Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:02:41:00 | WinXP | 87.48.83.77 (DSL.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, COPENHAGEN, KOBENHAVN, DK. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:03:21:00 | WinXP | 222.230.153.143 (VECTANT.NE.JP): SEIKA CORPORATION, YOKOHAMA, KANAGAWA, JP. (100Mbps) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | ASM:Graph |
none|none | lines=61 | trace | |
T:04:47:00 | WinXP | 79.162.154.159 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
213.219.245.212:80 218.93.205.30:65520 | CN:proxim.ircgalaxy.pl RU:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http irc 4 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 36 | 9bb68450cd NEW |
c2d5ac2315 [0] | ASM:Graph |
PolyEnE| | lines=73 embedded dns |
trace |
T:05:07:00 | WinXP | 114.48.9.173 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:05:22:00 | WinXP | 4.191.40.231 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, YAKIMA, WASHINGTON, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 124 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:06:13:00 | WinXP | 125.0.16.106 (INFOWEB.NE.JP): FUJITSU LIMITED, TOKYO, TOKYO, JP. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:06:52:00 | WinXP | 60.56.44.235 (EONET.NE.JP): K-OPTICOM CORPORATION, KOBE, HYOGO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:07:35:00 | WinXP | 88.210.73.142 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, LISBON, LISBOA, PT. (DSL) |
n/a | US:www.altavista.com :www.google.com.au :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 17028f1eda NEW |
none[3] | none:none |
tElock| | none | trace |
T:07:40:00 | Win2K-f | 173.22.154.11 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, SPRINGFIELD, MISSOURI, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:08:19:00 | WinXP | 205.158.100.75 (CONCENTRIC.NET): XO COMMUNICATIONS, CHICAGO, ILLINOIS, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
08:38:00 | Win2K-f | 84.236.144.36 (VL250-IXN-MAD-OPENCABLE-CF.AIRENETWORKS.ES): SERVIHOSTING NETWORKS S.L, ES. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org EU:getmyip.co.uk 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | d60e538e72 NEW |
none[3] | none:none |
UPX| | none | trace |
T:08:47:00 | Win2K-f | 84.236.144.36 (VL250-IXN-MAD-OPENCABLE-CF.AIRENETWORKS.ES): SERVIHOSTING NETWORKS S.L, ES. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk GB:www.vouchercodez.com :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 7 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | d60e538e72 NEW |
none[3] | none:none |
UPX| | none | trace |
T:08:48:00 | WinXP | 4.188.135.53 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, BELVIDERE, ILLINOIS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 140 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
|
09:17:00 | Win2K-f | 190.137.206.7 (NET.AR): APOLO -GOLD-TELECOM-PER, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org EU:getmyip.co.uk US:www.getmyip.org 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 7587773eea NEW |
none[3] | none:none |
StarForce| | none | trace |
T:09:37:00 | Win2K-f | 70.183.102.110 (COX.NET): COX COMMUNICATIONS, LA MESA, CALIFORNIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 580 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 | 97fa4ad4b5 NEW |
f1fc776893 [0] | none:none |
PolyEnE| | none | trace | |
T:14:41:00 | WinXP | 96.8.145.191 (GVTC.COM): GUADALUPE VALLEY TELEPHONE COOPERATIVE INC, NEW BRAUNFELS, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 39 of 41 |
77656a2953 NEW a77e51636f NEW |
13296a6198 [0] c5e16ba6b7[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:15:44:00 | WinXP | 82.66.147.1 (PROXAD.NET): PROXAD / FREE SAS, PARIS, ILE-DE-FRANCE, FR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 4e542c3ee4 NEW |
49662a1d03 [0] | none:none |
none|none | none | trace | |
T:16:18:00 | Win2K-f | 4.231.155.20 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, HUMBLE, TEXAS, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:55:00 | WinXP | 216.249.208.195 (MT-RUSHMORE.NET): FORT RANDALL TELEPHONE CO, HURON, SOUTH DAKOTA, US. (DSL) |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | a6a5edfece NEW |
75979eec19 [0] | none:none |
PolyEnE| | none | trace |
T:16:59:00 | WinXP | 12.74.195.125 (ATT.NET): AT&T WORLDNET SERVICES, DALLAS, TEXAS, US. (DIAL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:17:44:00 | Win2K-f | 24.87.194.20 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SQUAMISH, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 599 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 | bf740abeaf NEW |
1e6af813ad [0] | none:none |
StarForce| | none | trace | |
T:18:20:00 | Win2K-f | 123.214.205.136 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
193.104.94.11:65520 218.93.205.30:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:dl.guarddog2009.com :komojoke.cn CN:config1007.iwillhavesexygirls.com CN:maillist.iwillhavesexygirls.com EU:colopin.cn :bfkq.com :jsactivity.com FR:193.104.94.11:65520 US:66.96.221.101:8392 EU:91.206.201.39:80 |
135 | pcap | raw alerts ruleset |
irc http 156 lines |
Yeah : 1.8 profile |
none | summary tarball |
14 of 40 8 of 40 12 of 40 15 of 41 29 of 32 28 of 32 23 of 40 |
0b112b366f NEW 217611965c NEW 45b00b6927 NEW 83192a6119 NEW 8a75955033 NEW 9276c8b36b NEW edc631287a NEW |
934744264f [0] 5f46de0236[0] bae7328e81[0] fdc95e1fab[0] 2bf3e548b9[0] none [0] cfe906bf45[0] |
none:none none:none none:none none:none ASM:Graph ASM:Graph none:none |
Neolite| StarForce| Armadillo| none|none tElock| Armadillo| none|none |
none none none none lines=126 embedded dns lines=81 none |
trace trace trace trace trace trace trace |
T:18:37:00 | Win2K-f | 189.15.28.22 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, UBERLāNDIA, MINAS GERAIS, BR. (DSL) |
218.93.205.30:65520 | US:search.toptravellingtips.com CN:proxim.ircgalaxy.pl CN:www.brans.pl CN:dl.guarddog2009.com EU:colopin.cn US:microsoft.com EU:91.206.201.39:80 |
445 | pcap | raw alerts ruleset |
http irc 91 lines |
Yeah : 1.3 profile |
none | summary tarball |
12 of 40 6 of 40 0 of 40 23 of 40 |
93bca46541 NEW cc80b3c30b NEW d3e59debed NEW edc631287a NEW |
d1f10827ed [0] 8e26ea193e[0] none [4] cfe906bf45[0] |
none:none none:none none:none none:none |
StarForce| StarForce| none|none none|none |
none none none none |
trace trace trace trace |
T:19:21:00 | Win2K-f | 173.29.253.168 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, CHANHASSEN, MINNESOTA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 40 |
474acf88e5 NEW 68f0c14692 NEW |
1f53944b24 [0] ccc1b24d53[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:19:32:00 | WinXP | 78.251.181.10 (PROXAD.NET): PROXAD INTERNET SERVICE PROVIDER IN FRANCE, FR. (DSL) |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 912a073945 NEW |
7874c7f21e [0] | none:none |
PolyEnE| | none | trace |
20:00:00 | WinXP | 12.74.195.125 (ATT.NET): AT&T WORLDNET SERVICES, DALLAS, TEXAS, US. (DIAL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:20:32:00 | WinXP | 207.5.161.171 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:49:00 | Win2K-f | 113.254.91.79 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 11 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:23:53:00 | Win2K-f | 72.190.112.103 (RR.COM): ROAD RUNNER HOLDCO LLC, DALLAS, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |