Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:47:00 | Win2K-f | 24.103.196.250 (RR.COM): ROAD RUNNER HOLDCO LLC, ROCHESTER, NEW YORK, US. (DSL) |
72.10.172.211:8080 | :xx.enterhere.biz CA:xx.ka3ek.com :idfc.info 67.215.1.206:80 |
135 | pcap | raw alerts ruleset |
irc 340 lines |
Yeah : 1.8 profile |
none | summary tarball |
37 of 40 | a0a15f5ebf NEW |
c506c7cc86 [0] | none:none |
Mew| | none | trace |
T:01:05:00 | WinXP | 151.33.162.98 (14-151.IOL.IT): ITALIA ONLINE S.P.A, SASSARI, SARDEGNA, IT. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:03:33:00 | WinXP | 186.9.32.163 (IMOVIL.ENTELPCS.CL): ENTEL PCS TELECOMUNICACIONES S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 912a073945 NEW |
7874c7f21e [0] | none:none |
PolyEnE| | none | trace |
T:04:09:00 | Win2K-f | 74.215.65.114 (FUSE.NET): FUSE INTERNET ACCESS, HAMILTON, OHIO, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 4baf02c545 NEW |
b5ff98d951 [0] | none:none |
none|none | none | trace | |
T:04:52:00 | Win2K-f | 114.206.114.27 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
218.93.205.30:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com EU:gidromash.cn EU:91.206.201.39:80 |
135 | pcap | raw alerts ruleset |
irc 116 lines |
Yeah : 1.8 profile |
none | summary tarball |
30 of 33 28 of 33 |
533d15b5ce NEW 58c343a8d8 NEW |
c67adf46e2 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=126 embedded dns lines=91 |
trace trace |
T:04:54:00 | WinXP | 124.66.249.212 (FCH.NE.JP): FUREAI CHANNEL INC, HIROSHIMA, HIROSHIMA, JP. (DSL) |
n/a | US:www.yahoo.com :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 17028f1eda NEW |
none[3] | none:none |
tElock| | none | trace |
T:05:56:00 | WinXP | 69.109.244.161 (PACBELL.NET): PLTNCA INTERNAL, OAKLAND, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:06:12:00 | Win2K-f | 203.88.184.38 (CTT.NE.JP): CABLE TELEVISION TOYAMA INCORPORETED, TOYAMA, TOYAMA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:06:16:00 | WinXP | 79.162.170.17 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
n/a | CN:proxim.ircgalaxy.pl RU:citi-bank.ru RU:213.219.245.212:80 CN:218.93.205.30:65520 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 36 | 9bb68450cd NEW |
c2d5ac2315 [0] | ASM:Graph |
PolyEnE| | lines=73 embedded dns |
trace |
T:07:22:00 | WinXP | 70.183.227.133 (COX.NET): COX COMMUNICATIONS, FT. WALTON BEACH, FLORIDA, US. (DSL) |
218.93.205.30:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com EU:gidromash.cn CN:www.brans.pl EU:91.206.201.39:80 |
135 | pcap | raw alerts ruleset |
irc http 146 lines |
Yeah : 1.8 profile |
none | summary tarball |
19 of 41 32 of 36 35 of 36 |
9a6ca2e7ed NEW bea8cb1865 NEW fac78fde16 NEW |
292b7d9e63 [0] 154de51a66[0] 882896ab05[0] |
none:none ASM:Graph none:none |
ASPack| Armadillo| tElock| |
none lines=91 none |
trace trace trace |
07:58:00 | Win2K-f | 200.80.187.235 (TECHTELNET.NET): TECHTEL LMDS COMUNICACIONES INTERACTIVAS S.A, LA PLATA, BUENOS AIRES, AR. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org US:getmyip.co.uk DE:131.220.6.26:80 208.78.70.70:80 |
445 | pcap | raw alerts ruleset |
http 7 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | d60e538e72 NEW |
none[3] | none:none |
UPX| | none | trace |
T:08:10:00 | Win2K-f | 4.231.156.238 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, HUMBLE, TEXAS, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:09:30:00 | WinXP | 218.220.162.132 (ZAQ.NE.JP): J:COM WEST CO. LTD, TOYONAKA, OSAKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:15:00 | WinXP | 60.234.101.122 (ORCON.NET.NZ): ORCON INTERNET LTD SUPPORT, AUCKLAND, AUCKLAND, NZ. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:12:43:00 | WinXP | 190.19.247.98 (COM.AR): CABLEVISION S.A, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | ebddbaef33 NEW |
246edc390a [0] | none:none |
PolyEnE| | none | trace |
13:36:00 | WinXP | 64.33.132.85 (AIRSTREAMCOMM.NET): TRI COUNTY TELEPHONE, WISCONSIN, US. (DIAL) |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 0cfab99612 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:13:38:00 | WinXP | 173.22.163.154 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, SPRINGFIELD, MISSOURI, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 115 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 39 of 41 |
73d9e10cba NEW de3bdf7b4e NEW |
15076d5de4 [0] ff08fc71e3[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:14:11:00 | Win2K-f | 174.1.105.102 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:29:00 | Win2K-f | 65.6.132.38 (BELLSOUTH.NET): BELLSOUTH.NET INC, ATLANTA, GEORGIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 80 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:52:00 | WinXP | 114.137.89.211 (HINET.NET): MOBILE BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
15:02:00 | WinXP | 190.19.247.98 (COM.AR): CABLEVISION S.A, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | ebddbaef33 NEW |
246edc390a [0] | none:none |
PolyEnE| | none | trace |
T:15:40:00 | WinXP | 114.48.168.172 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | c6dd3f96e4 NEW |
012c0580d1 [0] | none:none |
none|none | none | trace | |
17:32:00 | WinXP | 114.137.89.211 (HINET.NET): MOBILE BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | :moscow-advokat.ru SE:coins.dal.net FI:london.uk.eu.undernet.org SE:ced.dal.net :washington.dc.us.undernet.org NL:diemen.nl.eu.undernet.org :brussels.be.eu.undernet.org SE:ozbytes.dal.net SE:vancouver.dal.net |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:17:50:00 | WinXP | 76.166.164.100 (RR.COM): ROAD RUNNER HOLDCO LLC, OXNARD, CALIFORNIA, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:19:03:00 | WinXP | 69.154.11.4 (SWBELL.NET): AT&T INTERNET SERVICES, AUSTIN, TEXAS, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:20:33:00 | WinXP | 68.203.231.60 (RR.COM): ROAD RUNNER HOLDCO LLC, ORANGE, TEXAS, US. (100Mbps) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | none:none |
PolyEnE| | none | trace |
T:22:01:00 | Win2K-f | 70.71.230.45 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, LANGLEY, BRITISH COLUMBIA, CA. (DSL) |
89.149.227.51:3938 | :wiger.blacktiehsbdcs.com | 135 | pcap | raw alerts ruleset |
irc http 466 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 41 28 of 40 |
3686bdd560 NEW f28b31493e NEW |
f7cf109413 [0] e1e1d22148[0] |
none:none none:none |
Armadillo| PENinja S| |
none none |
trace trace |
T:22:57:00 | Win2K-f | 203.76.66.181 (KCT.AD.JP): KURASHIKI CABLE TV CORPORATION, KURASHIKI, OKAYAMA, JP. (DSL) |
92.240.234.164:3305 | JP:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 608 lines |
Yeah : 1.8 profile |
none | summary tarball |
40 of 41 | 5ec55a04a2 NEW |
c77c150cc2 [0] | none:none |
StarForce| | none | trace |
T:23:28:00 | Win2K-f | 174.6.21.151 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:23:59:00 | Win2K-f | 60.249.37.106 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 38 35 of 38 |
38ed850a0e NEW b9297745a1 NEW |
46990f37cd [0] 4294884d84[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |