Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:08:00 | WinXP | 63.17.215.150 (UU.NET): UUNET TECHNOLOGIES INC, CANTON, GEORGIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 116 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:18:00 | WinXP | 66.66.248.19 (RR.COM): ROAD RUNNER HOLDCO LLC, WATERLOO, NEW YORK, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:02:40:00 | WinXP | 211.120.159.142 (ZAQ.NE.JP): J:COM WEST CO. LTD, OSAKA, OSAKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 91 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 39 of 41 |
53bfe15e91 NEW c3dbc57ce4 NEW |
1473091351 [0] c5b6b72bf9[0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns none |
trace trace |
T:03:14:00 | Win2K-f | 203.91.165.198 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:03:44:00 | WinXP | 93.102.5.68 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, COIMBRA, COIMBRA, PT. (DSL) |
n/a | US:www.altavista.com US:www.yahoo.com :jbeegvia.ru |
135 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 17028f1eda NEW |
none[3] | none:none |
tElock| | none | trace |
T:05:41:00 | Win2K-f | 207.200.197.163 (QWEST.NET): NETWORK INNOVATIONS INC, CHICAGO, ILLINOIS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 78 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
|
T:06:33:00 | WinXP | 207.5.200.230 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:57:00 | WinXP | 79.162.139.200 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
n/a | CN:proxim.ircgalaxy.pl RU:citi-bank.ru CN:218.93.205.30:65520 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 36 | 9bb68450cd NEW |
c2d5ac2315 [0] | ASM:Graph |
PolyEnE| | lines=73 embedded dns |
trace |
T:07:58:00 | Win2K-f | 218.32.97.169 (SDTV.NET.TW): SAN DA CATV CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 183 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 37 of 41 |
a205366bef NEW efaef2451a NEW |
82bbbe4789 [0] 5382f9a037[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:08:33:00 | WinXP | 41.210.219.64 (SNETFAST.COM): AFRINIC, AO. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:09:02:00 | WinXP | 79.163.45.127 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
91.212.220.75:65520 | CN:proxim.ircgalaxy.pl CN:dl.guarddog2009.com :nenastiya.cn EU:sleepatnight.cn CN:config1007.iwillhavesexygirls.com CN:maillist.iwillhavesexygirls.com :wws.mobiec.net CN:218.10.18.30:88 CN:218.10.18.30:888 CN:218.93.205.30:65520 |
445 | pcap | raw alerts ruleset |
shell ftp irc http 30 lines |
Yeah : 1.8 profile |
none | summary tarball |
18 of 41 15 of 41 39 of 41 26 of 41 |
405ce10c9b NEW 83192a6119 NEW a7564e22c7 NEW dd96e88e03 NEW |
9f1a7125b9 [0] fdc95e1fab[0] bffd103c5d[0] 6f87541765[0] |
none:none none:none none:none none:none |
Armadillo| none|none none|none StarForce| |
none none none none |
trace trace trace trace |
T:09:05:00 | WinXP | 4.254.82.148 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DES MOINES, IOWA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 82 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:09:41:00 | WinXP | 109.86.222.87 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 01c4a6b3eb NEW |
dd524b0259 [0] | none:none |
PolyEnE| | none | trace |
T:10:06:00 | WinXP | 64.105.214.163 (COVAD.NET): COVAD COMMUNICATIONS CO, BURNSVILLE, MINNESOTA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:10:12:00 | WinXP | 190.120.136.211 (EMTEL.NET.CO): COLOMBIA MVIL, TOCAIMA, CUNDINAMARCA, CO. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 02f196daa0 NEW |
4db84f0199 [0] | none:none |
PolyEnE| | none | trace |
T:11:28:00 | WinXP | 81.9.191.120 (CM-81-9-237-10.TELECABLE.ES): TELECABLE, OVIEDO, ASTURIAS, ES. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | none:none |
PolyEnE| | none | trace |
T:12:22:00 | Win2K-f | 71.135.165.76 (PACBELL.NET): AT&T INTERNET SERVICES, HAYWARD, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:13:13:00 | WinXP | 74.210.231.9 (CGOCABLE.CA): COGECO CABLE CANADA INC, RIMOUSKI, QUEBEC, CA. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | a25dfda335 NEW |
29d2ef505b [0] | none:none |
PolyEnE| | none | trace |
T:13:19:00 | WinXP | 65.32.210.196 (RR.COM): ROAD RUNNER HOLDCO LLC, TAMPA, FLORIDA, US. (100Mbps) |
92.240.234.164:3305 | AR:cx10man.weedns.com TH:fx010413.whyI.org 92.240.234.164:3305 |
135 | pcap | raw alerts ruleset |
irc 608 lines |
Yeah : 1.8 profile |
none | summary tarball |
40 of 41 | 2187d1dd44 NEW |
c2248c0c3e [0] | none:none |
StarForce| | none | trace |
T:14:04:00 | WinXP | 4.161.136.73 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, CINCINNATI, OHIO, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 170 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 40 39 of 41 |
51f4ecded7 NEW cde64e4527 NEW |
389cdefb96 [0] 6f8ad99a9c[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:14:34:00 | Win2K-f | 70.61.191.97 (RR.COM): ROAD RUNNER HOLDCO LLC, SUNBURY, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:50:00 | Win2K-f | 186.8.24.37 (MOVINET.COM.UY): TELEFONICA MOVILES DEL URUGUAY SA, UY. (DSL) |
n/a | CZ:qtas.net CZ:mi.thelive-photo.com CZ:mi.www-images.com CZ:82.114.87.50:8080 |
445 | pcap | raw alerts ruleset |
http 52 lines |
Yeah : 0.8 profile |
none | summary tarball |
17 of 41 | 66df987a25 NEW |
244e5c5ade [0] | none:none |
StarForce| | none | trace |
T:15:07:00 | WinXP | 79.163.116.32 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 708f64b1b7 NEW |
a18ef8ac1f [0] | none:none |
PolyEnE| | none | trace |
T:16:19:00 | WinXP | 124.184.184.104 (BIGPOND.NET.AU): TELSTRAINTERNET44, SYDNEY, NEW SOUTH WALES, AU. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:16:36:00 | Win2K-f | 211.20.222.150 (HINET.NET): XUN HANG TECHNOLOGY CO. LTD, TAIPEI, T'AI-PEI, TW. (100Mbps) |
92.240.234.164:3305 | :cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 696 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:17:16:00 | WinXP | 188.192.53.70 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :wpad US:204.13.161.51:80 |
445 | pcap | raw alerts ruleset |
http http http 7 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee NEW |
none[0] | none:none |
ASPack| | lines=298 embedded dns |
trace |
T:18:36:00 | Win2K-f | 207.200.197.163 (QWEST.NET): NETWORK INNOVATIONS INC, CHICAGO, ILLINOIS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 85 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:00:00 | WinXP | 68.151.243.247 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, EDMONTON, ALBERTA, CA. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 226 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 38 of 41 |
4180c19d91 NEW b6e91e001c NEW |
9f3f2de385 [0] d2275a6cf5[0] |
none:none none:none |
Armadillo| PolyEnE| |
none none |
trace trace |
T:20:53:00 | WinXP | 116.58.145.141 (CCNET-AI.NE.JP): COMMUNITY NETWORK CENTER INC, TOYOKAWA, AICHI, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 88 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 33 of 33 |
42402ff5fa NEW 53bfe15e91 NEW |
9f15424080 [0] 1473091351[0] |
none:none ASM:Graph |
Armadillo| tElock| |
none lines=75 embedded dns |
trace trace |
T:21:22:00 | WinXP | 114.166.155.199 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:21:47:00 | WinXP | 118.87.20.65 (ODWR.J-CNET.JP): ODAWARA CABLETV INTERNET SERVICE, ODAWARA, KANAGAWA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 122 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 36 34 of 36 |
0b951c2832 NEW e4ed4df0f0 NEW |
5fe761661a [0] de471fc380[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:22:04:00 | Win2K-f | 24.86.71.239 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SURREY, BRITISH COLUMBIA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:22:00 | WinXP | 208.126.133.30 (NETINS.NET): NETINS INC, MOVILLE, IOWA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 392 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | ebb5c23610 NEW |
d1aa50283d [0] | none:none |
StarForce| | none | trace | |
T:22:34:00 | WinXP | 203.98.113.5 (-): M/S ORTEL COMMUNICATIONS LTD PLOT C1 CHANDRASEKHARPUR, BHUBANESHWAR, ORISSA, IN. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | none:none |
PolyEnE| | none | trace |
T:23:14:00 | WinXP | 109.86.13.24 (JWS.COM): EU-ZZ, UK. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | 81d48d18af NEW |
8b8f52fb93 [0] | none:none |
PolyEnE| | none | trace |
T:23:22:00 | WinXP | 159.121.147.85 (OR.US): STATE OF OREGON, SALEM, OREGON, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:23:29:00 | WinXP | 61.215.157.7 (CABLENET.NE.JP): CABLENET SAITAMA CO. LTD, FUNABASHI, CHIBA, JP. (DSL) |
92.240.234.164:3305 | FI:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 696 lines |
Yeah : 1.8 profile |
none | summary tarball |
34 of 41 | deffdf68e8 NEW |
2b011e15ba [0] | none:none |
StarForce| | none | trace |
T:23:53:00 | WinXP | 4.224.186.26 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, BRUNSWICK, OHIO, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace |