Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:19:00 | Win2K-f | 63.17.218.177 (UU.NET): UUNET TECHNOLOGIES INC, SMYRNA, GEORGIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 145 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | aa52a1cad3 NEW |
822158a84f [0] | none:none |
Armadillo| | none | trace | |
T:00:34:00 | WinXP | 173.25.3.229 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, COLUMBIA, MISSOURI, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 38 of 41 |
b8f53b4800 NEW e9ef6d378d NEW |
4208eb65f3 [0] 72080f1764[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:01:19:00 | Win2K-f | 219.114.249.200 (ZAQ.NE.JP): J:COM WEST CO. LTD, OSAKA, OSAKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 33 of 33 |
2e45ae247e NEW 53bfe15e91 NEW |
36aa8cd03d [0] 1473091351[0] |
none:none ASM:Graph |
Armadillo| tElock| |
none lines=75 embedded dns |
trace trace |
T:02:04:00 | WinXP | 64.144.35.70 (MEGAPATH.NET): MEGAPATH NETWORKS INC, JERSEY CITY, NEW JERSEY, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:09:00 | Win2K-f | 211.187.97.165 (SONICANT.CO.KR): THRUNET CO. LTD, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
218.93.205.30:65520 | EU:proxima.ircgalaxy.pl US:microsoft.com EU:gidromash.cn :nenastiya.cn CN:config1007.iwillhavesexygirls.com :wws.mobiec.net CN:maillist.iwillhavesexygirls.com US:xz.ub9.net :in.7cy.net :in1.7cy.net US:theglobegallery.com :www.google-analytics.com US:64.95.64.197:80 EU:91.206.201.39:80 |
135 | pcap | raw alerts ruleset |
irc http 144 lines |
Yeah : 1.8 profile |
none | summary tarball |
31 of 41 34 of 36 12 of 41 3 of 41 34 of 41 30 of 33 |
1fa41f09fc NEW 24e59ab043 NEW 3c6b773d78 NEW a62f6fc33b NEW ef5fd50f61 NEW ff2150aa95 NEW |
8267b23408 [0] 778da26bf3[0] fb2dc717f9[0] 020eee55f3[0] c932de5e59[0] 6e55004755[0] |
none:none none:none none:none none:none none:none none:none |
Armadillo| Armadillo| Armadillo| StarForce| StarForce| tElock| |
none none none none none none |
trace trace trace trace trace trace |
T:02:12:00 | WinXP | 62.11.40.39 (DIALUP.TISCALI.IT): TISCALI ITALIA SPA, RIMINI, EMILIA-ROMAGNA, IT. (DIAL) |
n/a | EU:siliconfireware.ru GB:new.egg.com :wpad US:searchportal.information.com US:spi.domainsponsor.com DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http http http 37 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:02:19:00 | Win2K-f | 74.222.107.27 (FTC-I.NET): FARMERS TELEPHONE COOPERATIVE INC, SUMTER, SOUTH CAROLINA, US. (DSL) |
91.212.220.75:65520 | US:microsoft.com US:getrichquickbusiness.com US:searchportal.information.com US:spi.domainsponsor.com US:ads1.revenue.net US:as.casalemedia.com US:activex.microsoft.com US:codecs.microsoft.com :xz.ub9.net EU:proxima.ircgalaxy.pl EU:gidromash.cn EU:ottopay.cn :nenastiya.cn CN:config1007.iwillhavesexygirls.com :wws.mobiec.net CN:www.petdoso.com :jnmr.com :hf.davinci.com CN:maillist.iwillhavesexygirls.com US:faxwelt.com :www.statcounter.com :c.statcounter.com US:www.themakecash.com :datingpopular.com US:emphasisi.com :incometaxliabilities.com :sqltop.net CA:bestgamingoffers.com US:dealandplay.com US:freeonly.net US:shopmastersdegree.info US:cellphonesdish.info 174.36.176.242:81 US:208.109.98.106:80 |
445 | pcap | raw alerts ruleset |
http irc 84 lines |
Yeah : 1.3 profile |
none | summary tarball |
17 of 41 31 of 41 12 of 41 0 of 41 3 of 41 0 of 41 7 of 41 34 of 41 |
1c5e79f5f4 NEW 1fa41f09fc NEW 3c6b773d78 NEW 8b9732ded9 NEW a62f6fc33b NEW c3c12f9578 NEW c7830331fc NEW ef5fd50f61 NEW |
none[4] 8267b23408[0] fb2dc717f9[0] none [4] 020eee55f3[0] none [4] 7953649664[0] c932de5e59[0] |
none:none none:none none:none none:none none:none none:none none:none none:none |
FSG| Armadillo| Armadillo| none|none StarForce| none|none tElock| StarForce| |
none none none none none none none none |
trace trace trace trace trace trace trace trace |
T:04:11:00 | Win2K-f | 196.208.67.52 (TELKOMADSL.CO.ZA): AFRINIC, JOHANNESBURG, GAUTENG, ZA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 149 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 39 of 41 |
1bc51bf964 NEW e33c8e30b9 NEW |
4ab7eeaf6c [0] 95caa6a57d[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:04:16:00 | WinXP | 85.176.240.238 (ALICEDSL.DE): HANSENET-ADSL, WURZBURG, BAYERN, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:04:52:00 | WinXP | 74.65.164.131 (RR.COM): ROAD RUNNER HOLDCO LLC, SOUTH PORTLAND, MAINE, US. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:04:58:00 | Win2K-f | 173.29.130.232 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, CHANHASSEN, MINNESOTA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 38 of 40 |
067917e07b NEW d764c1dcb2 NEW |
dae35b319c [0] 3d2bc60c5d[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:05:47:00 | Win2K-f | 195.137.30.127 (FREEDOM2SURF.NET): FREEDOM TO SURF LTD, LONDON, ENGLAND, UK. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
99c07c4fd6 NEW bc43f0abc4 NEW |
bbf30ef165 [0] 67bede154c[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:07:16:00 | WinXP | 98.141.9.117 (CAVTEL.NET): CAVALIER TELEPHONE, VIRGINIA BEACH, VIRGINIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:07:42:00 | WinXP | 69.4.99.185 (AIRSTREAMCOMM.NET): AMERY TELEPHONE COMPANY, RICE LAKE, WISCONSIN, US. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 0cfab99612 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:08:27:00 | Win2K-f | 4.231.158.81 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, HUMBLE, TEXAS, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:10:07:00 | WinXP | 203.180.17.238 (BMOBILE.NE.JP): JAPAN COMMUNICATION INC, TOKYO, TOKYO, JP. (DSL) |
82.98.86.170:80 | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com DE:ebookfinaltrash.ru :wpad |
445 | pcap | raw alerts ruleset |
http http http http http 29 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 41 | e49826ceaa NEW |
none[4] | none:none |
ASPack| | none | trace |
T:10:08:00 | WinXP | 70.235.77.227 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, WEST HARTFORD, CONNECTICUT, US. (DSL) |
n/a | US:www.yahoo.com :www.google.com.au :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | bb7681eca8 NEW |
none[3] | none:none |
tElock| | none | trace |
T:10:26:00 | WinXP | 76.172.181.154 (RR.COM): ROAD RUNNER HOLDCO LLC, NORTH HOLLYWOOD, CALIFORNIA, US. (100Mbps) |
213.219.245.212:80 | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 3ae357d17b NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:10:27:00 | WinXP | 4.253.119.11 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, KNOX, INDIANA, US. (DIAL) |
n/a | :moscow-advokat.ru SE:coins.dal.net :gaspode.zanet.org.za :flanders.be.eu.undernet.org :los-angeles.ca.us.undernet.org AT:graz.at.eu.undernet.org SE:broadway.ny.us.dal.net :washington.dc.us.undernet.org :caen.fr.eu.undernet.org SE:vancouver.dal.net NL:diemen.nl.eu.undernet.org :brussels.be.eu.undernet.org |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:11:00:00 | WinXP | 4.236.15.13 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, NEW YORK, NEW YORK, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:15:00 | WinXP | 95.84.167.222 (NATIONALCABLENETWORKS.RU): NCNET BROADBAND CUSTOMERS, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :wpad |
445 | pcap | raw alerts ruleset |
http http http 19 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 2949a0ad17 NEW |
0b5f65174a [0] | none:none |
ASPack| | none | trace |
T:11:36:00 | Win2K-f | 173.29.252.46 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, CHANHASSEN, MINNESOTA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 38 of 40 |
067917e07b NEW d764c1dcb2 NEW |
dae35b319c [0] 3d2bc60c5d[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:13:34:00 | WinXP | 87.173.76.3 (T-DIALIN.NET): DEUTSCHE TELEKOM AG, MAGDEBURG, SACHSEN-ANHALT, DE. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:14:32:00 | Win2K-f | 173.171.247.163 (RR.COM): ROAD RUNNER HOLDCO LLC, TAMPA, FLORIDA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:45:00 | WinXP | 209.143.37.21 (BRIGHT.NET): WABASH COMMUNICATIONS, CELINA, OHIO, US. (DIAL) |
n/a | EU:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :www.proxy-socks.net :wpad |
445 | pcap | raw alerts ruleset |
http http 24 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:15:04:00 | WinXP | 71.108.47.7 (VERIZON.NET): VERIZON INTERNET SERVICES INC, LONG BEACH, CALIFORNIA, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 2f6afffda4 NEW |
ede9ae4e6d [0] | none:none |
PolyEnE| | none | trace |
T:16:07:00 | Win2K-f | 72.67.206.75 (VERIZON.NET): VERIZON INTERNET SERVICES INC, LOS ANGELES, CALIFORNIA, US. (DSL) |
92.240.234.164:3305 | FI:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 607 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 41 | 69f8ccc92e NEW |
e9613e6868 [0] | none:none |
StarForce| | none | trace |
T:16:51:00 | WinXP | 76.177.107.0 (RR.COM): ROAD RUNNER HOLDCO LLC, WINCHESTER, KENTUCKY, US. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
17:11:00 | WinXP | 76.177.107.0 (RR.COM): ROAD RUNNER HOLDCO LLC, WINCHESTER, KENTUCKY, US. (DSL) |
n/a | :moscow-advokat.ru NO:london.uk.eu.undernet.org :los-angeles.ca.us.undernet.org SE:qis.md.us.dal.net SE:ozbytes.dal.net :washington.dc.us.undernet.org SE:ced.dal.net :caen.fr.eu.undernet.org SE:coins.dal.net :gaspode.zanet.org.za |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:17:33:00 | WinXP | 96.49.4.72 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, RICHMOND, BRITISH COLUMBIA, CA. (DSL) |
92.240.234.164:3305 | JP:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 609 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 41 | 616f21b486 NEW |
348063e1c2 [0] | none:none |
StarForce| | none | trace |
T:18:04:00 | Win2K-f | 211.244.63.98 (SONICANT.CO.KR): THRUNET CO. LTD, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
91.212.220.75:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com EU:gidromash.cn EU:ottopay.cn CN:www.petdoso.com 174.36.176.242:81 EU:91.212.220.75:65520 |
135 | pcap | raw alerts ruleset |
irc http 137 lines |
Yeah : 1.8 profile |
none | summary tarball |
17 of 41 29 of 32 28 of 32 7 of 41 |
1c5e79f5f4 NEW 8a75955033 NEW 9276c8b36b NEW c7830331fc NEW |
none[4] 2bf3e548b9[0] none [0] 7953649664[0] |
none:none ASM:Graph ASM:Graph none:none |
FSG| tElock| Armadillo| tElock| |
none lines=126 embedded dns lines=81 none |
trace trace trace trace |
T:18:27:00 | WinXP | 63.27.188.214 (UU.NET): UUNET TECHNOLOGIES INC, RICHLAND, MICHIGAN, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 197 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:29:00 | Win2K-f | 124.169.197.151 (IINET.NET.AU): IINET LIMITED, PERTH, WESTERN AUSTRALIA, AU. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 165 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:32:00 | WinXP | 4.231.154.77 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, HUMBLE, TEXAS, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:28:00 | WinXP | 96.53.218.131 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SHERWOOD PARK, ALBERTA, CA. (DSL) |
n/a | :gg.arrancar.org | 135 | pcap | raw alerts ruleset |
other 188 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 39 | ce28648035 NEW |
126d2f4655 [0] | ASM:Graph |
none|none | lines=546 | trace |