:21:33:00 | WinXP | 114.48.7.104 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:21:34:00 | WinXP | 113.254.98.8 (-): . |
n/a | :abc.ihshsd8.com CN:russia.blacktiehsbdcs.com :munirah.nagitiriheiwu.net :jiets.soidudrf.com CN:218.61.22.10:7575 |
135 | pcap | raw alerts ruleset |
other 526 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 14c118316b NEW |
none[4] | none:none |
FSG| | none | trace |
T:21:55:00 | WinXP | 98.140.249.72 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:22:34:00 | WinXP | 122.53.91.224 (PLDT.NET): IPG, PH. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 120 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 39 36 of 39 |
ee4c5c80ea NEW f37bd4ab26 NEW |
28944e2541 [0] c78cfe6339[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=42 lines=64 embedded dns |
trace trace |
T:23:17:00 | WinXP | 174.6.21.151 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:23:27:00 | WinXP | 63.26.10.81 (UU.NET): UUNET TECHNOLOGIES INC, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 168 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |