Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:02:23:00 | WinXP | 124.241.138.142 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:47:00 | Win2K-f | 63.26.156.204 (UU.NET): UUNET TECHNOLOGIES INC, CHAMPAIGN, ILLINOIS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 202 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | ff34a1caa4 NEW |
979a6569d4 [0] | none:none |
Armadillo| | none | trace | |
T:03:42:00 | WinXP | 114.48.208.54 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:03:51:00 | WinXP | 62.103.92.70 (MAPLIBRARY.GR): THESSALONIKI, THESSALONIKI, THESSALONIKI, GR. (100Mbps) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 19 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | ASM:Graph |
none|none | lines=61 | trace | |
T:04:25:00 | WinXP | 65.184.134.99 (RR.COM): ROAD RUNNER HOLDCO LLC, NEWPORT, NORTH CAROLINA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 85 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 36 3 of 33 |
126a1d4446 NEW 3ed16ae12d NEW |
31867051da [0] none [0] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:04:36:00 | WinXP | 220.219.43.72 (INFOWEB.NE.JP): INFOWEB(FUJITSU LTD.), SHIZUOKA, SHIZUOKA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:05:03:00 | Win2K-f | 122.49.235.153 (CCNET-AI.NE.JP): COMMUNITY NETWORK CENTER INC, TOYOKAWA, AICHI, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=75 embedded dns |
trace trace |
T:05:46:00 | WinXP | 202.87.173.60 (AUSTRALIS.COM.AU): AUSTRALIS INTERNET SERVICE PROVIDER, MELBOURNE, VICTORIA, AU. (DSL) |
218.93.205.30:65520 | CN:proxima.ircgalaxy.pl US:microsoft.com EU:gidromash.cn EU:ottopay.cn CN:dl.guarddog2009.com :www.petdoso.com 174.36.176.242:81 |
135 | pcap | raw alerts ruleset |
irc http 161 lines |
Yeah : 1.8 profile |
none | summary tarball |
3 of 41 8 of 41 15 of 41 39 of 41 7 of 41 |
5ba3f75775 NEW 736b3db4fe NEW 83192a6119 NEW a885d0c168 NEW c7830331fc NEW |
e26ec73abb [0] none [4] fdc95e1fab[0] a6d2045191[0] 7953649664[0] |
none:none none:none none:none none:none none:none |
Armadillo| Obsidium| none|none tElock| tElock| |
none none none none none |
trace trace trace trace trace |
T:06:04:00 | WinXP | 71.113.142.157 (VERIZON.NET): VERIZON INTERNET SERVICES INC, BLOOMINGTON, ILLINOIS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:06:12:00 | WinXP | 114.48.208.162 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:06:18:00 | WinXP | 125.4.234.236 (ZAQ.NE.JP): J:COM WEST CO. LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 33 of 33 |
2e45ae247e NEW 53bfe15e91 NEW |
36aa8cd03d [0] 1473091351[0] |
none:none ASM:Graph |
Armadillo| tElock| |
none lines=75 embedded dns |
trace trace |
T:06:49:00 | WinXP | 218.163.45.23 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | fc21e133bb NEW |
6731b98370 [0] | none:none |
PolyEnE| | none | trace |
T:07:08:00 | Win2K-f | 60.249.198.98 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 39 of 41 |
4640a4ccd3 NEW 518025c884 NEW |
9d9f2a02f5 [0] e811756e2b[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:07:43:00 | Win2K-f | 4.131.86.58 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DALLAS, TEXAS, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1005 lines |
Yeah : 1.3 profile |
none | summary tarball |
28 of 41 | 18eacdb378 NEW |
3d17903825 [0] | none:none |
StarForce| | none | trace | |
T:08:52:00 | WinXP | 70.123.103.157 (RR.COM): ROAD RUNNER HOLDCO LLC, COPPELL, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 39 of 41 |
3dffff72ad NEW c03a1c24e8 NEW |
b2ac20b6e7 [0] af756c363a[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:09:39:00 | WinXP | 213.238.106.20 (INETIA.PL): NETIA SA ADSL NETWORK, WARSAW, WARSZAWA, PL. (DSL) |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | aab1b56620 NEW |
3b2e1c5b9d [0] | none:none |
PolyEnE| | none | trace |
T:10:40:00 | WinXP | 88.30.11.17 (RIMA-TDE.NET): TELEFONICA MOVILES ESPANA (NCC#2007041930), BARCELONA, CATALONIA, ES. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
35 of 36 | b27d73bfcb NEW |
473c6454ce [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:11:07:00 | WinXP | 85.152.139.4 (CM-93-156-61-10.TELECABLE.ES): TELECABLE, ALMERIA, ANDALUCIA, ES. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | eda3b7766c NEW |
7556343561 [0] | none:none |
PolyEnE| | none | trace |
T:11:11:00 | WinXP | 76.172.48.61 (RR.COM): ROAD RUNNER HOLDCO LLC, OXNARD, CALIFORNIA, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 41 26 of 28 |
7d89e4dffc NEW 7d99b0e910 NEW |
a9315eb14c [0] none [0] |
none:none none:none |
FASM| PolyEnE| |
none lines=68 |
trace trace |
T:11:25:00 | WinXP | 4.175.30.206 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, JAMISON, PENNSYLVANIA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 207 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | 47d3548e36 NEW |
ab13346633 [0] | none:none |
Armadillo| | none | trace | |
T:11:26:00 | Win2K-f | 71.121.172.204 (VERIZON.NET): VERIZON INTERNET SERVICES INC, BURLINGTON, WASHINGTON, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1009 lines |
Yeah : 1.3 profile |
none | summary tarball |
20 of 41 | c20138fa2a NEW |
none[3] | none:none |
none|none | none | trace | |
T:14:25:00 | Win2K-f | 91.66.202.118 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, LEIPZIG, SACHSEN, DE. (DSL) |
66.252.13.214:9890 | US:f.unicat.org | 445 | pcap | raw alerts ruleset |
ftp irc 36 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 NEW |
none[0] | none:none |
ASProtect| | lines=585 embedded dns |
trace |
14:49:00 | Win2K-f | 85.21.30.238 (MSECURITY.RU): CORBINA-MORBEZ, MOSCOW, MOSCOW CITY, RU. (100Mbps) |
n/a | US:www.maxmind.com US:getmyip.co.uk :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 7 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:15:03:00 | Win2K-f | 98.189.18.35 (COX.NET): COX COMMUNICATIONS, ATLANTA, GEORGIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:35:00 | WinXP | 60.249.37.247 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 38 35 of 38 |
38ed850a0e NEW b9297745a1 NEW |
46990f37cd [0] 4294884d84[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:16:43:00 | WinXP | 75.185.222.213 (RR.COM): ROAD RUNNER HOLDCO LLC, DAYTON, OHIO, US. (100Mbps) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:17:09:00 | WinXP | 207.5.236.176 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:17:37:00 | WinXP | 69.193.78.147 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:04:00 | WinXP | 203.91.165.198 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:20:07:00 | WinXP | 12.74.167.191 (ATT.NET): AT&T WORLDNET SERVICES, NEW CASTLE, DELAWARE, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:20:15:00 | WinXP | 93.102.0.70 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, VILA NOVA DE GAIA, PORTO, PT. (DSL) |
n/a | US:www.yahoo.com :jbeegvia.ru US:www.worldbank.org :crime-research.ru :yoiayoi.ru :wcqahzhzn.ru :iirpryry.ru :rihafvu.ru :wpad :ryryodokm.ru :uvjiis.ru :gwvwka.ru :jqsbnyzkp.ru :pvygdo.ru :fxkyagpnw.ru :knclvdz.ru :trsqeigw.ru :odokeqy.ru :kelmpsjp.ru :edjiesp.ru :vllcdvv.ru :nuksdln.ru :tmmeno.ru :zoxdgqx.ru :pwvbfz.ru :nuzbcp.ru :bqpuqt.ru :okskyyn.ru DE:kavkaz.co.uk :pnlkria.ru :kargai.ru RU:alfabank.ru :kfwfceki.ru :nhuwxyuw.ru :udluzuq.ru :fiazpvnne.ru GB:www.candidateverifier.com :ppxuub.ru :lvwgdhwlj.ru NL:www.viruslist.com :raxeqajrf.ru :dhagunb.ru RU:www.cbr.ru :zpwmktjv.ru RU:prodexteam.net :aadqca.ru |
135 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 17028f1eda NEW |
none[3] | none:none |
tElock| | none | trace |
T:20:40:00 | WinXP | 121.121.31.35 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 | cdbb312d0a NEW |
8050e5ba3e [0] | none:none |
PolyEnE| | none | trace |
T:22:22:00 | WinXP | 84.47.202.68 (-): NAVIDNET ISP, TEHRAN, ESFAHAN, IR. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :vit.ln.ua GB:new.egg.com :wpad |
445 | pcap | raw alerts ruleset |
http http http 37 lines |
Yeah : 0.8 profile |
none | summary tarball |
30 of 32 | 7dd1fe2970 NEW |
none[0] | ASM:Graph |
ASPack| | lines=374 embedded dns |
trace |
T:22:42:00 | Win2K-f | 75.23.66.177 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, PEORIA, ILLINOIS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 36 29 of 33 |
0474b4b09f NEW 1c3210698a NEW |
affa94efc0 [0] 38bbefb8cc[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:23:03:00 | Win2K-f | 24.85.206.212 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SURREY, BRITISH COLUMBIA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 115 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 38 of 40 |
2721d2b151 NEW b044168966 NEW |
fde14d4abe [0] b02ac1f831[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |