Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:39:00 | WinXP | 114.38.109.212 (-): . |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | aab1b56620 NEW |
3b2e1c5b9d [0] | none:none |
PolyEnE| | none | trace |
T:01:27:00 | WinXP | 78.82.192.63 (TELENOR.SE): TELENOR BUSINESS SOLUTION AB, SE. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:03:05:00 | Win2K-f | 61.101.18.156 (HAEDONGTEK.CO.KR): THRUNET CO. LTD, SEOUL, KYONGGI-DO, KR. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:15:00 | WinXP | 98.141.30.215 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:04:12:00 | WinXP | 79.163.207.99 (-): IDEA, PL. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 40 | b41ac85a53 NEW |
3e23c7ba7b [0] | none:none |
PolyEnE| | none | trace |
T:04:25:00 | Win2K-f | 63.246.122.215 (SPEAKEASY.NET): US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:04:41:00 | WinXP | 114.48.22.185 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:06:14:00 | WinXP | 115.81.167.196 (-): . |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 74c3429921 NEW |
1265c25f7f [0] | none:none |
PolyEnE| | none | trace |
T:06:38:00 | Win2K-f | 70.167.73.201 (COX.NET): COX COMMUNICATIONS, VINCENNES, INDIANA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:51:00 | WinXP | 93.102.1.91 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | US:www.altavista.com :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 17028f1eda NEW |
none[3] | none:none |
tElock| | none | trace |
T:07:59:00 | Win2K-f | 24.234.68.126 (COX.NET): COX COMMUNICATIONS INC, LAS VEGAS, NEVADA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:08:21:00 | WinXP | 61.221.226.3 (HINET.NET): DATA COMMUNICATION BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:08:31:00 | Win2K-f | 118.87.20.81 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 331 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 820b27d4c6 NEW |
1102de0215 [0] | none:none |
Armadillo| | none | trace | |
T:10:06:00 | WinXP | 195.252.86.137 (BEOTEL.NET): BEOTELNET-ISPMODEMI, CS. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:11:21:00 | WinXP | 89.195.207.45 (-): ORANGE, UK. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 0cfab99612 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:11:27:00 | WinXP | 189.97.243.145 (-): . |
213.219.245.212:80 | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 40 | 824d6a706e NEW |
a66fd13bcb [0] | none:none |
PolyEnE| | none | trace |
T:11:30:00 | WinXP | 87.123.178.90 (VERSANET.DE): VERSATEL DEUTSCHLAND DYNAMIC POOL, DE. |
n/a | 445 | pcap | raw alerts ruleset |
shell 4 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:12:49:00 | WinXP | 92.226.93.94 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | :jiets.soidudrf.com CN:bti.jeiahsdod.net |
135 | pcap | raw alerts ruleset |
irc http 430 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 41 29 of 32 |
3c77533bf6 NEW d74613e216 NEW |
389c06c67e [0] d74613e216[1] |
none:none ASM:Graph |
StarForce| ASProtect| |
none lines=45 |
trace trace |
T:13:29:00 | WinXP | 87.123.188.99 (VERSANET.DE): VERSATEL DEUTSCHLAND DYNAMIC POOL, DE. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 9 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:51:00 | WinXP | 41.202.177.49 (-): . |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 7f38ca84af NEW |
89991cf07f [0] | none:none |
PolyEnE| | none | trace |
T:15:22:00 | WinXP | 89.111.226.218 (TEOL.NET): TELEKOMSRPSKE, BA. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | f54691063f NEW |
6039c698cd [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:18:01:00 | Win2K-f | 4.131.156.249 (APEXCOVANTAGE.COM): LEVEL 3 COMMUNICATIONS INC, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
94d593200e NEW e7d2955781 NEW |
14c35aa65e [0] da13cb0c9c[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:18:34:00 | WinXP | 69.111.90.215 (PACBELL.NET): CHI2CA INTERNAL, CHICO, CALIFORNIA, US. (DIAL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:19:51:00 | WinXP | 122.146.80.231 (SPARQNET.NET): NEW CENTURY INFOCOMM TECH. CO. LTD, TW. |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:20:41:00 | WinXP | 76.8.230.207 (TELAPEX.COM): TELEPAK NETWORKS INC, JACKSON, MISSISSIPPI, US. |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:21:02:00 | WinXP | 68.123.255.190 (PACBELL.NET): PPPOX POOL - BRAS1 IRVNCA, LOS ANGELES, CALIFORNIA, US. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | d6df3972a0 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=65 | trace |
T:21:32:00 | WinXP | 96.51.42.224 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 250 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | bd133be999 NEW |
503a67cfa9 [0] | none:none |
StarForce| | none | trace | |
T:22:27:00 | WinXP | 96.13.17.241 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 812 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 40 | 8f0bb9144b NEW |
7583fe4738 [0] | none:none |
Armadillo| | none | trace | |
T:22:31:00 | Win2K-f | 4.162.156.191 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, MEMPHIS, TENNESSEE, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 84 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | c6519a27ba NEW |
389cdefb96 [0] | none:none |
Armadillo| | none | trace |