Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:02:09:00 | WinXP | 121.80.33.227 (EONET.NE.JP): K-OPTICOM CORPORATION, HIKONE, SHIGA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 7b313206a2 NEW |
0c866c8cce [0] | none:none |
none|none | none | trace | |
T:02:36:00 | WinXP | 81.153.105.250 (BTCENTRALPLUS.COM): BT BROADBAND, LONDON, ENGLAND, UK. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | ASM:Graph |
none|none | lines=61 | trace | |
T:03:07:00 | WinXP | 79.9.7.219 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA NET, FLORENCE, TOSCANA, IT. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:03:21:00 | Win2K-f | 122.146.240.251 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 39 of 41 |
0fccdfacbc NEW 5e904b9f03 NEW |
94d4924744 [0] a7385cf17d[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:03:29:00 | WinXP | 61.218.193.250 (HINET.NET): CHUNGHWA TELECOM CO. LTD. DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:45:00 | WinXP | 218.228.145.72 (EONET.NE.JP): K-OPTICOM CORPORATION, OSAKA, OSAKA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 7b313206a2 NEW |
0c866c8cce [0] | none:none |
none|none | none | trace | |
T:04:18:00 | WinXP | 77.21.44.132 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BAYREUTH, BAYERN, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 4530fc0b7f NEW |
1ce549df2a [0] | none:none |
none|none | none | trace | |
T:05:19:00 | WinXP | 125.58.120.87 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:05:24:00 | Win2K-f | 70.241.118.148 (SWBELL.NET): AT&T INTERNET SERVICES, HOUSTON, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:05:27:00 | WinXP | 4.229.198.138 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, JACKSON, MICHIGAN, US. (DIAL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:05:55:00 | WinXP | 121.84.19.239 (EONET.NE.JP): K-OPTICOM CORPORATION, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | baf381c459 NEW |
84c5ca466d [0] | none:none |
none|none | none | trace | |
T:06:05:00 | WinXP | 219.114.254.171 (ZAQ.NE.JP): J:COM WEST CO. LTD, OSAKA, OSAKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 93 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 39 of 41 |
53bfe15e91 NEW e6f694cd8d NEW |
1473091351 [0] 954b65edac[0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns none |
trace trace |
T:06:47:00 | WinXP | 122.220.143.197 (UCOM.NE.JP): TKMITAU, TOKYO, TOKYO, JP. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:08:42:00 | WinXP | 120.138.155.209 (STARCAT.NE.JP): KMN CORPORATION, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
6a1dc43309 NEW 94e49d5627 NEW |
522dace6c1 [0] 777259292a[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
09:57:00 | WinXP | 186.9.39.1 (IMOVIL.ENTELPCS.CL): ENTEL PCS TELECOMUNICACIONES S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | eda3b7766c NEW |
7556343561 [0] | none:none |
PolyEnE| | none | trace |
T:10:34:00 | Win2K-f | 70.166.138.106 (COX.NET): COX COMMUNICATIONS, NEW YORK, NEW YORK, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:53:00 | WinXP | 69.201.142.98 (RR.COM): ROAD RUNNER HOLDCO LLC, NEW YORK, NEW YORK, US. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com RU:www.bbin.ru RU:www.binbank.ru :wpad US:204.13.161.51:80 DE:217.11.54.126:80 |
445 | pcap | raw alerts ruleset |
http http http http 37 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:13:24:00 | WinXP | 174.1.103.110 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 5241018ca4 NEW |
96e4efb859 [0] | none:none |
PolyEnE| | none | trace |
T:13:53:00 | WinXP | 209.42.181.230 (WISPNET.NET): WISPNET LLC, LEXINGTON, KENTUCKY, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 36 | b27d73bfcb NEW |
473c6454ce [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
14:18:00 | WinXP | 81.9.191.99 (CM-81-9-237-10.TELECABLE.ES): TELECABLE, OVIEDO, ASTURIAS, ES. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | none:none |
PolyEnE| | none | trace |
T:15:14:00 | WinXP | 187.89.241.156 (CAMPUSEAI.ORG): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | b850153581 NEW |
97aa41e3e3 [0] | none:none |
PolyEnE| | none | trace |
T:15:52:00 | WinXP | 4.165.120.243 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, CLINTON TOWNSHIP, MICHIGAN, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 109 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:32:00 | WinXP | 59.120.228.224 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 52 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 | 57ce4acac2 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:17:43:00 | WinXP | 76.15.117.20 (MINDSPRING.COM): EARTHLINK INC, POUGHKEEPSIE, NEW YORK, US. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :wpad US:204.13.161.51:80 DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee NEW |
none[0] | none:none |
ASPack| | lines=298 embedded dns |
trace |
T:17:48:00 | Win2K-f | 4.231.235.251 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, BROOKLYN, NEW YORK, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:24:00 | WinXP | 61.221.237.252 (-): HUNG REN SHIN IE CO. LTD. PINGTUNG BRANCH COMPANY, TAIPEI, T'AI-PEI, TW. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 1002 lines |
Yeah : 1.3 profile |
none | summary tarball |
17 of 41 | e1693609f9 NEW |
none[3] | none:none |
none|none | none | trace | |
T:21:50:00 | WinXP | 207.5.161.171 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:44:00 | Win2K-f | 24.103.196.250 (RR.COM): ROAD RUNNER HOLDCO LLC, ROCHESTER, NEW YORK, US. (DSL) |
n/a | :xx.nadnadzz.info :xx.enterhere.biz |
135 | pcap | raw alerts ruleset |
other 333 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | a0a15f5ebf NEW |
c506c7cc86 [0] | none:none |
Mew| | none | trace |
T:22:55:00 | WinXP | 151.67.192.90 (51-151.NET24.IT): IUNET-BNET, NAPOLI, CAMPANIA, IT. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 470b31abb8 NEW |
c11e97bf10 [0] | none:none |
PolyEnE| | none | trace |
23:07:00 | Win2K-f | 201.65.77.151 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:23:08:00 | WinXP | 71.121.66.140 (VERIZON.NET): VERIZON INTERNET SERVICES INC, ERIE, PENNSYLVANIA, US. (DSL) |
92.240.234.164:3305 | JP:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 608 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 40 | b578280b18 NEW |
b69a6b100c [0] | none:none |
StarForce| | none | trace |
T:23:51:00 | Win2K-f | 60.249.37.106 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 38 35 of 38 |
38ed850a0e NEW b9297745a1 NEW |
46990f37cd [0] 4294884d84[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |