Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:36:00 | WinXP | 24.85.50.32 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, VANCOUVER, BRITISH COLUMBIA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 38 of 40 |
2721d2b151 NEW b044168966 NEW |
fde14d4abe [0] b02ac1f831[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:02:09:00 | Win2K-f | 63.22.219.54 (UU.NET): UUNET TECHNOLOGIES INC, BOSTON, MASSACHUSETTS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 956 lines |
Yeah : 1.3 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace | |
T:03:36:00 | Win2K-f | 219.255.61.82 (HANANET.NET): HANARO TELECOM INC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
1 of 33 32 of 33 |
ce46f7ab87 NEW d7dc1e3bea NEW |
5780633b71 [0] 3189a15056[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:03:43:00 | Win2K-f | 90.189.149.64 (SNT.RU): OJSC SIBIRTELECOM, MOSCOW, MOSCOW CITY, RU. (DIAL) |
66.252.13.214:2081 | US:s.unicat.org US:attacke.100free.com |
445 | pcap | raw alerts ruleset |
ftp irc http 70 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 39 of 41 |
67a66839f7 NEW f3024245d5 NEW |
7b1fc808a3 [0] 8032e9a084[0] |
none:none none:none |
none|none Armadillo| |
none none |
trace trace |
T:03:46:00 | WinXP | 190.179.5.209 (COM.AR): TELEFONICA DE ARGENTINA, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 11 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:03:54:00 | WinXP | 220.208.153.200 (TCNET.NE.JP): TONAMI TRANSPORTATION CO. LTD, TAKAOKA, TOYAMA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 57ef739a9e NEW |
fbdf9f6053 [0] | none:none |
none|none | none | trace | |
T:05:10:00 | WinXP | 66.72.68.122 (AMERITECH.NET): AT&T INTERNET SERVICES, NASHVILLE, INDIANA, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:07:13:00 | Win2K-f | 70.184.102.222 (COX.NET): COX COMMUNICATIONS, PHOENIX, ARIZONA, US. (100Mbps) |
91.212.220.75:65520 | US:microsoft.com CN:proxim.ircgalaxy.pl EU:gidromash.cn EU:ottopay.cn |
135 | pcap | raw alerts ruleset |
irc http 137 lines |
Yeah : 1.8 profile |
none | summary tarball |
32 of 36 7 of 41 35 of 36 |
bea8cb1865 NEW c7830331fc NEW fac78fde16 NEW |
154de51a66 [0] 7953649664[0] 882896ab05[0] |
ASM:Graph none:none none:none |
Armadillo| tElock| tElock| |
lines=91 none none |
trace trace trace |
T:07:59:00 | WinXP | 4.159.247.12 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, FOREST PARK, ILLINOIS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 245 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
|
T:08:11:00 | WinXP | 110.12.138.252 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
218.93.205.30:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com EU:gidromash.cn CN:dl.guarddog2009.com CN:218.93.205.30:65520 EU:91.206.201.39:80 |
135 | pcap | raw alerts ruleset |
irc http 127 lines |
Yeah : 1.8 profile |
none | summary tarball |
30 of 33 28 of 33 |
533d15b5ce NEW 58c343a8d8 NEW |
c67adf46e2 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=126 embedded dns lines=91 |
trace trace |
T:10:33:00 | WinXP | 4.159.247.12 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, FOREST PARK, ILLINOIS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 155 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:10:40:00 | Win2K-f | 78.60.40.32 (ZEBRA.LT): LIETUVOS, VILNIUS, VILNIAUS APSKRITIS, LT. (DSL) |
66.252.13.214:2081 | US:s.unicat.org DE:members.lycos.co.uk |
445 | pcap | raw alerts ruleset |
ftp irc http 1029 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 6 of 41 6 of 41 |
67a66839f7 NEW b93ae25cb1 NEW ea00dd87f5 NEW |
7b1fc808a3 [0] 9af8e2f833[0] 9af8e2f833[0] |
none:none none:none none:none |
none|none FSG| FSG| |
none none none |
trace trace trace |
T:10:51:00 | Win2K-f | 77.22.136.171 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BERLIN, BERLIN, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 310e02aa2d NEW |
81e39ed8ec [0] | none:none |
Armadillo| | none | trace | |
T:10:52:00 | WinXP | 88.156.37.233 (VECTRANET.PL): VECTRA S.A, OLSZTYN, WARMINSKO-MAZURSKIE, PL. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 11 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:10:58:00 | WinXP | 95.220.189.116 (-): FAIRLIE HOLDING & FINANCE LIMITED, MOSCOW, MOSCOW CITY, RU. (DSL) |
66.252.13.214:2081 | US:s.unicat.org | 445 | pcap | raw alerts ruleset |
ftp irc 39 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | 67a66839f7 NEW |
7b1fc808a3 [0] | none:none |
none|none | none | trace |
T:11:13:00 | Win2K-f | 114.38.196.253 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
66.252.13.214:2081 | US:s.unicat.org | 445 | pcap | raw alerts ruleset |
ftp irc 32 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | 67a66839f7 NEW |
7b1fc808a3 [0] | none:none |
none|none | none | trace |
T:11:13:00 | WinXP | 62.162.197.36 (FINANCE.GOV.MK): MAKEDONSKI TELEKOMUNIKACII A.D, SKOPJE, KARPOS, MK. (DSL) |
66.252.13.214:2081 | US:s.unicat.org | 445 | pcap | raw alerts ruleset |
ftp irc 22 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 8000c39c15 NEW |
48ffee723d [0] | none:none |
none|none | none | trace |
T:11:14:00 | Win2K-f | 78.51.182.10 (ALICEDSL.DE): HANSENET TELEKOMMUNIKATION GMBH, BERLIN, BERLIN, DE. (DSL) |
n/a | US:s.unicat.org US:66.252.13.214:2081 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 5ba3d03fb4 NEW |
28efd36ea0 [0] | none:none |
none|none | none | trace |
T:11:34:00 | WinXP | 70.168.11.10 (COX.NET): COX COMMUNICATIONS, PROVIDENCE, RHODE ISLAND, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:37:00 | WinXP | 212.117.11.193 (INTURBO.LT): INTURBO BROADBAND NETWORK, LT. (DSL) |
66.252.13.214:2081 | US:s.unicat.org 95.0.0.67:16888 95.0.0.68:16888 95.0.0.69:16888 95.0.0.70:16888 95.0.0.71:16888 95.0.0.72:16888 95.0.0.73:16888 95.0.0.74:16888 95.0.0.75:16888 95.0.0.76:16888 95.0.0.77:16888 95.0.0.78:16888 95.0.0.79:16888 95.0.0.80:16888 95.0.0.81:16888 95.0.0.82:16888 95.0.0.83:16888 95.0.0.84:16888 95.0.0.85:16888 95.0.0.86:16888 95.0.0.87:16888 95.0.0.88:16888 |
445 | pcap | raw alerts ruleset |
ftp irc 29 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | e43fe08b67 NEW |
a5a0a54c1e [0] | none:none |
none|none | none | trace |
T:11:38:00 | Win2K-f | 97.107.62.113 (CYG.NET): CYGNET INTERNET SERVICES INC, ONTARIO, CA. (DSL) |
66.252.13.214:2081 | US:s.unicat.org | 445 | pcap | raw alerts ruleset |
ftp irc 21 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 01482c1f63 NEW |
1152c8c686 [0] | none:none |
none|none | none | trace |
T:11:40:00 | Win2K-f | 91.67.232.121 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BERLIN, BERLIN, DE. (DSL) |
66.252.13.214:2081 | US:s.unicat.org | 445 | pcap | raw alerts ruleset |
ftp irc 21 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 288590d40a NEW |
afa15f1c59 [0] | none:none |
none|none | none | trace |
T:12:13:00 | Win2K-f | 95.89.242.202 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. (DSL) |
66.252.13.214:2081 | US:s.unicat.org | 445 | pcap | raw alerts ruleset |
ftp irc 25 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 9d3c7885e7 NEW |
da5cec1caa [0] | none:none |
none|none | none | trace |
T:12:42:00 | WinXP | 74.70.230.40 (RR.COM): ROAD RUNNER HOLDCO LLC, SCHENECTADY, NEW YORK, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:14:15:00 | Win2K-f | 24.103.196.250 (RR.COM): ROAD RUNNER HOLDCO LLC, ROCHESTER, NEW YORK, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 332 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | a0a15f5ebf NEW |
c506c7cc86 [0] | none:none |
Mew| | none | trace | |
T:14:37:00 | Win2K-f | 4.234.0.10 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, HOLLYWOOD, FLORIDA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 159 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 | a08f3b74a4 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:15:37:00 | Win2K-f | 96.51.29.79 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, RED DEER, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | 916752f248 NEW |
4e604fc8cb [0] | none:none |
none|none | none | trace | |
T:15:57:00 | WinXP | 186.40.41.36 (E-CORPNET.ORG): TELEFONICA MOVIL DE CHILE S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:16:13:00 | Win2K-f | 60.249.37.247 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 38 35 of 38 |
38ed850a0e NEW b9297745a1 NEW |
46990f37cd [0] 4294884d84[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:17:30:00 | WinXP | 74.70.230.40 (RR.COM): ROAD RUNNER HOLDCO LLC, SCHENECTADY, NEW YORK, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:18:29:00 | WinXP | 72.251.14.236 (1DIAL.COM): AD-BASE SYSTEMS INC. (DBA GLOBALPOPS), ARLINGTON, TEXAS, US. (DIAL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 2f6afffda4 NEW |
ede9ae4e6d [0] | none:none |
PolyEnE| | none | trace |
19:39:00 | Win2K-f | 62.60.136.125 (-): IRANSCIENCE NETWORK DATA CENTER & STORAGE NETWORK, IR. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | 409ef22885 NEW |
none[3] | none:none |
UPX| | none | trace |
T:19:53:00 | Win2K-f | 210.202.122.39 (EBTNET.NET): ASIA PACIFIC ONLINE SERVICE INC, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 299 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d32131ba55 NEW |
0e138688c4 [0] | none:none |
StarForce| | none | trace | |
T:20:41:00 | WinXP | 210.79.182.218 (MEDIATTI.NET): MEDIATTI COMMUNICATIONS INC, KADENA, OKINAWA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 86 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 33 33 of 33 |
3ed16ae12d NEW 79c01ec060 NEW |
none[0] 1bfd34056c[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=64 embedded dns |
trace trace |
T:21:37:00 | WinXP | 116.120.197.42 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
218.93.205.30:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com EU:gidromash.cn CN:dl.guarddog2009.com EU:91.206.201.39:80 |
135 | pcap | raw alerts ruleset |
irc http 142 lines |
Yeah : 1.8 profile |
none | summary tarball |
30 of 33 28 of 33 15 of 41 |
533d15b5ce NEW 58c343a8d8 NEW 83192a6119 NEW |
c67adf46e2 [0] none [0] fdc95e1fab[0] |
ASM:Graph none:none none:none |
tElock| Armadillo| none|none |
lines=126 embedded dns lines=91 none |
trace trace trace |
T:21:42:00 | WinXP | 114.48.14.143 (E-MOBILE.NE.JP): EMOBILE LTD, TACHIKAWA, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:22:14:00 | Win2K-f | 60.249.37.106 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 38 35 of 38 |
38ed850a0e NEW b9297745a1 NEW |
46990f37cd [0] 4294884d84[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:23:03:00 | Win2K-f | 210.79.178.29 (MEDIATTI.NET): MEDIATTI COMMUNICATIONS INC, NAHA, OKINAWA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 85 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 33 33 of 33 |
3ed16ae12d NEW 79c01ec060 NEW |
none[0] 1bfd34056c[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=64 embedded dns |
trace trace |
T:23:22:00 | WinXP | 125.2.96.90 (INFOWEB.NE.JP): INFOWEB(FUJITSU LTD.), TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:23:31:00 | Win2K-f | 203.99.178.161 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, ISLAMABAD, ISLAMABAD, PK. (DSL) |
n/a | CZ:qtas.net CZ:mi.thelive-photo.com |
445 | pcap | raw alerts ruleset |
http 58 lines |
Yeah : 0.8 profile |
none | summary tarball |
11 of 41 | 3cc3b8f86d NEW |
fccf13d773 [0] | none:none |
FASM| | none | trace |
T:23:48:00 | WinXP | 207.5.155.42 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
8 of 33 30 of 33 |
b7082104e4 NEW cf298ee908 NEW |
c5b49e7b82 [0] none [3] |
ASM:Graph none:none |
tElock| tElock| |
lines=41 none |
trace trace |