Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:22:00 | Win2K-f | 74.214.47.11 (METROCAST.NET): GMP CABLE TV, BERWICK, PENNSYLVANIA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 298 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 33 | fe22b8315f NEW |
bb25603f41 [0] | none:none |
StarForce| | none | trace | |
T:01:54:00 | WinXP | 203.118.238.245 (-): GRAND TAINAN TECHNOLOGY CO.LTD, TAINAN, KAO-HSIUNG, TW. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:05:00 | Win2K-f | 203.54.167.237 (TMNS.NET.AU): TELSTRAINTERNET5, SYDNEY, NEW SOUTH WALES, AU. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 132 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:03:28:00 | WinXP | 193.250.134.53 (ABO.WANADOO.FR): IP2000-ADSL-BAS, FR. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:03:36:00 | WinXP | 218.163.44.227 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
213.219.245.212:80 | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | ed96c03ca8 NEW |
c0028e9e98 [0] | none:none |
PolyEnE| | none | trace |
T:05:50:00 | WinXP | 219.254.99.231 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
218.93.205.30:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:gidromash.cn CN:211.95.79.170:80 |
135 | pcap | raw alerts ruleset |
irc 153 lines |
Yeah : 1.8 profile |
none | summary tarball |
30 of 33 31 of 33 |
87bd0a062f NEW c7d6018f97 NEW |
dc70d9623a [0] 5c1d8bbd5b[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:07:00:00 | Win2K-f | 75.60.192.208 (SBCGLOBAL.NET): PPPOX POOL - SE1.WOTNOH, COLUMBUS, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:33:00 | WinXP | 86.105.216.12 (PANEVO.RO): SC PAN ELECTRO SRL, RO. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | ed96c03ca8 NEW |
c0028e9e98 [0] | none:none |
PolyEnE| | none | trace |
T:07:40:00 | WinXP | 75.50.255.74 (SBCGLOBAL.NET): PPPOX POOL - RBACK6.MILWWI, MILWAUKEE, WISCONSIN, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | 03f912899b NEW |
none[0] | none:none |
none|none | lines=64 | trace | |
T:08:11:00 | WinXP | 193.250.12.56 (ABO.WANADOO.FR): WANADOO, DIJON, BOURGOGNE, FR. |
n/a | EU:siliconfireware.ru US:searchportal.information.com :wpad US:208.73.210.125:80 |
445 | pcap | raw alerts ruleset |
http http http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee NEW |
none[0] | none:none |
ASPack| | lines=298 embedded dns |
trace |
T:08:22:00 | WinXP | 92.40.221.126 (IKBCC.COM): EU-ZZ, UK. |
n/a | DE:siliconfireware.ru US:searchportal.information.com RU:www.bbin.ru RU:www.binbank.ru :wpad US:spi.domainsponsor.com US:208.73.210.125:80 |
445 | pcap | raw alerts ruleset |
http http http http 32 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | c4ab97fc12 NEW |
50ed7b9394 [0] | none:none |
ASPack| | none | trace |
T:09:07:00 | Win2K-f | 121.121.155.116 (MAXIS.NET.MY): MAXIS COMMUNICATIONS BHD, MY. |
n/a | CZ:qtas.net | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
12 of 41 | 2a27386964 NEW |
af2777b025 [0] | none:none |
FASM| | none | trace |
T:10:09:00 | Win2K-f | 4.167.92.209 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 28 lines |
Yeah : 1.3 profile |
none | summary tarball |
5 of 41 | 3fe7912340 NEW |
none[3] | none:none |
FASM| | none | trace | |
T:10:11:00 | Win2K-f | 113.255.102.60 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 11 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:11:47:00 | WinXP | 87.116.205.58 (TNP.PL): BROADBAND_SERVICES, PL. |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | 5818023061 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:12:26:00 | Win2K-f | 4.233.127.63 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, LOS ANGELES, CALIFORNIA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:43:00 | WinXP | 64.144.35.70 (LADDFINANCIAL.COM): DSL.NET INC, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:44:00 | WinXP | 84.47.201.114 (-): PARSCYBERIAN CONSULTANTS, AE. |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :vit.ln.ua GB:new.egg.com :wpad |
445 | pcap | raw alerts ruleset |
http http http 38 lines |
Yeah : 0.8 profile |
none | summary tarball |
30 of 32 | 7dd1fe2970 NEW |
none[0] | ASM:Graph |
ASPack| | lines=374 embedded dns |
trace |
T:14:03:00 | WinXP | 85.174.24.246 (RUNEXT.COM): PROVIDER LOCAL REGISTRY, RU. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | aab1b56620 NEW |
3b2e1c5b9d [0] | none:none |
PolyEnE| | none | trace |
T:14:36:00 | WinXP | 72.181.45.25 (RR.COM): ROAD RUNNER HOLDCO LLC, HOUSTON, TEXAS, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:43:00 | Win2K-f | 4.225.23.3 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, KOKOMO, INDIANA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:50:00 | WinXP | 71.108.148.40 (VERIZON.NET): VERIZON INTERNET SERVICES INC, HUNTINGTON BEACH, CALIFORNIA, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 9fe0ab64c0 NEW |
60b46aa7dd [0] | none:none |
none|none | none | trace | |
T:14:56:00 | WinXP | 75.49.12.225 (SBCGLOBAL.NET): PPPOX POOL - SE1.WOTNOH 101906-1259, COLUMBUS, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:15:37:00 | WinXP | 64.203.49.113 (MINDSPRING.COM): EARTHLINK INC, SAN DIEGO, CALIFORNIA, US. (DSL) |
n/a | EU:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :wpad US:splegacy.information.com RU:www.bbin.ru RU:www.binbank.ru |
445 | pcap | raw alerts ruleset |
http http http http 49 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee NEW |
none[0] | none:none |
ASPack| | lines=298 embedded dns |
trace |
T:19:08:00 | WinXP | 189.97.58.27 (-): . |
213.219.245.212:80 | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | eda3b7766c NEW |
7556343561 [0] | none:none |
PolyEnE| | none | trace |
T:19:14:00 | Win2K-f | 208.79.59.198 (GROUPTELECOM.NET): 3757277 CANADA INC. (OA 295.CA), KITCHENER, ONTARIO, CA. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 160 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:19:55:00 | Win2K-f | 174.6.206.210 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:20:11:00 | Win2K-f | 70.184.219.41 (COX.NET): COX COMMUNICATIONS, OMAHA, NEBRASKA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 1008 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 41 | a34194ff12 NEW |
none[3] | none:none |
none|none | none | trace | |
T:20:38:00 | WinXP | 68.124.62.159 (PACBELL.NET): PPPOX POOL - BRAS1 IRVNCA, LOS ANGELES, CALIFORNIA, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | d6df3972a0 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=65 | trace |
T:21:16:00 | WinXP | 61.62.45.220 (SO-NET.NET.TW): SONY NETWORK TAIWAN LIMITED, TAIPEI, T'AI-PEI, TW. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | eda3b7766c NEW |
7556343561 [0] | none:none |
PolyEnE| | none | trace |
T:21:58:00 | WinXP | 110.12.67.17 (-): . |
218.93.205.30:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com |
135 | pcap | raw alerts ruleset |
irc 139 lines |
Yeah : 1.8 profile |
none | summary tarball |
37 of 41 38 of 41 |
598636aa73 NEW a57ddcdef0 NEW |
613af3f9a2 [0] none [4] |
none:none none:none |
Armadillo| PolyEnE| |
none none |
trace trace |
T:22:11:00 | WinXP | 122.146.83.69 (SPARQNET.NET): NEW CENTURY INFOCOMM TECH. CO. LTD, TW. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |