Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
12:16:00 | WinXP | 98.141.30.61 (CAVTEL.NET): CAVALIER TELEPHONE, NORFOLK, VIRGINIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:22:15:00 | WinXP | 98.141.17.98 (CAVTEL.NET): CAVALIER TELEPHONE, HAMPTON, VIRGINIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:22:28:00 | Win2K-f | 122.19.83.245 (OCN.NE.JP): OPEN COMPUTER NETWORK, OTSU, SHIGA, JP. (DSL) |
n/a | EE:www.starman.ee | 135 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:22:52:00 | WinXP | 114.51.19.29 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | none:none |
PolyEnE| | none | trace |
T:23:01:00 | WinXP | 60.56.156.141 (EONET.NE.JP): K-OPTICOM CORPORATION, SANDA, HYOGO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 | 8ab0fb88b8 NEW |
968cc91789 [0] | none:none |
none|none | none | trace | |
23:12:00 | WinXP | 203.192.202.147 (IN2CABLE.COM): IN2CABLE (INDIA) LTD, INDORE, MADHYA PRADESH, IN. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:23:30:00 | Win2K-f | 113.254.21.75 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |