Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:02:02:00 | WinXP | 67.123.204.202 (PACBELL.NET): RICHARD MULHALL, SAN FRANCISCO, CALIFORNIA, US. (DSL) |
n/a | CA:xx.ka3ek.com :idfc.info |
135 | pcap | raw alerts ruleset |
irc http 622 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 29 of 41 32 of 38 |
3842e66ff7 NEW 39336e51eb NEW 524bc0f75c NEW |
fc7c8aaf10 [0] 3f5ab71d39[0] d3e9510bb3[0] |
none:none none:none none:none |
EXECrypto| Neolite| PENinja S| |
none none none |
trace trace trace |
T:03:09:00 | Win2K-f | 116.127.127.93 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR. |
218.93.205.30:65520 | US:microsoft.com CN:proxim.ircgalaxy.pl CN:gidromash.cn CN:211.95.79.170:80 |
135 | pcap | raw alerts ruleset |
irc 135 lines |
Yeah : 1.8 profile |
none | summary tarball |
29 of 32 28 of 32 |
8a75955033 NEW 9276c8b36b NEW |
2bf3e548b9 [0] none [0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=126 embedded dns lines=81 |
trace trace |
T:03:29:00 | WinXP | 69.235.213.5 (PACBELL.NET): RBACK30B.IRVNCA, LOS ANGELES, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:34:00 | Win2K-f | 114.137.71.49 (-): . |
91.212.220.75:65520 | CN:proxim.ircgalaxy.pl CN:dl.guarddog2009.com CN:gidromash.cn CN:211.95.79.170:80 CN:218.93.205.19:80 |
445 | pcap | raw alerts ruleset |
irc 19 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:05:28:00 | WinXP | 219.110.47.32 (CATV02.ITSCOM.JP): ITS COMMUNICATIONS INC, TOKYO, TOKYO, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:08:29:00 | WinXP | 116.81.71.33 (INFOWEB.NE.JP): INFOWEB(FUJITSU LTD.), JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
03eb887daa NEW 1179d0de83 NEW |
71e224b041 [0] ab96b69318[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:09:05:00 | WinXP | 119.154.25.121 (-): . |
213.219.245.212:80 | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 109188d5f8 NEW |
aa7be7c5d9 [0] | none:none |
PolyEnE| | none | trace |
T:09:56:00 | WinXP | 85.152.138.216 (CM-85-152-150-10.TELECABLE.ES): TELECABLE, GIJON, ASTURIAS, ES. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | eda3b7766c NEW |
7556343561 [0] | none:none |
PolyEnE| | none | trace |
T:10:00:00 | WinXP | 4.156.234.24 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, BOSTON, MASSACHUSETTS, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 143 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 36 of 41 |
84ace068d1 NEW c584af4fcd NEW |
c822a7d0e4 [0] bdfcf0a930[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:10:46:00 | WinXP | 115.82.221.168 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:11:49:00 | Win2K-f | 68.149.138.254 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, EDMONTON, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 402 lines |
Yeah : 1.3 profile |
none | summary tarball |
11 of 36 | c4c5a56ffe NEW |
8bef2f9170 [0] | none:none |
StarForce| | none | trace | |
T:12:46:00 | Win2K-f | 61.221.237.252 (HINET.NET): DATA COMMUNICATION BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TW. |
n/a | 135 | pcap | raw alerts ruleset |
other 1002 lines |
Yeah : 1.3 profile |
none | summary tarball |
17 of 41 | e1693609f9 NEW |
none[3] | none:none |
none|none | none | trace | |
T:12:56:00 | WinXP | 69.201.142.98 (RR.COM): ROAD RUNNER HOLDCO LLC, NEW YORK, NEW YORK, US. |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:splegacy.information.com US:spi.domainsponsor.com GB:welcome3.smile.co.uk :wpad GB:195.92.84.198:80 |
445 | pcap | raw alerts ruleset |
http http http 30 lines |
Yeah : 0.8 profile |
none | summary tarball |
0 of 41 29 of 29 0 of 41 |
8f490cc57d NEW a12cab51ef NEW db29fa6a62 NEW |
none[4] none [0] none [4] |
none:none none:none none:none |
none|none ASPack| none|none |
none lines=281 embedded dns none |
trace trace trace |
T:13:21:00 | WinXP | 72.187.130.172 (RR.COM): ROAD RUNNER HOLDCO LLC, LAND O LAKES, FLORIDA, US. |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 9d8ec60aeb NEW |
97d170c714 [0] | none:none |
PolyEnE| | none | trace |
T:13:40:00 | Win2K-f | 196.208.71.102 (TELKOM-IPNET.CO.ZA): AFRINIC, JOHANNESBURG, GAUTENG, ZA. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 133 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 39 of 41 |
1bc51bf964 NEW e33c8e30b9 NEW |
4ab7eeaf6c [0] 95caa6a57d[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:14:49:00 | Win2K-f | 97.107.33.63 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:14:54:00 | WinXP | 24.231.90.132 (PERSONAINC.NET): PERSONA COMMUNICATIONS INC, CA. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:15:00:00 | WinXP | 71.148.35.37 (SBCGLOBAL.NET): KASSA KASSA, PLANO, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:33:00 | Win2K-f | 71.189.119.92 (-): LINDA LIU, ONTARIO, CALIFORNIA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:41:00 | WinXP | 74.215.65.114 (FUSE.NET): FUSE INTERNET ACCESS, CINCINNATI, OHIO, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 39 of 41 |
8459377032 NEW 8c3fbe8572 NEW |
2f809ba47f [0] 6d017d228b[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:16:55:00 | WinXP | 71.74.122.21 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 36 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 | 53bfe15e91 NEW |
1473091351 [0] | ASM:Graph |
tElock| | lines=75 embedded dns |
trace |
T:17:42:00 | Win2K-f | 210.233.207.180 (MEDIATTI.NET): MEDIATTI COMMUNICATIONS INC, OKINAWA, OKINAWA, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 88 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 33 33 of 33 |
3ed16ae12d NEW 79c01ec060 NEW |
none[0] 1bfd34056c[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=64 embedded dns |
trace trace |
T:19:06:00 | Win2K-f | 174.3.91.226 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 420 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 33e758de52 NEW |
cdb2e7c60a [0] | none:none |
StarForce| | none | trace | |
T:19:16:00 | WinXP | 70.138.7.167 (SBCGLOBAL.NET): PPPOX POOL - BRAS12.MRDNCT, SEYMOUR, CONNECTICUT, US. (DSL) |
n/a | US:www.altavista.com US:www.yahoo.com :jbeegvia.ru US:www.worldbank.org EU:crutop.nu :yoiayoi.ru :wcqahzhzn.ru :iirpryry.ru :rihafvu.ru :ryryodokm.ru :wpad :uvjiis.ru :gwvwka.ru :jqsbnyzkp.ru :pvygdo.ru :fxkyagpnw.ru :knclvdz.ru :trsqeigw.ru :odokeqy.ru :kelmpsjp.ru :edjiesp.ru :vllcdvv.ru :nuksdln.ru :tmmeno.ru :zoxdgqx.ru :pwvbfz.ru :nuzbcp.ru :bqpuqt.ru :okskyyn.ru :pnlkria.ru RU:alfabank.ru :kargai.ru RU:prodexteam.net :kfwfceki.ru :nhuwxyuw.ru :udluzuq.ru GB:www.candidateverifier.com NL:www.viruslist.com :fiazpvnne.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | bb7681eca8 NEW |
none[3] | none:none |
tElock| | none | trace |
T:19:57:00 | WinXP | 64.203.49.114 (MINDSPRING.COM): EARTHLINK INC, SAN DIEGO, CALIFORNIA, US. (DSL) |
n/a | EU:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :wpad GB:new.egg.com |
445 | pcap | raw alerts ruleset |
http http http http 43 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee NEW |
none[0] | none:none |
ASPack| | lines=298 embedded dns |
trace |
T:20:10:00 | WinXP | 76.8.230.207 (TELAPEX.COM): TELEPAK NETWORKS INC, JACKSON, MISSISSIPPI, US. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 41 26 of 28 |
7d89e4dffc NEW 7d99b0e910 NEW |
a9315eb14c [0] none [0] |
none:none none:none |
FASM| PolyEnE| |
none lines=68 |
trace trace |
T:20:21:00 | WinXP | 114.137.243.253 (-): . |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | eda3b7766c NEW |
7556343561 [0] | none:none |
PolyEnE| | none | trace |
T:21:17:00 | WinXP | 200.31.8.59 (IMPSAT.NET.EC): IMPSAT ECUADOR-INTERNET DIALUP, QUITO, PICHINCHA, EC. |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 36 | 96d089e522 NEW |
b9dd25bdfb [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
T:23:29:00 | WinXP | 87.55.74.30 (IP.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, DK. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | b26ed6eeac NEW |
97c1157bf8 [0] | none:none |
PolyEnE| | none | trace |
T:23:31:00 | WinXP | 114.48.3.23 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace |