Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:54:00 | WinXP | 24.48.129.139 (USA2NET.NET): FLORIDA CABLE INC, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:03:25:00 | Win2K-f | 76.175.124.185 (RR.COM): ROAD RUNNER HOLDCO LLC, PERRIS, CALIFORNIA, US. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 1009 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 41 | 96511f48b8 NEW |
none[3] | none:none |
none|none | none | trace | |
T:03:42:00 | Win2K-f | 86.99.90.108 (NET.AE): EMIRATES TELECOMMUNICATIONS CORPORATION, DUBAI, DUBAI, AE. (DSL) |
91.212.220.75:65520 | CN:www.brans.pl CN:dl.guarddog2009.com EU:sleepatnight.cn CN:www.petdoso.com CN:202.97.184.196:81 |
139 | pcap | raw alerts ruleset |
irc http 23 lines |
Yeah : 1.3 profile |
none | summary tarball |
11 of 41 17 of 41 15 of 41 14 of 41 13 of 41 |
0bf694b0fd NEW 1c5e79f5f4 NEW 83192a6119 NEW b715292e04 NEW f725e57065 NEW |
bcdaec12b6 [0] none [4] fdc95e1fab[0] 569c05a15f[0] 3f11911aa9[0] |
none:none none:none none:none none:none none:none |
none|none FSG| none|none PE-PACK| tElock| |
none none none none none |
trace trace trace trace trace |
T:04:43:00 | Win2K-f | 202.157.56.125 (WAKUWAKU-LAND.COM): KUMAMOTO CABLE NETWORK CORPORATION, KUMAMOTO, KUMAMOTO, JP. (DSL) |
212.54.2.171:3305 | AR:cx10man.weedns.com AR:fx010413.whyI.org FI:gynoman.weedns.com AR:c010x1.co.cc :commgr.co.cc JP:g.0x20.biz FI:telephone.dd.blueline.be 92.240.234.164:3305 |
135 | pcap | raw alerts ruleset |
irc 590 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 40 | 70ec5c4b3f NEW |
f697adabdd [0] | none:none |
StarForce| | none | trace |
T:04:59:00 | WinXP | 82.254.104.67 (PROXAD.NET): PROXAD / FREE SAS, NICE, PROVENCE-ALPES-COTE D'AZUR, FR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | 03f912899b NEW |
none[0] | none:none |
none|none | lines=64 | trace | |
T:06:07:00 | WinXP | 200.234.19.152 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | EU:siliconfireware.ru US:searchportal.information.com :wpad US:208.73.210.125:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee NEW |
none[0] | none:none |
ASPack| | lines=298 embedded dns |
trace |
T:06:19:00 | WinXP | 125.4.230.39 (ZAQ.NE.JP): J:COM WEST CO. LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 592 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 2c6d4171e6 NEW |
4197bf0c86 [0] | none:none |
StarForce| | none | trace | |
T:06:23:00 | WinXP | 219.110.139.17 (CATV02.ITSCOM.JP): ITS COMMUNICATIONS INC, KAWASAKI, KANAGAWA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:06:45:00 | WinXP | 112.68.34.94 (EONET.NE.JP): K-OPTICOM CORPORATION, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | baf381c459 NEW |
84c5ca466d [0] | none:none |
none|none | none | trace | |
T:07:04:00 | WinXP | 114.207.51.73 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
91.212.220.75:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:www.brans.pl :komojoke.cn EU:sleepatnight.cn :bfkq.com CN:config1007.iwillhavesexygirls.com :jsactivity.com CN:maillist.iwillhavesexygirls.com :wws.mobiec.net CN:218.93.205.30:65520 EU:91.206.201.39:80 98.126.9.218:80 |
135 | pcap | raw alerts ruleset |
irc http 139 lines |
Yeah : 1.8 profile |
none | summary tarball |
9 of 41 8 of 41 30 of 33 28 of 33 14 of 41 6 of 41 13 of 41 |
1fa783c4d6 NEW 39ef7eae36 NEW 533d15b5ce NEW 58c343a8d8 NEW b715292e04 NEW b9bb8aed2c NEW f725e57065 NEW |
ce23deb1d1 [0] f16483aeef[0] c67adf46e2[0] none [0] 569c05a15f[0] afab6f51b9[0] 3f11911aa9[0] |
none:none none:none ASM:Graph none:none none:none none:none none:none |
Neolite| Armadillo| tElock| Armadillo| PE-PACK| StarForce| tElock| |
none none lines=126 embedded dns lines=91 none none none |
trace trace trace trace trace trace trace |
T:07:27:00 | WinXP | 95.158.234.183 (KURSKNET.RU): JSC CENTRAL TELECOMMUNICATION COMPANY, RU. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 | c6f9cc8dd0 NEW |
bf53dec126 [0] | none:none |
none|none | none | trace | |
T:08:35:00 | WinXP | 4.159.56.139 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, HINCKLEY, ILLINOIS, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 140 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 644c58fee9 NEW |
22a350de78 [0] | none:none |
Armadillo| | none | trace | |
T:08:51:00 | Win2K-f | 69.193.74.22 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:08:56:00 | WinXP | 61.224.74.77 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 35 | f63e70fa11 NEW |
4f3f7ff5ac [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:09:07:00 | Win2K-f | 96.8.227.187 (GVTC.COM): GUADALUPE VALLEY TELEPHONE COOPERATIVE INC, NEW BRAUNFELS, TEXAS, US. (DSL) |
92.240.234.164:3305 | :cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 578 lines |
Yeah : 1.8 profile |
none | summary tarball |
23 of 41 | a0e262b14d NEW |
4ae21c0514 [0] | none:none |
StarForce| | none | trace |
T:09:13:00 | WinXP | 116.197.10.2 (-): DIGI TELECOMMUNICATIONS SDN BHD, SHAH ALAM, SELANGOR, MY. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:10:46:00 | Win2K-f | 71.136.17.68 (-): MILANO DESIGN, PLANO, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 85 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 33 33 of 33 |
73ce2b74da NEW 79c01ec060 NEW |
none[0] 1bfd34056c[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=64 embedded dns |
trace trace |
T:10:54:00 | WinXP | 79.163.2.24 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 40 | b41ac85a53 NEW |
3e23c7ba7b [0] | none:none |
PolyEnE| | none | trace |
T:11:31:00 | WinXP | 62.169.92.200 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, LISBON, LISBOA, PT. (DSL) |
n/a | US:www.yahoo.com :jbeegvia.ru |
135 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 17028f1eda NEW |
none[3] | none:none |
tElock| | none | trace |
T:11:58:00 | WinXP | 70.182.87.115 (COX.NET): COX COMMUNICATIONS, BROKEN ARROW, OKLAHOMA, US. (DSL) |
91.212.220.75:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:dl.guarddog2009.com :komojoke.cn :bfkq.com EU:sleepatnight.cn :jsactivity.com CN:www.petdoso.com US:totalinventories.info CN:202.97.184.196:81 US:64.191.44.5:80 EU:91.212.220.75:65520 |
135 | pcap | raw alerts ruleset |
irc http 267 lines |
Yeah : 1.8 profile |
none | summary tarball |
17 of 41 0 of 41 9 of 41 15 of 41 7 of 41 32 of 36 13 of 41 35 of 36 |
1c5e79f5f4 NEW 1c881c13c6 NEW 1fa783c4d6 NEW 83192a6119 NEW ba3f1640d4 NEW bea8cb1865 NEW f725e57065 NEW fac78fde16 NEW |
none[4] none [4] ce23deb1d1[0] fdc95e1fab[0] 9aa28e4745[0] 154de51a66[0] 3f11911aa9[0] 882896ab05[0] |
none:none none:none none:none none:none none:none ASM:Graph none:none none:none |
FSG| none|none Neolite| none|none StarForce| Armadillo| tElock| tElock| |
none none none none none lines=91 none none |
trace trace trace trace trace trace trace trace |
T:12:03:00 | WinXP | 95.27.26.41 (CORBINA.NET): INVESTELEKTROSVIAZ LTD, RU. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:12:12:00 | WinXP | 61.218.193.250 (HINET.NET): CHUNGHWA TELECOM CO. LTD. DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 81 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:20:00 | Win2K-f | 96.8.145.191 (GVTC.COM): GUADALUPE VALLEY TELEPHONE COOPERATIVE INC, NEW BRAUNFELS, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 115 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 39 of 41 |
77656a2953 NEW a77e51636f NEW |
13296a6198 [0] c5e16ba6b7[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:14:42:00 | WinXP | 24.234.219.233 (COX.NET): COX COMMUNICATIONS INC, LAS VEGAS, NEVADA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:42:00 | WinXP | 87.18.116.95 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A. TIN EASY LITE, LAMEZIA TERME, CALABRIA, IT. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :wpad :www.proxy-socks.net US:204.13.161.51:80 |
445 | pcap | raw alerts ruleset |
http http http 7 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 6152c54fc2 NEW |
ccc8b54f0a [0] | none:none |
ASPack| | none | trace |
T:15:51:00 | WinXP | 211.20.222.150 (HINET.NET): XUN HANG TECHNOLOGY CO. LTD, TAIPEI, T'AI-PEI, TW. (100Mbps) |
92.240.234.164:3305 | FI:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 696 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:16:10:00 | WinXP | 189.99.216.151 (VIRTUA.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, SãO PAULO, SAO PAULO, BR. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 38624f25cd NEW |
642a2cc6f2 [0] | none:none |
PolyEnE| | none | trace |
T:16:19:00 | WinXP | 151.68.202.91 (51-151.NET24.IT): IUNET-BNET, LATINA, LAZIO, IT. (DSL) |
122.160.232.194:12351 | IN:irc.shkumbimi.net | 445 | pcap | raw alerts ruleset |
ftp lanman irc 332 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 41 | 55138aeacf NEW |
9782d5ed48 [0] | none:none |
Armadillo| | none | trace |
T:16:46:00 | WinXP | 173.168.162.214 (RR.COM): ROAD RUNNER HOLDCO LLC, CLEARWATER, FLORIDA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:50:00 | Win2K-f | 70.167.73.201 (COX.NET): COX COMMUNICATIONS, OCEANSIDE, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:54:00 | WinXP | 58.70.81.182 (EONET.NE.JP): K-OPTICOM CORPORATION, KYOTO, KYOTO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 7b313206a2 NEW |
0c866c8cce [0] | none:none |
none|none | none | trace | |
T:17:31:00 | WinXP | 222.124.151.93 (TELKOM.NET.ID): PT TELKOM INDONESIA'S CUSTOMER, JAKARTA, JAKARTA RAYA, ID. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:17:39:00 | Win2K-f | 172.162.36.113 (AOL.COM): AMERICA ONLINE, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 164 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:17:43:00 | Win2K-f | 218.211.207.104 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:17:46:00 | WinXP | 124.66.248.106 (FCH.NE.JP): FUREAI CHANNEL INC, HIROSHIMA, HIROSHIMA, JP. (DSL) |
n/a | US:www.yahoo.com :jbeegvia.ru US:www.worldbank.org SE:www.kavkazcenter.com :yoiayoi.ru :wcqahzhzn.ru :iirpryry.ru :rihafvu.ru :wpad :ryryodokm.ru :uvjiis.ru :gwvwka.ru :jqsbnyzkp.ru :pvygdo.ru :fxkyagpnw.ru :knclvdz.ru :trsqeigw.ru :odokeqy.ru :kelmpsjp.ru :edjiesp.ru :vllcdvv.ru :nuksdln.ru :tmmeno.ru :zoxdgqx.ru :pwvbfz.ru :nuzbcp.ru :bqpuqt.ru :okskyyn.ru RU:prodexteam.net :pnlkria.ru :kargai.ru RU:alfabank.ru :kfwfceki.ru SE:kavkaz.tv :nhuwxyuw.ru :udluzuq.ru :fiazpvnne.ru :ppxuub.ru GB:www.candidateverifier.com :lvwgdhwlj.ru :raxeqajrf.ru :dhagunb.ru :zpwmktjv.ru RU:www.cbr.ru :aadqca.ru :ygnrqi.ru :ycgnbe.ru :yeqsuem.ru :aiizkak.ru RU:www.mmbank.ru :crime-research.ru :dupeloz.ru :dodgscv.ru :lodrzze.ru :nkuoonxuz.ru :tmamzn.ru RU:www.sbrf.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 17028f1eda NEW |
none[3] | none:none |
tElock| | none | trace |
T:19:24:00 | Win2K-f | 218.113.72.48 (BBTEC.NET): JAPAN NATION-WIDE NETWORK OF SOFTBANK BB CORP, NAGASAKI, NAGASAKI, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:19:51:00 | Win2K-f | 70.60.183.191 (RR.COM): ROAD RUNNER HOLDCO LLC, MEMPHIS, TENNESSEE, US. (DSL) |
n/a | CA:xx.ka3ek.com :idfc.info 67.215.1.206:80 |
135 | pcap | raw alerts ruleset |
irc 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | a894e6640a NEW |
2a62540340 [0] | none:none |
PolyEnE| | none | trace |
T:21:10:00 | Win2K-f | 173.22.147.122 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, SPRINGFIELD, MISSOURI, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 40 |
474acf88e5 NEW 68f0c14692 NEW |
1f53944b24 [0] ccc1b24d53[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:21:23:00 | WinXP | 114.48.98.30 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:21:33:00 | WinXP | 98.141.163.84 (CAVTEL.NET): CAVALIER TELEPHONE, PHILADELPHIA, PENNSYLVANIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:22:35:00 | WinXP | 4.161.151.186 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, CINCINNATI, OHIO, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |