Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:07:00 | WinXP | 119.228.80.212 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 2cb7fb5674 NEW |
4bf8dcd347 [0] | none:none |
none|none | none | trace | |
T:00:12:00 | WinXP | 96.11.133.187 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:01:08:00 | Win2K-f | 116.127.127.93 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR. |
218.93.205.30:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:www.brans.pl CN:gidromash.cn CN:211.95.79.170:80 CN:218.93.205.19:80 CN:218.93.205.30:65520 |
135 | pcap | raw alerts ruleset |
irc 131 lines |
Yeah : 1.8 profile |
none | summary tarball |
29 of 32 28 of 32 |
8a75955033 NEW 9276c8b36b NEW |
2bf3e548b9 [0] none [0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=126 embedded dns lines=81 |
trace trace |
T:04:18:00 | WinXP | 60.56.99.192 (EONET.NE.JP): K-OPTICOM CORPORATION, OSAKA, OSAKA, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | ASM:Graph |
none|none | lines=61 | trace | |
T:04:22:00 | Win2K-f | 172.130.223.208 (AOL.COM): AMERICA ONLINE, RESTON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 106 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:04:41:00 | Win2K-f | 24.86.71.239 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SURREY, BRITISH COLUMBIA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:06:24:00 | Win2K-f | 207.5.236.176 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:54:00 | Win2K-f | 96.8.204.191 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:09:58:00 | WinXP | 87.173.120.188 (T-IPCONNECT.DE): DEUTSCHE TELEKOM AG, DE. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:10:21:00 | WinXP | 66.184.4.23 (LDMI.COM): TALK AMERICA, DETROIT, MICHIGAN, US. |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
35 of 36 | b27d73bfcb NEW |
473c6454ce [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:10:40:00 | Win2K-f | 114.205.180.89 (-): . |
218.93.205.30:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:dl.guarddog2009.com CN:gidromash.cn CN:211.95.79.170:80 CN:218.93.205.19:80 |
135 | pcap | raw alerts ruleset |
irc 127 lines |
Yeah : 1.8 profile |
none | summary tarball |
29 of 32 28 of 32 |
8a75955033 NEW 9276c8b36b NEW |
2bf3e548b9 [0] none [0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=126 embedded dns lines=81 |
trace trace |
T:11:05:00 | WinXP | 61.59.150.186 (SEED.NET.TW): DIGITAL UNITED INC, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | e70e195b77 NEW |
3d277747d3 [0] | none:none |
PolyEnE| | none | trace |
T:11:14:00 | WinXP | 114.48.30.243 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:12:12:00 | Win2K-f | 66.19.3.93 (USLEC.NET): USLEC CORP, WORCESTER, MASSACHUSETTS, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:21:00 | WinXP | 174.7.12.128 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:13:38:00 | WinXP | 172.129.139.131 (AOL.COM): AMERICA ONLINE, RESTON, VIRGINIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 168 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | 73f1082158 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:14:39:00 | WinXP | 218.220.142.12 (ZAQ.NE.JP): KITAKAWACHI CABLE NET CO LTD, OSAKA, OSAKA, JP. |
n/a | CN:done.blacktiehsbdcs.com | 135 | pcap | raw alerts ruleset |
irc http 589 lines |
Yeah : 1.3 profile |
none | summary tarball |
23 of 41 39 of 40 |
3c77533bf6 NEW d8b652221d NEW |
389c06c67e [0] edfa4116ba[0] |
none:none none:none |
StarForce| ASPack| |
none none |
trace trace |
T:15:06:00 | WinXP | 173.29.130.232 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 38 of 40 |
067917e07b NEW d764c1dcb2 NEW |
dae35b319c [0] 3d2bc60c5d[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:16:21:00 | WinXP | 122.30.183.72 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:17:05:00 | WinXP | 219.122.214.29 (EONET.NE.JP): K-OPTICOM CORPORATION, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 2cb7fb5674 NEW |
4bf8dcd347 [0] | none:none |
none|none | none | trace | |
T:18:17:00 | WinXP | 72.181.45.25 (RR.COM): ROAD RUNNER HOLDCO LLC, HOUSTON, TEXAS, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:59:00 | WinXP | 95.93.192.191 (-): . |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | a1f992a08e NEW |
75ca0b4a8f [0] | none:none |
PolyEnE| | none | trace |
T:20:02:00 | Win2K-f | 70.123.103.157 (RR.COM): ROAD RUNNER HOLDCO LLC, LEAGUE CITY, TEXAS, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 414 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | fd120fafac NEW |
3fbd04c869 [0] | none:none |
PENinja S| | none | trace | |
T:20:03:00 | WinXP | 68.125.24.230 (PACBELL.NET): PPPOX POOL - BRAS1 IRVNCA, LOS ANGELES, CALIFORNIA, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | d6df3972a0 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=65 | trace |
T:21:29:00 | WinXP | 119.228.209.183 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 7b313206a2 NEW |
0c866c8cce [0] | none:none |
none|none | none | trace | |
T:21:47:00 | WinXP | 119.228.136.40 (-): . |
n/a | US:mx1.hotmail.com US:ftp.newaol.com US:mailin-02.mx.aol.com US:yutunrz.1dumb.com US:mailin-01.mx.aol.com :wpad |
445 | pcap | raw alerts ruleset |
shell ftp http http 174 lines |
Yeah : 1.3 profile |
none | summary tarball |
1 of 41 38 of 41 1 of 41 |
3137f0c609 NEW 85ea746b9a NEW bf01cf2a15 NEW |
cb9eaddc3c [0] 54e7ab3f6f[0] cb9eaddc3c[0] |
none:none none:none none:none |
Free| none|none Free| |
none none none |
trace trace trace |
T:22:09:00 | WinXP | 222.127.187.88 (SUMIFRU.COM): GLOBE TELECOM/INNOVE COMMUNICATION, PH. |
n/a | US:mx1.hotmail.com US:mailin-04.mx.aol.com US:ftp.newaol.com US:yutunrz.1dumb.com US:mailin-02.mx.aol.com US:ftp.icq.com US:mcduii.3-a.net US:http.icq.com.edgesuite.net |
445 | pcap | raw alerts ruleset |
http http 105 lines |
Yeah : 0.8 profile |
none | summary tarball |
1 of 41 | 3137f0c609 NEW |
cb9eaddc3c [0] | none:none |
Free| | none | trace |
T:22:44:00 | WinXP | 113.252.241.214 (-): . |
n/a | US:imtoey.3-a.net BE:ftp.scarlet.be US:yutunrz.1dumb.com US:ftp.icq.com US:http.icq.com.edgesuite.net US:mx1.hotmail.com US:mailin-04.mx.aol.com US:ftp.newaol.com US:mailin-01.mx.aol.com BE:193.74.22.160:80 |
135 | pcap | raw alerts ruleset |
http http http 120 lines |
Yeah : 1.3 profile |
none | summary tarball |
1 of 41 | edcdbe29d1 NEW |
cb9eaddc3c [0] | none:none |
Free| | none | trace |