Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:40:00 | WinXP | 76.170.204.145 (RR.COM): ROAD RUNNER HOLDCO LLC, LOS ANGELES, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:00:52:00 | Win2K-f | 65.34.30.26 (RR.COM): ROAD RUNNER HOLDCO LLC, CLERMONT, FLORIDA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:01:19:00 | WinXP | 211.22.219.109 (-): HUANG-KAI-JI-PT, KAOHSIUNG, T'AI-WAN, TW. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 38 of 41 |
3f136c55b3 NEW ac394d7d5f NEW |
f4e18974f3 [0] c9a79e75f5[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:02:30:00 | Win2K-f | 210.94.115.64 (SONICANT.CO.KR): THRUNET CO. LTD, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
218.93.205.30:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:www.brans.pl :komojoke.cn CN:218.93.205.19:80 93.174.92.220:80 |
135 | pcap | raw alerts ruleset |
irc 119 lines |
Yeah : 1.8 profile |
none | summary tarball |
30 of 33 28 of 33 |
533d15b5ce NEW 58c343a8d8 NEW |
c67adf46e2 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=126 embedded dns lines=91 |
trace trace |
T:02:46:00 | WinXP | 69.201.142.98 (RR.COM): ROAD RUNNER HOLDCO LLC, NEW YORK, NEW YORK, US. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com GB:new.egg.com :wpad US:204.13.161.51:80 |
445 | pcap | raw alerts ruleset |
http http http http 30 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:02:56:00 | Win2K-f | 207.5.121.144 (MICROLNK.COM): MICROLNK LLC, OMAHA, NEBRASKA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:47:00 | Win2K-f | 70.167.73.201 (COX.NET): COX COMMUNICATIONS, OCEANSIDE, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:04:09:00 | WinXP | 113.254.185.252 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 38 of 41 |
a5ceb6c29d NEW adadfc0e1c NEW |
d64cd9d18b [0] 0f57439d82[0] |
none:none none:none |
tElock| tElock| |
none none |
trace trace |
T:06:20:00 | WinXP | 203.91.165.198 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:07:05:00 | Win2K-f | 211.20.222.150 (HINET.NET): XUN HANG TECHNOLOGY CO. LTD, TAIPEI, T'AI-PEI, TW. (100Mbps) |
92.240.234.164:3305 | AR:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 696 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:07:11:00 | Win2K-f | 4.143.86.129 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, CLEVELAND, OHIO, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 39 37 of 39 |
166484192b NEW 2a1e547005 NEW |
0c886fcb7b [0] 5c75fa020a[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:07:51:00 | WinXP | 208.34.236.140 (ESINC.NET): ELECTRONIC SOLUTION INC, ROXBORO, NORTH CAROLINA, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:08:59:00 | WinXP | 4.231.155.8 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, HUMBLE, TEXAS, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 80 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:09:00:00 | WinXP | 95.75.123.51 (-): TELECOM ITALIA MOBILE, IT. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | fd98cc2311 NEW |
3f13afc4b1 [0] | none:none |
none|none | none | trace | |
T:11:12:00 | Win2K-f | 72.128.17.163 (RR.COM): ROAD RUNNER HOLDCO LLC, KANSAS CITY, KANSAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:11:21:00 | WinXP | 172.166.205.218 (AOL.COM): AMERICA ONLINE, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 141 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 39 of 41 |
932dbb4b69 NEW f6e5daee26 NEW |
dd4d9c7adf [0] 413c524714[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
11:50:00 | WinXP | 69.207.60.68 (RR.COM): ROAD RUNNER HOLDCO LLC, LOCKPORT, NEW YORK, US. (100Mbps) |
n/a | :moscow-advokat.ru SE:ced.dal.net :brussels.be.eu.undernet.org AT:graz.at.eu.undernet.org :caen.fr.eu.undernet.org :flanders.be.eu.undernet.org SE:broadway.ny.us.dal.net :washington.dc.us.undernet.org SE:qis.md.us.dal.net |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:13:11:00 | WinXP | 188.192.55.27 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. (DSL) |
n/a | EU:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :wpad GB:welcome3.smile.co.uk GB:195.92.84.198:80 |
445 | pcap | raw alerts ruleset |
http http http 27 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee NEW |
none[0] | none:none |
ASPack| | lines=298 embedded dns |
trace |
T:13:37:00 | Win2K-f | 66.25.119.119 (RR.COM): ROAD RUNNER HOLDCO LLC, BIRMINGHAM, ALABAMA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:13:40:00 | WinXP | 74.65.164.131 (RR.COM): ROAD RUNNER HOLDCO LLC, SOUTH PORTLAND, MAINE, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:14:55:00 | WinXP | 72.128.17.163 (RR.COM): ROAD RUNNER HOLDCO LLC, KANSAS CITY, KANSAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 60 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:15:42:00 | WinXP | 173.93.205.10 (RR.COM): ROAD RUNNER HOLDCO LLC, LEXINGTON, SOUTH CAROLINA, US. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :www.proxy-socks.net :wpad US:204.13.161.51:80 |
445 | pcap | raw alerts ruleset |
http http http 7 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:17:13:00 | Win2K-f | 68.192.32.204 (OPTONLINE.NET): OPTIMUM ONLINE (CABLEVISION SYSTEMS), BAYONNE, NEW JERSEY, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:17:29:00 | Win2K-f | 4.163.252.247 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, LOVELAND, COLORADO, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 160 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 00d318af6b NEW |
351f7b03c0 [0] | none:none |
Armadillo| | none | trace | |
T:17:44:00 | WinXP | 82.66.147.1 (PROXAD.NET): PROXAD / FREE SAS, PARIS, ILE-DE-FRANCE, FR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 | 4e542c3ee4 NEW |
49662a1d03 [0] | none:none |
none|none | none | trace | |
T:17:52:00 | WinXP | 190.185.19.115 (NODE-BE0B9E0A.SCARLET.AN): SCARLET B.V, WILLEMSTAD, CURACAO, AN. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 945cb548ce NEW |
9c2350203d [0] | none:none |
PolyEnE| | none | trace |
T:18:52:00 | Win2K-f | 67.8.48.244 (RR.COM): ROAD RUNNER HOLDCO LLC, LONGWOOD, FLORIDA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:19:22:00 | WinXP | 75.187.198.55 (RR.COM): ROAD RUNNER HOLDCO LLC, LOS ANGELES, CALIFORNIA, US. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:22:03:00 | WinXP | 99.179.96.1 (PACBELL.NET): AT&T INTERNET SERVICES, AUSTIN, TEXAS, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:22:39:00 | WinXP | 174.6.21.151 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |