Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:41:00 | Win2K-f | 217.118.193.19 (OSS-SERVICES.CH): DELTAPOINT AG, ZURICH, ZURICH, CH. (100Mbps) |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org DE:131.220.6.26:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:09:36:00 | WinXP | 83.97.220.151 (CM-83-97-220-10.TELECABLE.ES): TELECABLE, GIJON, ASTURIAS, ES. (DSL) |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1fcc146d70 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:09:54:00 | Win2K-f | 4.226.165.105 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, MILLINGTON, TENNESSEE, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 29 lines |
Yeah : 1.3 profile |
none | summary tarball |
4 of 41 | e9e92c9470 NEW |
none[none] | none:none |
none|none | none | none | |
T:10:10:00 | Win2K-f | 69.193.74.22 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:16:00 | Win2K-f | 114.203.62.178 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
218.93.205.30:65520 | US:microsoft.com CN:proxima.ircgalaxy.pl CN:www.brans.pl :pozemle.cn EU:colopin.cn CN:config1007.iwillhavesexygirls.com CN:russia.2288.org :wws.mobiec.net CN:js.users.51.la CN:icon.ajiang.net CN:web.51.la :xz.ub9.net CN:www.petdoso.com :in.7cy.net :in1.7cy.net US:criminallawyercell.info US:speedywindshieldrepair.info GB:www.businesstomb.com US:growthhormoneproducts.com :cuguy.com :pdffilesite.com |
135 | pcap | raw alerts ruleset |
irc http 137 lines |
Yeah : 1.8 profile |
none | summary tarball |
31 of 33 24 of 41 17 of 41 31 of 33 29 of 41 26 of 41 41 of 41 5 of 41 23 of 40 |
168aab35a3 NEW 380d81c374 NEW 49a0d63ff3 NEW 667f0c59f3 NEW 785e86954f NEW dd96e88e03 NEW dece7e8313 NEW df2ceea992 NEW fd5d639b8d NEW |
60b730b97e [0] none [none] none [none] 8fe2be2095[0] c6edee8e8b[0] 6f87541765[0] none [none] none [none] none [none] |
ASM:Graph none:none none:none ASM:Graph none:none none:none none:none none:none none:none |
tElock| none|none none|none Armadillo| PeStubOEP| StarForce| none|none none|none none|none |
lines=120 embedded dns none none lines=91 none none none none none |
trace none none trace trace trace none none none |
T:11:57:00 | Win2K-f | 78.106.173.16 (CORBINA.RU): BROADBAND CUSTOMERS IN MOSCOW, MOSCOW, MOSCOW CITY, RU. (DSL) |
193.104.94.11:65520 | US:searchportal.information.com US:spi.domainsponsor.com GB:www.businesstomb.com US:xz.ub9.net CN:proxima.ircgalaxy.pl EU:colopin.cn US:beautyclone.com US:ads1.revenue.net :panther1.cpxinteractive.com :adserving.cpxinteractive.com US:content.yieldmanager.com US:cookex.amp.yahoo.com US:activex.microsoft.com US:codecs.microsoft.com CN:www.petdoso.com CA:bargainventures.com CA:flyingenthusiast.com US:sprayairfresheners.com US:ventmotors.com |
445 | pcap | raw alerts ruleset |
http irc 73 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 41 | 896f1f0d01 NEW |
none[none] | none:none |
none|none | none | none |
T:13:31:00 | Win2K-f | 24.167.191.56 (RR.COM): ROAD RUNNER HOLDCO LLC, HIGH POINT, NORTH CAROLINA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:13:48:00 | Win2K-f | 208.126.80.146 (NETINS.NET): SENECA TELEPHONE COMPANY, NOEL, MISSOURI, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 39 of 41 |
2c26b059c2 NEW 6acaa6978a NEW |
73425e8808 [0] 13a339bb33[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:15:09:00 | Win2K-f | 69.193.78.147 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:15:20:00 | WinXP | 109.86.177.101 (JWS.COM): EU-ZZ, UK. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru :adult-empire.com |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 01c4a6b3eb NEW |
dd524b0259 [0] | none:none |
PolyEnE| | none | trace |
T:15:40:00 | Win2K-f | 71.127.246.16 (VERIZON.NET): VERIZON INTERNET SERVICES INC, RED BANK, NEW JERSEY, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
irc 7 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:16:01:00 | Win2K-f | 96.48.196.52 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SURREY, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:17:09:00 | Win2K-f | 174.2.16.196 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SASKATOON, SASKATCHEWAN, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 222 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 38 of 41 |
4180c19d91 NEW b6e91e001c NEW |
9f3f2de385 [0] d2275a6cf5[0] |
none:none none:none |
Armadillo| PolyEnE| |
none none |
trace trace |
T:18:55:00 | Win2K-f | 70.184.12.131 (COX.NET): COX COMMUNICATIONS, NORTH KINGSTOWN, RHODE ISLAND, US. (DSL) |
218.93.205.30:65520 | US:microsoft.com FR:proxim.ircgalaxy.pl CN:dl.guarddog2009.com :pozemle.cn DE:zstudio1.cn EU:colopin.cn CN:config1007.iwillhavesexygirls.com CN:russia.2288.org :wws.mobiec.net CN:js.users.51.la CN:icon.ajiang.net CN:web.51.la :xz.ub9.net CN:www.petdoso.com :bgroup2.cn :in.7cy.net :in1.7cy.net US:newmarketinglabs.info US:autoinsurancedawn.info US:homepricelookup.com US:homevacancies.com :superphotospot.com CN:202.97.184.196:81 DE:84.16.243.241:80 |
135 | pcap | raw alerts ruleset |
irc http 903 lines |
Yeah : 1.8 profile |
none | summary tarball |
0 of 41 0 of 41 17 of 41 17 of 41 29 of 41 15 of 41 8 of 41 32 of 36 26 of 41 35 of 36 |
0d59e8b72d NEW 1bbcd68031 NEW 1c5e79f5f4 NEW 49a0d63ff3 NEW 785e86954f NEW 83192a6119 NEW b1e1aa3d77 NEW bea8cb1865 NEW dd96e88e03 NEW fac78fde16 NEW |
none[none] none [none] none [4] none [none] c6edee8e8b[0] fdc95e1fab[0] none [none] 154de51a66[0] 6f87541765[0] 882896ab05[0] |
none:none none:none none:none none:none none:none none:none none:none ASM:Graph none:none none:none |
none|none none|none FSG| none|none PeStubOEP| none|none none|none Armadillo| StarForce| tElock| |
none none none none none none none lines=91 none none |
none none trace none trace trace none trace trace trace |
T:19:07:00 | Win2K-f | 32.178.245.245 (MYCINGULAR.NET): AT&T GLOBAL NETWORK SERVICES LLC, NEW YORK, NEW YORK, US. (DSL) |
218.93.205.30:65520 | US:usafoodindustry.com US:zoo.parkingspa.com US:xz.ub9.net FR:proxim.ircgalaxy.pl :pozemle.cn US:devicesmarkets.com EU:colopin.cn CN:www.petdoso.com US:rc10.overture.com :www.cromermaterialhandling.com GB:dev.virtualearth.net US:c66.yellowpages.com :dci-press.com US:yorkshireguides.com FR:193.104.94.11:65520 CN:202.97.184.196:81 US:208.109.98.106:80 US:66.246.235.42:80 |
445 | pcap | raw alerts ruleset |
http irc http http 107 lines |
Yeah : 0.8 profile |
none | summary tarball |
17 of 41 29 of 41 8 of 41 |
1c5e79f5f4 NEW 785e86954f NEW b1e1aa3d77 NEW |
none[4] c6edee8e8b[0] none [none] |
none:none none:none none:none |
FSG| PeStubOEP| none|none |
none none none |
trace trace none |
T:20:17:00 | Win2K-f | 206.131.28.251 (MN.US): BROOKLYN CENTER SCHOOL DISTRICT, MINNEAPOLIS, MINNESOTA, US. (DSL) |
n/a | FI:194.215.38.3:80 EE:62.65.192.24:80 |
135 | pcap | raw alerts ruleset |
irc 3 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:37:00 | Win2K-f | 190.49.164.99 (COM.AR): TELEFONICA DE ARGENTINA, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk :checkip.dyndns.org DE:131.220.6.26:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 3862324588 NEW |
none[3] | none:none |
UPX| | none | trace |
T:20:45:00 | Win2K-f | 190.49.164.99 (COM.AR): TELEFONICA DE ARGENTINA, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 3862324588 NEW |
none[3] | none:none |
UPX| | none | trace |
T:21:33:00 | WinXP | 124.44.74.215 (WAKWAK.NE.JP): XEPHION(NTT-ME CORPORATION), OKAYAMA, OKAYAMA, JP. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:22:08:00 | Win2K-f | 63.246.122.215 (ALTUSCGI.NET): PRIVATE CABLE ISP SUBSCRIBER (GEORGETOWN SC MARKET), GEORGETOWN, SOUTH CAROLINA, US. (DSL) |
n/a | FI:194.215.38.3:80 EE:62.65.192.25:80 |
135 | pcap | raw alerts ruleset |
irc 3 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
23:08:00 | WinXP | 64.188.132.213 (-): WINDJAMMER COMMUNICATIONS LLC, APPLETON, WISCONSIN, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
none[none] | none:none |
none|none | none | none |
T:23:24:00 | Win2K-f | 211.208.192.210 (HANANET.NET): HANARO TELECOM INC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 6 of 41 |
5213395833 NEW 9fdf6de4a9 NEW |
515eacbc36 [0] 794f9a1087[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:23:54:00 | Win2K-f | 174.0.6.93 (KODIAKPETROLEUM.COM): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 227 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 39 of 41 |
4180c19d91 NEW 68f14883ff NEW |
9f3f2de385 [0] none [none] |
none:none none:none |
Armadillo| none|none |
none none |
trace none |