Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:04:00 | WinXP | 122.202.26.82 (YCT.NE.JP): YAKAGE CABLE TELEVISION, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:01:22:00 | Win2K-f | 173.18.224.173 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, EXCELSIOR, MINNESOTA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 40 |
474acf88e5 NEW 68f0c14692 NEW |
1f53944b24 [0] ccc1b24d53[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:01:53:00 | Win2K-f | 123.215.35.89 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
88.198.228.238:65520 193.104.94.11:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:av.ghura.pl EU:colopin.cn CN:www.petdoso.com CN:q.kfgrtjer.cn CN:www.liagand.cn CN:202.97.184.196:81 |
135 | pcap | raw alerts ruleset |
irc http 140 lines |
Yeah : 1.8 profile |
none | summary tarball |
30 of 40 29 of 41 29 of 32 28 of 32 23 of 41 6 of 41 |
3c4fbb459d NEW 785e86954f NEW 8a75955033 NEW 9276c8b36b NEW 9b6ea363eb NEW de5125b518 NEW |
none[none] c6edee8e8b[0] 2bf3e548b9[0] none [0] 7a32f7a54f[none] none [none] |
none:none none:none ASM:Graph ASM:Graph none:none none:none |
none|none PeStubOEP| tElock| Armadillo| UPX| none|none |
none none lines=126 embedded dns lines=81 none none |
none trace trace trace none none |
T:02:14:00 | Win2K-f | 75.37.173.250 (SBCGLOBAL.NET): JASON LEE, PLANO, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
02:41:00 | Win2K-f | 115.194.192.152 (HZ.ZJ.CN): CHINANET-ZJ HANGZHOU NODE NETWORK, BEIJING, BEIJING, CN. (DSL) |
n/a | US:www.maxmind.com US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:04:17:00 | WinXP | 76.202.6.225 (PACBELL.NET): AT&T INTERNET SERVICES, HOUSTON, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:05:02:00 | WinXP | 114.48.154.12 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | e49bd14db6 NEW |
cd910f4cfa [0] | none:none |
PolyEnE| | none | trace |
T:05:17:00 | WinXP | 186.9.46.216 (IMOVIL.ENTELPCS.CL): ENTEL PCS TELECOMUNICACIONES S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
35 of 35 | 9716d7995a NEW |
c3a5354b6f [0] | none:none |
PolyEnE| | none | trace | |
T:05:57:00 | WinXP | 113.255.73.129 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 11 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:05:59:00 | Win2K-f | 99.164.23.178 (SBCGLOBAL.NET): RANI PAL LLC, PLANO, TEXAS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 402 lines |
Yeah : 1.3 profile |
none | summary tarball |
11 of 36 | c4c5a56ffe NEW |
8bef2f9170 [0] | none:none |
StarForce| | none | trace | |
T:05:59:00 | WinXP | 60.39.34.1 (OCN.NE.JP): OPEN COMPUTER NETWORK, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
07:04:00 | Win2K-f | 94.184.96.112 (-): NPD OF IKCO CO, TEHRAN, ESFAHAN, IR. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:07:13:00 | Win2K-f | 94.184.96.112 (-): NPD OF IKCO CO, TEHRAN, ESFAHAN, IR. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk GB:www.vouchercodez.com :checkip.dyndns.org US:www.getmyip.org DE:131.220.6.26:80 208.78.70.70:80 |
445 | pcap | raw alerts ruleset |
http 7 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
07:13:00 | Win2K-f | 201.225.127.20 (CWPANAMA.NET): CABLE & WIRELESS PANAMA, PA. (DSL) |
n/a | US:hrppinxp.org :bdnqpfljyfv.com :hiyhvtfb.net :vgzgx.biz :bedccpuev.biz US:nfojdhqc.org :ttafnhnkzw.net US:zqiznfyw.info :gffpkb.biz :zrwphxoai.com US:fyuzqagi.org :azjmwglbaf.net :zmhtwuhpssz.biz :zzohle.net :mlnzax.net US:rwspfom.info US:dbifd.org US:coiqbrseix.org :hlcvnezqh.net US:fezbjqbgtdp.org :ztgpgifr.com US:uestffae.info :cmwschic.com :uuooymc.biz :jszxtyudpwj.net US:gjmqxcu.org :lqznzgkq.net US:rhbfcyocomh.org US:kxugfuvzzk.info US:zyqjegu.org :szzyveyrphm.com :arptk.com :tsqkx.com US:xowlq.org US:qqsjwikiy.info :isjtfkm.com :jrcuwjy.biz US:owlps.info :mvpju.net NL:tfqysxkdbx.org :ftnkkrhugkd.biz US:znnflydubc.info :rgfbnw.com :ygyqlsqb.net :xhnekuijcdo.net US:mhwfuvfam.org :hbczullb.com US:mclbyuy.info :ajdbommayk.biz US:fbywi.info :xzpfenhi.net :njjflciy.biz :loapm.net :wvjfyijufbp.net :vxeovak.net :lprgyercckj.net :pizcntpi.net US:gdealwwmet.org :myiycfdv.net :fuklqdjlfbj.com US:cgnpxnhozge.info :cyztplbb.org NL:cnsyik.org :bivzrcok.net :gbhiha.com :jqrvplmjlr.com :balyowpi.com :kabxuj.biz :lrmijtywjxs.biz :rydlobepy.net US:204.152.184.139:80 US:74.208.64.145:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:08:12:00 | WinXP | 24.81.81.133 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, NORTH VANCOUVER, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 592 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 8ed7ea5f60 NEW |
none[none] | none:none |
none|none | none | none | |
T:08:13:00 | WinXP | 186.9.37.91 (IMOVIL.ENTELPCS.CL): ENTEL PCS TELECOMUNICACIONES S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:08:32:00 | WinXP | 218.32.98.19 (SDTV.NET.TW): SAN DA CATV CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 23 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:08:44:00 | WinXP | 218.224.139.113 (PLALA.OR.JP): NTT PLALA INC, NIIGATA, NIIGATA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 97616d9c7b NEW |
none[none] | none:none |
none|none | none | none | |
T:09:13:00 | WinXP | 83.29.232.157 (TPNET.PL): NEOSTRADA PLUS, LODZ, LODZKIE, PL. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | 03f912899b NEW |
none[0] | none:none |
none|none | lines=64 | trace | |
T:09:32:00 | WinXP | 173.19.210.234 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, IOWA CITY, IOWA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 40 |
474acf88e5 NEW 68f0c14692 NEW |
1f53944b24 [0] ccc1b24d53[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:09:55:00 | WinXP | 70.241.194.56 (SWBELL.NET): AT&T INTERNET SERVICES, ST. LOUIS, MISSOURI, US. (DSL) |
n/a | EU:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com SE:kavkazcenter.com SE:kavkazcenter.net FI:kavkazchat.com :chechenpress.info GB:chechenpress.co.uk :shaheeds.org :daymohk.info :chripress.org :marsho.dk FI:imgs2.kavkazcenter.com GB:www.chechenpress.co.uk :www.google.com :www.google-analytics.com :widget-c6.slide.com :www.youtube.com :blip.tv :wpad 174.46.45.151:80 SE:88.80.5.15:80 |
445 | pcap | raw alerts ruleset |
http http 120 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | ab5e47bf8d NEW |
67fb5eff61 [0] | none:none |
ASPack| | none | trace |
10:05:00 | Win2K-f | 217.23.10.62 (WORLDSTREAM.NL): WORLDSTREAM, NL. (DSL) |
n/a | 208.78.70.70:80 US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
18:08:00 | Win2K-f | 189.106.72.216 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, BELO HORIZONTE, MINAS GERAIS, BR. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 18 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:17:00 | Win2K-f | 123.97.119.7 (HZ.ZJ.CN): CHINANET-ZJ TAIZHOU NODE NETWORK, BEIJING, BEIJING, CN. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 18 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:00:00 | Win2K-f | 190.173.109.241 (COM.AR): TELEFONICA DE ARGENTINA, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
88.198.228.238:65520 | :pozemle.cn CA:maxdomzhit.com CN:www.liagand.cn EU:colopin.cn SE:www.iguardpc.com CN:www.petdoso.com US:trafficconverter.biz US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
irc http 33 lines |
Yeah : 1.3 profile |
none | summary tarball |
7 of 41 5 of 41 27 of 41 29 of 41 28 of 41 6 of 41 6 of 41 41 of 41 7 of 41 |
1b53f12497 NEW 1ee64d1c3c NEW 39046faac8 NEW 785e86954f NEW 8b9297aaa6 NEW c2d45244d9 NEW de5125b518 NEW dece7e8313 NEW f183776f39 NEW |
none[none] none [none] none [none] c6edee8e8b[0] none [none] none [none] none [none] d505dbcbf1[none] none [none] |
none:none none:none none:none none:none none:none none:none none:none none:none none:none |
none|none none|none none|none PeStubOEP| none|none none|none none|none ASProtect| none|none |
none none none none none none none none none |
none none none trace none none none none none |
23:12:00 | Win2K-f | 125.64.18.31 (163DATA.COM.CN): CHINANET SICHUAN PROVINCE NETWORK, CHENGDU, SICHUAN, CN. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |