Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:07:00 | WinXP | 61.221.237.252 (-): HUNG REN SHIN IE CO. LTD. PINGTUNG BRANCH COMPANY, TAIPEI, T'AI-PEI, TW. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 1002 lines |
Yeah : 1.3 profile |
none | summary tarball |
17 of 41 | e1693609f9 NEW |
none[3] | none:none |
none|none | none | trace | |
T:00:35:00 | Win2K-f | 70.184.216.215 (COX.NET): COX COMMUNICATIONS, OMAHA, NEBRASKA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
3b3a6d7615 NEW b7a694b220 NEW |
ed7beb96f5 [0] 9f0354af30[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:02:24:00 | WinXP | 121.121.161.178 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:04:50:00 | WinXP | 12.74.185.227 (ATT.NET): AT&T WORLDNET SERVICES, MOBILE, ALABAMA, US. (DSL) |
n/a | EU:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :wpad US:204.13.161.51:80 US:208.73.210.125:80 |
445 | pcap | raw alerts ruleset |
http http http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee NEW |
none[0] | none:none |
ASPack| | lines=298 embedded dns |
trace |
T:05:23:00 | WinXP | 78.88.149.163 (VECTRANET.PL): BROADBAND USERS OF VECTRA S.A, JELENIA GORA, DOLNOSLASKIE, PL. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 | 5bb1174a3d NEW |
8ba258f5b1 [0] | none:none |
PolyEnE| | none | trace |
T:05:48:00 | WinXP | 79.162.184.179 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
213.219.245.212:80 91.212.220.75:65520 | EU:proxim.ircgalaxy.pl RU:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http irc 4 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 36 | 9bb68450cd NEW |
c2d5ac2315 [0] | ASM:Graph |
PolyEnE| | lines=73 embedded dns |
trace |
T:06:12:00 | WinXP | 190.108.150.103 (E-CORPNET.ORG): TELEFONICA MOVIL DE CHILE S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | 72134e4b44 NEW |
28c60e99a7 [0] | none:none |
PolyEnE| | none | trace |
T:07:03:00 | WinXP | 207.199.202.42 (NETINS.NET): ALPINE COMMUNICATIONS, IOWA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 114 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 39 of 41 |
7bceac44b9 NEW b26accfa42 NEW |
5dc69354a4 [0] 13bd762c2a[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:08:05:00 | WinXP | 87.57.134.1 (DSL.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, ÅRHUS, ARHUS, DK. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 40 | 624d43be60 NEW |
3caff61b75 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:08:42:00 | WinXP | 193.250.88.5 (ABO.WANADOO.FR): WANADOO, CHAMBERY, RHONE-ALPES, FR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:10:56:00 | Win2K-f | 201.220.232.51 (E-CORPNET.ORG): TELEFONICA MOVIL DE CHILE S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
n/a | CZ:qtas.net CZ:mi.thelive-photo.com CZ:82.114.87.50:8080 |
445 | pcap | raw alerts ruleset |
http 49 lines |
Yeah : 0.8 profile |
none | summary tarball |
15 of 41 | 1bbbe63042 NEW |
3d78d77332 [0] | none:none |
StarForce| | none | trace |
T:11:02:00 | Win2K-f | 4.231.91.143 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, NEW ORLEANS, LOUISIANA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 119 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | 73f1082158 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:11:13:00 | WinXP | 77.254.83.175 (INETIA.PL): INTERNETIA, SZCZECIN, ZACHODNIOPOMORSKIE, PL. (DSL) |
n/a | :moscow-advokat.ru :los-angeles.ca.us.undernet.org SE:ced.dal.net AT:graz.at.eu.undernet.org :lia.zanet.net |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 | 4740471483 NEW |
db0cbac4be [0] | none:none |
PolyEnE| | none | trace |
T:11:22:00 | WinXP | 63.28.38.75 (UU.NET): UUNET TECHNOLOGIES INC, SPOTSYLVANIA, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:03:00 | WinXP | 95.220.54.169 (-): FAIRLIE HOLDING & FINANCE LIMITED, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | ASM:Graph |
none|none | lines=61 | trace | |
T:12:24:00 | Win2K-f | 180.64.64.123 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:41:00 | WinXP | 89.155.161.25 (CPE.NETCABO.PT): TVCABO-PORTUGAL CABLE MODEM NETWORK, LEIRIA, LEIRIA, PT. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | a1f992a08e NEW |
75ca0b4a8f [0] | none:none |
PolyEnE| | none | trace |
T:13:18:00 | WinXP | 66.205.215.153 (ALLWEST.NET): ALL WEST COMMUNICATIONS INC, BIG PINEY, WYOMING, US. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
13:35:00 | WinXP | 66.205.215.153 (ALLWEST.NET): ALL WEST COMMUNICATIONS INC, BIG PINEY, WYOMING, US. (DSL) |
n/a | :moscow-advokat.ru AT:graz.at.eu.undernet.org |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:13:49:00 | Win2K-f | 70.168.11.10 (COX.NET): COX COMMUNICATIONS, PROVIDENCE, RHODE ISLAND, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:37:00 | WinXP | 96.8.227.186 (GVTC.COM): GUADALUPE VALLEY TELEPHONE COOPERATIVE INC, NEW BRAUNFELS, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:15:12:00 | WinXP | 118.231.143.43 (FETNET.NET): FAR EASTONE TELECOMMUNICATION CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | :moscow-advokat.ru SE:coins.dal.net |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
33 of 36 | d61760f6a1 NEW |
22542b9b5e [0] | none:none |
PolyEnE| | none | trace |
T:16:41:00 | Win2K-f | 24.214.232.107 (VROOOOMHOSTING.NET): KNOLOGY INC, COLUMBUS, GEORGIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:55:00 | WinXP | 4.226.125.248 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, HOT SPRINGS NATIONAL PARK, ARKANSAS, US. (DIAL) |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:19:10:00 | WinXP | 60.249.37.247 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 38 35 of 38 |
38ed850a0e NEW b9297745a1 NEW |
46990f37cd [0] 4294884d84[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:19:12:00 | Win2K-f | 211.20.222.150 (HINET.NET): XUN HANG TECHNOLOGY CO. LTD, TAIPEI, T'AI-PEI, TW. (100Mbps) |
92.240.234.164:3305 | :cx10man.weedns.com :fx010413.whyI.org 92.240.234.164:3305 |
135 | pcap | raw alerts ruleset |
irc 696 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:19:49:00 | Win2K-f | 74.214.47.11 (METROCAST.NET): METROCAST COMMUNICATIONS, KING GEORGE, VIRGINIA, US. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 98 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 | e30fb27bda NEW |
90ee26f451 [0] | ASM:Graph |
MEW| | lines=185 embedded dns |
trace | |
T:21:29:00 | WinXP | 4.227.195.244 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DENVER, COLORADO, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 82 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:45:00 | WinXP | 125.58.87.23 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:56:00 | WinXP | 58.98.192.202 (WAKWAK.NE.JP): XEPHION(NTT-ME CORPORATION), TOKYO, TOKYO, JP. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:23:01:00 | Win2K-f | 173.28.198.4 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, CHANHASSEN, MINNESOTA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 38 of 40 |
067917e07b NEW d764c1dcb2 NEW |
dae35b319c [0] 3d2bc60c5d[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |