Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:23:00 | WinXP | 79.163.108.136 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
35 of 36 | 06a5e31b47 NEW |
25e6e52787 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:02:06:00 | WinXP | 89.111.226.236 (PALEOL.NET): NF-TEL D.O.O, SARAJEVO, FEDERATION OF BOSNIA AND HERZEGOVINA, BA. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | f54691063f NEW |
6039c698cd [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:02:38:00 | Win2K-f | 118.87.8.68 (ODWR.J-CNET.JP): ODAWARA CABLETV INTERNET SERVICE, ODAWARA, KANAGAWA, JP. (DSL) |
92.240.234.164:3305 | JP:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 603 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 41 | 79852d4022 NEW |
3232618771 [0] | none:none |
StarForce| | none | trace |
T:03:43:00 | Win2K-f | 98.141.30.215 (CAVTEL.NET): CAVALIER TELEPHONE, NORFOLK, VIRGINIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:04:30:00 | WinXP | 83.68.65.111 (TNP.PL): TELENETCENTRUM-NET, WARSAW, WARSZAWA, PL. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | 5818023061 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
05:09:00 | Win2K-f | 77.37.163.3 (NATIONALCABLENETWORKS.RU): NCN-INFRA, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org US:getmyip.co.uk :checkip.dyndns.org 208.78.70.70:80 US:65.254.39.170:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:06:42:00 | WinXP | 151.82.179.197 (51-151.NET24.IT): IUNET-BNET, IT. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:07:01:00 | WinXP | 203.54.163.94 (TMNS.NET.AU): TELSTRAINTERNET5, SYDNEY, NEW SOUTH WALES, AU. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:07:57:00 | WinXP | 122.220.143.197 (UCOM.NE.JP): TKMITAU, TOKYO, TOKYO, JP. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:08:37:00 | WinXP | 94.153.30.0 (KYIVSTAR.NET): UA-KYIVSTAR, KIEV, KYYIV, UA. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | b2d26563e4 NEW |
03e1f7bcc7 [0] | none:none |
PolyEnE| | none | trace |
T:09:48:00 | WinXP | 173.20.140.66 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, ALBANY, GEORGIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 39 of 41 |
5e3a9c2d9d NEW 630308d06b NEW |
dbc48b815a [0] 847d302e37[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:10:27:00 | WinXP | 12.74.167.212 (ATT.NET): AT&T WORLDNET SERVICES, NEW CASTLE, DELAWARE, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:11:41:00 | WinXP | 117.254.8.60 (STERLINGSTUDENTS.NET): NIB (NATIONAL INTERNET BACKBONE), NEW DELHI, DELHI, IN. (DSL) |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | d6df3972a0 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=65 | trace |
T:12:59:00 | Win2K-f | 70.117.157.9 (RR.COM): ROAD RUNNER HOLDCO LLC, LUMBERTON, NORTH CAROLINA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:13:11:00 | WinXP | 64.33.132.6 (AIRSTREAMCOMM.NET): TRI COUNTY TELEPHONE, WISCONSIN, US. (DIAL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 0cfab99612 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:14:58:00 | WinXP | 97.107.33.63 (DCWIS.COM): ONLINE DOOR COUNTY, FISH CREEK, WISCONSIN, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:17:22:00 | WinXP | 165.247.1.101 (MINDSPRING.COM): EARTHLINK INC, BOSTON, MASSACHUSETTS, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 142 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:17:29:00 | Win2K-f | 116.127.80.191 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
91.212.220.75:65520 | EU:proxima.ircgalaxy.pl US:microsoft.com EU:gidromash.cn EU:ottopay.cn :nenastiya.cn US:mssecur.com US:64.235.53.208:80 |
135 | pcap | raw alerts ruleset |
irc http 128 lines |
Yeah : 1.8 profile |
none | summary tarball |
3 of 41 34 of 36 29 of 32 7 of 41 |
91ff6ae755 NEW 99b248336f NEW 9d677c3f70 NEW c7830331fc NEW |
ea99083d64 [0] c64bd1a776[0] 77e75ff10f[0] 7953649664[0] |
none:none none:none none:none none:none |
StarForce| Armadillo| tElock| tElock| |
none none none none |
trace trace trace trace |
T:17:49:00 | Win2K-f | 130.13.145.197 (QWEST.NET): QWEST BROADBAND SERVICES INC, PHOENIX, ARIZONA, US. (DSL) |
218.93.205.30:65520 | EU:proxima.ircgalaxy.pl EU:gidromash.cn EU:ottopay.cn US:64.235.53.208:80 |
445 | pcap | raw alerts ruleset |
irc http 17 lines |
Yeah : 0.8 profile |
none | summary tarball |
7 of 41 | c7830331fc NEW |
7953649664 [0] | none:none |
tElock| | none | trace |
T:18:36:00 | WinXP | 203.88.185.238 (CTT.NE.JP): CABLE TELEVISION TOYAMA INCORPORETED, TOYAMA, TOYAMA, JP. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1003 lines |
Yeah : 1.3 profile |
none | summary tarball |
9 of 41 | 1ec665aee0 NEW |
none[3] | none:none |
ASProtect| | none | trace | |
T:19:01:00 | WinXP | 115.165.79.231 (CATV02.ITSCOM.JP): ITS COMMUNICATIONS INC, YOKOHAMA, KANAGAWA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:19:17:00 | Win2K-f | 211.20.222.150 (HINET.NET): XUN HANG TECHNOLOGY CO. LTD, TAIPEI, T'AI-PEI, TW. (100Mbps) |
92.240.234.164:3305 | TH:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 695 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:19:33:00 | Win2K-f | 70.60.2.234 (RR.COM): ROAD RUNNER HOLDCO LLC, COLUMBUS, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:19:37:00 | Win2K-f | 196.208.67.97 (TELKOMADSL.CO.ZA): AFRINIC, JOHANNESBURG, GAUTENG, ZA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:08:00 | WinXP | 74.215.65.114 (FUSE.NET): FUSE INTERNET ACCESS, HAMILTON, OHIO, US. (DSL) |
n/a | :gg.arrancar.org | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 4baf02c545 NEW |
b5ff98d951 [0] | none:none |
none|none | none | trace |
T:22:57:00 | WinXP | 121.58.204.179 (CCTLL.COM): COMCLARK-BROADBAND-NETWORK, MANILA, MANILA, PH. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | eda3b7766c NEW |
7556343561 [0] | none:none |
PolyEnE| | none | trace |