Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:23:00 | WinXP | 125.103.232.248 (UCOM.NE.JP): G-TK0024N, TOKYO, TOKYO, JP. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | aa298099d5 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:00:39:00 | Win2K-f | 173.28.201.188 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, CHANHASSEN, MINNESOTA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 38 of 40 |
067917e07b NEW d764c1dcb2 NEW |
dae35b319c [0] 3d2bc60c5d[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:01:20:00 | Win2K-f | 173.19.210.223 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, IOWA CITY, IOWA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 39 of 41 |
10759405e0 NEW d08e00dfaf NEW |
292d343248 [0] 854c49d8c4[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:02:41:00 | WinXP | 119.228.212.26 (EONET.NE.JP): K-OPTICOM CORPORATION, OSAKA, OSAKA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 7b313206a2 NEW |
0c866c8cce [0] | none:none |
none|none | none | trace | |
T:03:16:00 | Win2K-f | 70.60.117.169 (RR.COM): ROAD RUNNER HOLDCO LLC, CHARLOTTE, NORTH CAROLINA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:34:00 | WinXP | 87.173.65.54 (T-DIALIN.NET): DEUTSCHE TELEKOM AG, BERLIN, BERLIN, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:04:53:00 | WinXP | 83.2.21.13 (-): AUTO HIT ANNA OLESZCZUK, WARSAW, WARSZAWA, PL. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 36 | 6b3beaea1a NEW |
154f174df6 [0] | none:none |
PolyEnE| | none | trace |
T:05:43:00 | WinXP | 118.7.7.146 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | ASM:Graph |
none|none | lines=61 | trace | |
T:06:06:00 | WinXP | 124.8.113.65 (TFN.NET.TW): TAIWAN FIXED NETWORK CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:06:07:00 | WinXP | 67.242.136.24 (RR.COM): ROAD RUNNER HOLDCO LLC, WELLSVILLE, NEW YORK, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:07:42:00 | WinXP | 109.87.116.86 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | b26ed6eeac NEW |
97c1157bf8 [0] | none:none |
PolyEnE| | none | trace |
T:08:21:00 | WinXP | 75.43.199.128 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, LOS ANGELES, CALIFORNIA, US. (DSL) |
n/a | EU:siliconfireware.ru US:searchportal.information.com :www.proxy-socks.net :wpad US:spi.domainsponsor.com US:208.73.210.125:80 |
445 | pcap | raw alerts ruleset |
http http http 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:09:24:00 | WinXP | 87.62.253.62 (DSL.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, HERNING, RINGKOBING, DK. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | b26ed6eeac NEW |
97c1157bf8 [0] | none:none |
PolyEnE| | none | trace |
T:09:32:00 | WinXP | 189.64.216.211 (TIMBRASIL.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, SãO PAULO, SAO PAULO, BR. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:10:37:00 | WinXP | 114.201.62.212 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
218.93.205.30:65520 | CN:proxima.ircgalaxy.pl US:microsoft.com CN:dl.guarddog2009.com EU:gidromash.cn EU:ottopay.cn US:64.235.53.208:80 EU:91.212.220.75:65520 |
135 | pcap | raw alerts ruleset |
irc http 120 lines |
Yeah : 1.8 profile |
none | summary tarball |
31 of 33 31 of 33 15 of 41 7 of 41 |
168aab35a3 NEW 667f0c59f3 NEW 83192a6119 NEW c7830331fc NEW |
60b730b97e [0] 8fe2be2095[0] fdc95e1fab[0] 7953649664[0] |
ASM:Graph ASM:Graph none:none none:none |
tElock| Armadillo| none|none tElock| |
lines=120 embedded dns lines=91 none none |
trace trace trace trace |
T:10:51:00 | Win2K-f | 113.254.43.160 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | CN:italian.swiifatecihno.com | 135 | pcap | raw alerts ruleset |
irc http 730 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 41 36 of 41 |
65ab01055a NEW cfc1d2f1e6 NEW |
8af090abd4 [0] 8e35d85b6b[0] |
none:none none:none |
StarForce| ASPack| |
none none |
trace trace |
T:11:20:00 | WinXP | 212.225.148.87 (PTVTELECOM.COM): ES-PROCONO-AS, CóRDOBA, ANDALUCIA, ES. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 39 | e1cc0f1f8d NEW |
edeeb27e4a [0] | none:none |
PolyEnE| | none | trace |
11:32:00 | WinXP | 76.177.111.13 (RR.COM): ROAD RUNNER HOLDCO LLC, WINCHESTER, KENTUCKY, US. (DSL) |
n/a | :moscow-advokat.ru :lia.zanet.net SE:ced.dal.net SE:ozbytes.dal.net AT:graz.at.eu.undernet.org |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:12:07:00 | WinXP | 76.171.146.5 (RR.COM): ROAD RUNNER HOLDCO LLC, LOS ANGELES, CALIFORNIA, US. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a0139d7ad8 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:13:13:00 | WinXP | 81.9.191.114 (CM-81-9-237-10.TELECABLE.ES): TELECABLE, OVIEDO, ASTURIAS, ES. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | none:none |
PolyEnE| | none | trace |
13:26:00 | Win2K-f | 114.38.190.31 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org US:www.getmyip.org US:getmyip.co.uk 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:13:28:00 | WinXP | 80.253.147.240 (AZADNET.NET): RANGE FOR COUNTRYWISE DSL INFRASTRUCTURE, TEHRAN, ESFAHAN, IR. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :vit.ln.ua RU:www.bbin.ru RU:www.binbank.ru :wpad RU:195.200.213.54:80 |
445 | pcap | raw alerts ruleset |
http http http http 39 lines |
Yeah : 0.8 profile |
none | summary tarball |
30 of 39 | aaf763d687 NEW |
9ca935dd78 [0] | none:none |
ASPack| | none | trace |
T:13:35:00 | Win2K-f | 114.38.190.31 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org US:www.getmyip.org US:getmyip.co.uk DE:131.220.6.26:80 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:14:08:00 | WinXP | 83.97.247.80 (CM-93-156-61-10.TELECABLE.ES): TELECABLE, BARCELONA, CATALONIA, ES. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | none:none |
PolyEnE| | none | trace |
T:14:17:00 | WinXP | 92.230.96.24 (ALICEDSL.DE): HANSENET-ADSL, BIELEFELD, NORDRHEIN-WESTFALEN, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:14:17:00 | WinXP | 95.91.201.173 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BERLIN, BERLIN, DE. (DSL) |
66.252.13.214:2081 | US:s.unicat.org | 445 | pcap | raw alerts ruleset |
ftp irc 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 453e0d6f52 NEW |
f024cb64bb [0] | none:none |
none|none | none | trace |
14:20:00 | WinXP | 114.137.65.248 (HINET.NET): MOBILE BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:14:23:00 | WinXP | 94.251.153.203 (-): CUSTOMERS IN BYTOM, PL. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | e585bb1e8e NEW |
bdddd170de [0] | none:none |
StarForce| | none | trace | |
T:16:27:00 | WinXP | 187.47.236.125 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
16:38:00 | WinXP | 187.47.236.125 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:18:14:00 | WinXP | 125.4.229.201 (ZAQ.NE.JP): J:COM WEST CO. LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | :teek.ihshsd8.com :japan.youngpeyatech.info CN:done.blacktiehsbdcs.com |
135 | pcap | raw alerts ruleset |
irc http 616 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 41 40 of 41 |
65ab01055a NEW 8ca2204d15 NEW |
8af090abd4 [0] b4b671eb52[0] |
none:none none:none |
StarForce| ASPack| |
none none |
trace trace |
T:18:29:00 | WinXP | 74.214.47.11 (METROCAST.NET): METROCAST COMMUNICATIONS, KING GEORGE, VIRGINIA, US. (100Mbps) |
194.109.11.65:6556 | :0x80.my-secure.name NL:0x80.my1x1.com NL:0x80.martiansong.com NL:0x80.goingformars.com NL:194.109.11.65:6556 |
135 | pcap | raw alerts ruleset |
other 229 lines |
Yeah : 1.8 profile |
none | summary tarball |
32 of 33 | fe22b8315f NEW |
bb25603f41 [0] | none:none |
StarForce| | none | trace |
T:19:02:00 | WinXP | 78.226.17.128 (PROXAD.NET): PROXAD / FREE SAS, AMIENS, PICARDIE, FR. (DSL) |
66.252.13.214:2081 | US:s.unicat.org US:66.252.13.214:2081 |
445 | pcap | raw alerts ruleset |
ftp irc 34 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | 67a66839f7 NEW |
7b1fc808a3 [0] | none:none |
none|none | none | trace |
19:27:00 | WinXP | 66.217.240.119 (MCLEODUSA.NET): PAETEC COMMUNICATIONS INC, BIRMINGHAM, ALABAMA, US. (DSL) |
n/a | :moscow-advokat.ru SE:qis.md.us.dal.net :washington.dc.us.undernet.org :brussels.be.eu.undernet.org :caen.fr.eu.undernet.org BE:london.uk.eu.undernet.org SE:broadway.ny.us.dal.net |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:20:56:00 | Win2K-f | 207.5.155.42 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:21:00:00 | Win2K-f | 113.255.111.101 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |