Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:12:00 | Win2K-f | 4.137.77.10 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, CHARLOTTE, NORTH CAROLINA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 130 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:20:00 | WinXP | 63.17.174.162 (UU.NET): UUNET TECHNOLOGIES INC, CONYERS, GEORGIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 131 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:28:00 | WinXP | 115.69.137.242 (-): ICL-NET-IN, DELHI, DELHI, IN. (DIAL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:04:43:00 | WinXP | 208.125.40.153 (RR.COM): ROAD RUNNER HOLDCO LLC, ROCHESTER, NEW YORK, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:05:05:00 | Win2K-f | 125.4.249.231 (ZAQ.NE.JP): J:COM WEST CO. LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | :sdihsihdsfsofhsohs.net CN:haiys.eiheihre3.com |
135 | pcap | raw alerts ruleset |
irc http 408 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d805fd89c4 NEW |
036c86797f [0] | none:none |
EXECrypto| | none | trace |
T:06:24:00 | WinXP | 99.164.23.178 (SBCGLOBAL.NET): RANI PAL LLC, PLANO, TEXAS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 402 lines |
Yeah : 1.3 profile |
none | summary tarball |
11 of 36 | c4c5a56ffe NEW |
8bef2f9170 [0] | none:none |
StarForce| | none | trace | |
T:06:34:00 | WinXP | 211.20.222.150 (HINET.NET): XUN HANG TECHNOLOGY CO. LTD, TAIPEI, T'AI-PEI, TW. (100Mbps) |
92.240.234.164:3305 | TH:cx10man.weedns.com FI:fx010413.whyI.org 92.240.234.164:3305 |
135 | pcap | raw alerts ruleset |
irc 695 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:06:54:00 | WinXP | 67.123.204.202 (PACBELL.NET): RICHARD MULHALL, SAN FRANCISCO, CALIFORNIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:09:03:00 | WinXP | 98.141.17.72 (CAVTEL.NET): CAVALIER TELEPHONE, HAMPTON, VIRGINIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:09:11:00 | WinXP | 60.249.198.98 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 39 of 41 |
4640a4ccd3 NEW 518025c884 NEW |
9d9f2a02f5 [0] e811756e2b[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:10:47:00 | WinXP | 109.86.222.87 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 01c4a6b3eb NEW |
dd524b0259 [0] | none:none |
PolyEnE| | none | trace |
T:11:29:00 | WinXP | 75.44.34.233 (SBCGLOBAL.NET): RBACK6A.MILWWI.20060913, MILWAUKEE, WISCONSIN, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | 03f912899b NEW |
none[0] | none:none |
none|none | lines=64 | trace | |
T:12:51:00 | WinXP | 60.249.37.247 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 38 35 of 38 |
38ed850a0e NEW b9297745a1 NEW |
46990f37cd [0] 4294884d84[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:13:11:00 | WinXP | 89.111.226.191 (PALEOL.NET): NF-TEL D.O.O, SARAJEVO, FEDERATION OF BOSNIA AND HERZEGOVINA, BA. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | f54691063f NEW |
6039c698cd [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:14:18:00 | Win2K-f | 202.215.39.39 (VECTANT.NE.JP): VECTANT LTD, TOKYO, TOKYO, JP. (DSL) |
92.240.234.164:3305 | AR:cx10man.weedns.com FI:fx010413.whyI.org AR:gynoman.weedns.com 92.240.234.164:3305 |
135 | pcap | raw alerts ruleset |
irc 708 lines |
Yeah : 1.8 profile |
none | summary tarball |
31 of 41 | cc88f4f016 NEW |
3d17903825 [0] | none:none |
StarForce| | none | trace |
T:14:46:00 | Win2K-f | 116.126.26.100 (-): HANARO TELECOM, KUNSAN, CHOLLA-BUKTO, KR. (DSL) |
91.212.220.75:65520 | EU:proxim.ircgalaxy.pl US:microsoft.com EU:gidromash.cn EU:ottopay.cn :www.petdoso.com 174.36.176.242:81 |
135 | pcap | raw alerts ruleset |
irc http 140 lines |
Yeah : 1.8 profile |
none | summary tarball |
8 of 41 29 of 32 28 of 32 7 of 41 |
736b3db4fe NEW 8a75955033 NEW 9276c8b36b NEW c7830331fc NEW |
none[4] 2bf3e548b9[0] none [0] 7953649664[0] |
none:none ASM:Graph ASM:Graph none:none |
Obsidium| tElock| Armadillo| tElock| |
none lines=126 embedded dns lines=81 none |
trace trace trace trace |
T:17:06:00 | WinXP | 98.28.8.104 (RR.COM): ROAD RUNNER HOLDCO LLC, LANCASTER, OHIO, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:17:20:00 | WinXP | 89.195.199.26 (-): ORANGE HIGH SPEED INTERNET, LONDON, ENGLAND, UK. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 7f38ca84af NEW |
89991cf07f [0] | none:none |
PolyEnE| | none | trace |
T:17:41:00 | WinXP | 70.183.99.81 (COX.NET): COX COMMUNICATIONS, CHULA VISTA, CALIFORNIA, US. (DSL) |
218.93.205.30:65520 | EU:proxim.ircgalaxy.pl US:microsoft.com EU:gidromash.cn EU:ottopay.cn :www.petdoso.com 174.36.176.242:81 |
135 | pcap | raw alerts ruleset |
irc http 253 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 41 8 of 41 38 of 41 7 of 41 |
619115df0d NEW 736b3db4fe NEW b3f96920fe NEW c7830331fc NEW |
7b9aa49eb9 [0] none [4] bf01f2b155[0] 7953649664[0] |
none:none none:none none:none none:none |
tElock| Obsidium| Armadillo| tElock| |
none none none none |
trace trace trace trace |
T:19:46:00 | Win2K-f | 76.217.106.182 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, PROSPECT HEIGHTS, ILLINOIS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:03:00 | Win2K-f | 125.4.219.172 (ZAQ.NE.JP): J:COM WEST CO. LTD, OSAKA, OSAKA, JP. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 250 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | a8a15ce6ae NEW |
0d23174d7b [0] | none:none |
PolyEnE| | none | trace | |
T:20:49:00 | Win2K-f | 4.234.36.241 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, MIAMI, FLORIDA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 957 lines |
Yeah : 1.3 profile |
none | summary tarball |
12 of 41 | 0151482932 NEW |
none[3] | none:none |
none|none | none | trace | |
T:21:36:00 | Win2K-f | 71.122.44.151 (VERIZON.NET): VERIZON INTERNET SERVICES INC, CLEARWATER, FLORIDA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 459d2bddeb NEW |
10fac04dd2 [0] | none:none |
none|none | none | trace | |
T:22:50:00 | Win2K-f | 121.124.81.92 (HANANET.NET): HANARO TELECOM INC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
91.212.220.75:65520 218.93.205.30:65520 | CN:proxima.ircgalaxy.pl US:microsoft.com EU:gidromash.cn EU:ottopay.cn :www.petdoso.com 174.36.176.242:81 |
135 | pcap | raw alerts ruleset |
irc http 167 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 41 38 of 41 8 of 41 7 of 41 |
0f5ec5c3b5 NEW 3cc6c5584c NEW 736b3db4fe NEW c7830331fc NEW |
2ab58743f8 [0] 4da1c2ed7d[0] none [4] 7953649664[0] |
none:none none:none none:none none:none |
tElock| Armadillo| Obsidium| tElock| |
none none none none |
trace trace trace trace |