Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:02:47:00 | WinXP | 114.48.75.146 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:03:59:00 | WinXP | 24.234.132.15 (COX.NET): COX COMMUNICATIONS INC, LAS VEGAS, NEVADA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 52 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 | a08f3b74a4 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:04:38:00 | WinXP | 219.85.9.82 (SO-NET.NET.TW): SONY NETWORK TAIWAN LIMITED, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | eda3b7766c NEW |
7556343561 [0] | none:none |
PolyEnE| | none | trace |
T:04:44:00 | Win2K-f | 211.201.218.62 (HANANET.NET): HANARO TELECOM INC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
218.93.205.30:65520 | US:microsoft.com CN:proxim.ircgalaxy.pl EU:sleepatnight.cn CN:www.petdoso.com CN:202.97.184.196:81 |
135 | pcap | raw alerts ruleset |
irc http 125 lines |
Yeah : 1.8 profile |
none | summary tarball |
17 of 41 30 of 33 28 of 33 7 of 41 13 of 41 |
1c5e79f5f4 NEW 533d15b5ce NEW 58c343a8d8 NEW 9e4a539611 NEW f725e57065 NEW |
none[4] c67adf46e2[0] none [0] 405940d276[0] 3f11911aa9[0] |
none:none ASM:Graph none:none none:none none:none |
FSG| tElock| Armadillo| none|none tElock| |
none lines=126 embedded dns lines=91 none none |
trace trace trace trace trace |
T:04:56:00 | Win2K-f | 71.148.35.37 (SBCGLOBAL.NET): KASSA KASSA, PLANO, TEXAS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:05:21:00 | Win2K-f | 220.216.60.167 (THN.NE.JP): TOKAI CORPORATION, SHIZUOKA, SHIZUOKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 103 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 40 of 41 |
6a6aaa5b73 NEW 8bde6dd126 NEW |
63889c9976 [0] 885c68f500[0] |
none:none none:none |
tElock| tElock| |
none none |
trace trace |
T:05:31:00 | WinXP | 203.118.238.245 (-): GRAND TAINAN TECHNOLOGY CO.LTD, TAINAN, T'AI-WAN, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:05:38:00 | WinXP | 121.121.93.144 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:07:43:00 | WinXP | 123.214.205.136 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
218.93.205.30:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com :komojoke.cn :bfkq.com :jsactivity.com EU:sleepatnight.cn US:search.toptravellingtips.com CN:www.petdoso.com :sendfan.com :www.sendfan.com US:atmospherey.info CN:202.97.184.196:81 US:69.59.170.246:80 |
135 | pcap | raw alerts ruleset |
irc http 245 lines |
Yeah : 1.8 profile |
none | summary tarball |
17 of 41 0 of 41 2 of 40 29 of 32 28 of 32 5 of 41 13 of 41 |
1c5e79f5f4 NEW 33713f3110 NEW 3b8d695a53 NEW 8a75955033 NEW 9276c8b36b NEW b64d7999db NEW f725e57065 NEW |
none[4] none [4] f4d477b372[0] 2bf3e548b9[0] none [0] 584147788c[0] 3f11911aa9[0] |
none:none none:none none:none ASM:Graph ASM:Graph none:none none:none |
FSG| none|none StarForce| tElock| Armadillo| Neolite| tElock| |
none none none lines=126 embedded dns lines=81 none none |
trace trace trace trace trace trace trace |
T:10:42:00 | WinXP | 151.33.165.19 (14-151.IOL.IT): ITALIA ONLINE S.P.A, CAGLIARI, SARDEGNA, IT. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:10:59:00 | WinXP | 208.125.40.153 (RR.COM): ROAD RUNNER HOLDCO LLC, ROCHESTER, NEW YORK, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:28:00 | WinXP | 68.151.243.247 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, EDMONTON, ALBERTA, CA. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 222 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 38 of 41 |
4180c19d91 NEW b6e91e001c NEW |
9f3f2de385 [0] d2275a6cf5[0] |
none:none none:none |
Armadillo| PolyEnE| |
none none |
trace trace |
T:13:01:00 | WinXP | 24.105.219.43 (MHCABLE.COM): MID-HUDSON CABLEVISION INC. (CATSKILL), COEYMANS HOLLOW, NEW YORK, US. (DSL) |
218.93.205.30:65520 | CN:proxim.ircgalaxy.pl EU:sleepatnight.cn CN:218.93.205.30:65520 |
445 | pcap | raw alerts ruleset |
http irc 5 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 36 | 04ed4d2967 NEW |
e8aa304d1c [0] | none:none |
PolyEnE| | none | trace |
T:13:05:00 | WinXP | 63.28.74.86 (UU.NET): UUNET TECHNOLOGIES INC, STAFFORD, VIRGINIA, US. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com RU:www.bbin.ru RU:www.binbank.ru :wpad US:208.73.210.125:80 DE:212.227.111.29:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http http http http 24 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:14:00:00 | Win2K-f | 68.146.136.164 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
92.240.234.164:3305 | TH:cx10man.weedns.com :fx010413.whyI.org 92.240.234.164:3305 |
135 | pcap | raw alerts ruleset |
irc 608 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 41 | 9ce56f9f19 NEW |
261c9da48f [0] | none:none |
StarForce| | none | trace |
T:14:17:00 | WinXP | 24.213.224.238 (RR.COM): ROAD RUNNER HOLDCO LLC, AMSTERDAM, NOORD-HOLLAND, NL. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:18:00 | Win2K-f | 203.76.105.17 (NEKSUS.COM): LINK3 TECHNOLOGIES LTD, DHAKA, DHAKA, BD. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 345 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 41 | cc88f4f016 NEW |
3d17903825 [0] | none:none |
StarForce| | none | trace | |
T:16:52:00 | Win2K-f | 75.179.184.106 (RR.COM): ROAD RUNNER HOLDCO LLC, BLACKLICK, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 114 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
63546c3b33 NEW 895c10c5ed NEW |
52748673c6 [0] eabab17862[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:17:18:00 | WinXP | 58.93.129.54 (PLALA.OR.JP): NTT PLALA INC, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | ASM:Graph |
none|none | lines=61 | trace | |
T:17:29:00 | WinXP | 187.89.171.75 (CAMPUSEAI.ORG): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace | |
T:17:42:00 | WinXP | 24.164.56.95 (RR.COM): ROAD RUNNER HOLDCO LLC, LAKELAND, FLORIDA, US. (DSL) |
200.49.145.197:3305 | AR:cx10man.weedns.com FI:fx010413.whyI.org :gynoman.weedns.com FI:g.0x20.biz FI:telephone.dd.blueline.be AR:phonewire.dd.blueline.be FI:212.54.2.171:3305 92.240.234.164:3305 |
135 | pcap | raw alerts ruleset |
irc 612 lines |
Yeah : 1.8 profile |
none | summary tarball |
40 of 41 | 2187d1dd44 NEW |
c2248c0c3e [0] | none:none |
StarForce| | none | trace |
T:18:18:00 | WinXP | 4.226.125.50 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, HOT SPRINGS NATIONAL PARK, ARKANSAS, US. (DIAL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:18:27:00 | Win2K-f | 118.87.20.81 (ODWR.J-CNET.JP): ODAWARA CABLETV INTERNET SERVICE, ODAWARA, KANAGAWA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 127 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 36 34 of 36 |
0b951c2832 NEW e4ed4df0f0 NEW |
5fe761661a [0] de471fc380[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
18:36:00 | Win2K-f | 190.0.77.238 (ASTER.COM.DO): ASTER, SANTO DOMINGO, DISTRITO NACIONAL, DO. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:19:14:00 | WinXP | 201.173.187.122 (INTERCABLE.NET): TELEVISION INTERNACIONAL S.A. DE C.V, MONTERREY, NUEVO LEON, MX. (100Mbps) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:19:58:00 | Win2K-f | 122.146.82.73 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 121 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 39 39 of 40 |
4949888849 NEW 7f66679cac NEW |
6e1ae1dc22 [0] b4110dd473[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:20:03:00 | WinXP | 114.48.21.113 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 13 lines |
Argh : 0.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:20:11:00 | Win2K-f | 203.91.165.198 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:20:58:00 | Win2K-f | 68.144.30.11 (HUB.SYSTEM.IO): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 39 40 of 41 |
19f9cb1f21 NEW a9d40bc96b NEW |
8b1482be5d [0] b07fa6d434[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:22:29:00 | Win2K-f | 211.117.46.190 (-): HANANET-LLINE-KICOX, SEOUL, SEOUL-T'UKPYOLSI, KR. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 33 of 33 |
4c3df24b32 NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=75 embedded dns |
trace trace |
T:23:49:00 | WinXP | 189.48.244.131 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, RIO DE JANEIRO, RIO DE JANEIRO, BR. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | e1a7bda6ff NEW |
cfc8c71bb6 [0] | none:none |
PolyEnE| | none | trace |