Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:30:00 | WinXP | 151.33.162.101 (14-151.IOL.IT): ITALIA ONLINE S.P.A, SASSARI, SARDEGNA, IT. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:01:54:00 | WinXP | 115.83.27.111 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 74c3429921 NEW |
1265c25f7f [0] | none:none |
PolyEnE| | none | trace | |
T:02:04:00 | WinXP | 61.218.193.250 (HINET.NET): CHUNGHWA TELECOM CO. LTD. DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 85 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:35:00 | Win2K-f | 70.184.102.222 (COX.NET): COX COMMUNICATIONS, PHOENIX, ARIZONA, US. (100Mbps) |
218.93.205.30:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com EU:gidromash.cn EU:ottopay.cn CN:www.petdoso.com GB:www.businesstomb.com CN:218.93.205.30:65520 |
135 | pcap | raw alerts ruleset |
irc http 137 lines |
Yeah : 1.8 profile |
none | summary tarball |
17 of 41 39 of 41 32 of 36 7 of 41 10 of 41 35 of 36 |
1c5e79f5f4 NEW 7d040c00c3 NEW bea8cb1865 NEW c7830331fc NEW cd1ecbc017 NEW fac78fde16 NEW |
none[4] 48830e2b12[0] 154de51a66[0] 7953649664[0] none [4] 882896ab05[0] |
none:none none:none ASM:Graph none:none none:none none:none |
FSG| FSG| Armadillo| tElock| Neolite| tElock| |
none none lines=91 none none none |
trace trace trace trace trace trace |
T:04:15:00 | Win2K-f | 4.253.114.193 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, KNOX, INDIANA, US. (DIAL) |
91.212.220.75:65520 | GB:www.businesstomb.com CN:proxim.ircgalaxy.pl EU:gidromash.cn :nenastiya.cn EU:ottopay.cn :bfkq.com :jsactivity.com US:assruance.info 173.45.105.218:8392 EU:91.206.201.39:80 |
445 | pcap | raw alerts ruleset |
http irc 181 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 41 5 of 41 2 of 41 7 of 41 0 of 41 |
1d7834eab8 NEW 8b11a5e53e NEW 8edc331d07 NEW c7830331fc NEW ec6a0c4add NEW |
3c0b7b7a8d [0] 34198921d2[0] 8edc331d07[1] 7953649664[0] none [4] |
none:none none:none ASM:Graph none:none none:none |
UPX| StarForce| ASProtect| tElock| none|none |
none none lines=7 none none |
trace trace trace trace trace |
T:05:23:00 | WinXP | 93.102.3.118 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, COIMBRA, COIMBRA, PT. (DSL) |
n/a | US:www.altavista.com US:www.yahoo.com :jbeegvia.ru |
135 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 17028f1eda NEW |
none[3] | none:none |
tElock| | none | trace |
T:06:03:00 | Win2K-f | 203.91.187.60 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 38 of 41 |
a373350c69 NEW c80b3e3022 NEW |
18f36af13d [0] 6114f3736d[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:06:16:00 | WinXP | 78.250.27.158 (PROXAD.NET): PROXAD INTERNET SERVICE PROVIDER IN FRANCE, FR. (DSL) |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:06:54:00 | WinXP | 121.87.41.190 (EONET.NE.JP): K-OPTICOM CORPORATION, TAKATSUKI, OSAKA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:07:46:00 | Win2K-f | 4.161.165.102 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DALLAS, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 38 of 41 |
02674c9a56 NEW 25eae40389 NEW |
0da2cae967 [0] 1e0aae0aeb[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:07:55:00 | WinXP | 221.140.75.42 (HANANET.NET): HANARO TELECOM INC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
218.93.205.30:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com EU:gidromash.cn :nenastiya.cn :bfkq.com :jsactivity.com US:archiecture.info :sendfan.com :www.sendfan.com US:gardenlawyer.com CN:218.93.205.30:65520 US:64.120.161.149:80 EU:91.206.201.39:80 |
135 | pcap | raw alerts ruleset |
irc http 249 lines |
Yeah : 1.8 profile |
none | summary tarball |
8 of 41 7 of 41 29 of 32 28 of 32 0 of 41 |
1d7834eab8 NEW 7f4221040e NEW 8a75955033 NEW 9276c8b36b NEW d0a27d286c NEW |
3c0b7b7a8d [0] cfbae30419[0] 2bf3e548b9[0] none [0] none [4] |
none:none none:none ASM:Graph ASM:Graph none:none |
UPX| StarForce| tElock| Armadillo| none|none |
none none lines=126 embedded dns lines=81 none |
trace trace trace trace trace |
T:09:00:00 | Win2K-f | 121.121.195.208 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | CZ:qtas.net CZ:mi.thelive-photo.com |
445 | pcap | raw alerts ruleset |
http 54 lines |
Yeah : 0.8 profile |
none | summary tarball |
11 of 41 | 3cc3b8f86d NEW |
fccf13d773 [0] | none:none |
FASM| | none | trace |
T:09:53:00 | Win2K-f | 58.85.252.49 (ZAQ.NE.JP): J:COM WEST CO. LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 37 of 41 |
98d2778fd6 NEW f676f3bf5b NEW |
9feea491cb [0] 0fba495fc4[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:10:31:00 | WinXP | 4.229.198.6 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, JACKSON, MICHIGAN, US. (DIAL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:11:09:00 | WinXP | 79.163.123.179 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 36 | 06a5e31b47 NEW |
25e6e52787 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:11:18:00 | WinXP | 109.86.144.216 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :www.proxy-socks.net :wpad US:204.13.161.51:80 |
445 | pcap | raw alerts ruleset |
http http http 7 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | a09f60cdc7 NEW |
4a30860fac [0] | none:none |
ASPack| | none | trace |
T:11:24:00 | WinXP | 62.162.169.196 (-): MOBI IP SUBNET, VELES, VELES, MK. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:11:36:00 | WinXP | 98.175.158.194 (COX.NET): COX COMMUNICATIONS, PROVIDENCE, RHODE ISLAND, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:03:00 | WinXP | 91.66.198.112 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BAYREUTH, BAYERN, DE. (DSL) |
97.74.144.31:80 216.32.75.74:80 213.74.4.161:80 115.124.113.5:80 217.74.65.162:80 72.167.232.226:80 208.109.177.30:80 195.238.0.64:80 64.202.189.170:80 | :fashionenigma.com TR:www.aysanco.com US:www.yahoo.com :www.shaolindeepakdubey.com PL:snowboard619.w.interia.pl :meta-kit.com US:www.merc-connect.com BE:www.railwayservices.be US:cychefs.com US:d.mx.mail.yahoo.com US:www.kjwre9fqwieluoi.info US:72.232.11.26:80 US:74.208.64.145:80 |
445 | pcap | raw alerts ruleset |
shell ftp http 236 lines |
Yeah : 1.8 profile |
none | summary tarball |
37 of 41 | 9cd397f1fd NEW |
6aee570ceb [0] | none:none |
none|none | none | trace |
T:12:12:00 | Win2K-f | 24.234.219.233 (COX.NET): COX COMMUNICATIONS INC, LAS VEGAS, NEVADA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:29:00 | WinXP | 213.99.224.12 (-): TELEFONICA MOVILES ESPANA (NCC#2006042768), MADRID, MADRID, ES. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | 03f912899b NEW |
none[0] | none:none |
none|none | lines=64 | trace | |
T:15:47:00 | WinXP | 76.224.126.11 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, PROSPECT HEIGHTS, ILLINOIS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
16:43:00 | WinXP | 186.97.50.247 (EMTEL.NET.CO): COLOMBIA MVIL, TOCAIMA, CUNDINAMARCA, CO. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 02f196daa0 NEW |
4db84f0199 [0] | none:none |
PolyEnE| | none | trace |
T:16:58:00 | WinXP | 125.4.8.185 (ZAQ.NE.JP): J:COM WEST CO. LTD, OSAKA, OSAKA, JP. (DSL) |
92.240.234.164:3305 | :cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 579 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | 1bb4b25c0e NEW |
9293a2c3db [0] | none:none |
StarForce| | none | trace |
T:17:14:00 | WinXP | 63.19.46.29 (UU.NET): UUNET TECHNOLOGIES INC, GLASGOW, KENTUCKY, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | 5818023061 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:18:11:00 | WinXP | 24.103.196.250 (RR.COM): ROAD RUNNER HOLDCO LLC, ROCHESTER, NEW YORK, US. (DSL) |
n/a | :xx.enterhere.biz :xx.nadnadzz.info CA:xx.ka3ek.com :idfc.info 67.215.1.206:80 |
135 | pcap | raw alerts ruleset |
irc 340 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | a0a15f5ebf NEW |
c506c7cc86 [0] | none:none |
Mew| | none | trace |
T:18:41:00 | WinXP | 92.40.208.61 (THREE.CO.UK): MOBILE BROADBAND SERVICE, MANCHESTER, ENGLAND, UK. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 36 | 6b3beaea1a NEW |
154f174df6 [0] | none:none |
PolyEnE| | none | trace |
T:18:42:00 | WinXP | 97.106.139.25 (RR.COM): ROAD RUNNER HOLDCO LLC, LARGO, FLORIDA, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 912a073945 NEW |
7874c7f21e [0] | none:none |
PolyEnE| | none | trace |
T:19:20:00 | WinXP | 76.93.247.89 (RR.COM): ROAD RUNNER HOLDCO LLC, BAKERSFIELD, CALIFORNIA, US. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:20:56:00 | WinXP | 67.150.6.29 (MDSG-PACWEST.COM): PAC-WEST MANAGED MODEM NAS POOL, HACIENDA HEIGHTS, CALIFORNIA, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:21:23:00 | Win2K-f | 70.241.73.193 (SWBELL.NET): AT&T INTERNET SERVICES, HOUSTON, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:23:15:00 | Win2K-f | 124.9.74.210 (TFN.NET.TW): TAIWAN FIXED NETWORK CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 302 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
088c8ea72a NEW 47280d3256 NEW |
7ccfe164f3 [0] none [4] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |