Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
02:09:00 | Win2K-f | 119.145.71.251 (163DATA.COM.CN): CHINANET GUANGDONG PROVINCE NETWORK, SHENZHEN, GUANGDONG, CN. (DSL) |
n/a | EE:www.starman.ee FI:194.215.38.3:80 US:204.152.184.139:80 EE:62.65.192.24:80 EE:62.65.192.25:80 |
445 | pcap | raw alerts ruleset |
http http irc 36 lines |
Argh : 0.3 profile |
none | summary tarball |
25 of 40 | bcb00c51ad NEW |
none[none] | none:none |
none|none | none | none |
06:02:00 | Win2K-f | 80.234.11.227 (SAMTEL.RU): SAMTEL, RU. (DSL) |
193.104.94.11:65520 | DE:proxim.ircgalaxy.pl CN:av.ghura.pl CN:q.kfgrtjer.cn :pozemle.cn EU:colopin.cn NL:www.iguardpc.com CN:www.petdoso.com CN:config1130.iwillhavesexygirls.com CN:russia.2288.org :wws.mobiec.net :xz.ub9.net :in.7cy.net :in1.7cy.net 174.133.57.140:80 CN:202.97.184.196:81 US:204.152.184.139:80 NL:85.12.25.111:80 DE:88.198.228.238:65520 |
445 | pcap | raw alerts ruleset |
irc http 30 lines |
Yeah : 1.3 profile |
none | summary tarball |
27 of 41 29 of 41 23 of 41 17 of 41 26 of 41 |
39046faac8 NEW 785e86954f NEW 9b6ea363eb NEW caeaaf2400 NEW dd96e88e03 NEW |
none[none] c6edee8e8b[0] 7a32f7a54f[none] none [none] 6f87541765[0] |
none:none none:none none:none none:none none:none |
none|none PeStubOEP| UPX| none|none StarForce| |
none none none none none |
none trace trace none trace |
06:09:00 | Win2K-f | 94.24.188.81 (IS74.RU): INTERSVYAZ-2 JSC, RU. (DSL) |
n/a | US:familyroomdecorations.com US:as.casalemedia.com :images.ddc.com :s7.addthis.com US:domdex.com US:activex.microsoft.com :b.collective-media.net :a.collective-media.net :ad.yieldmanager.com US:codecs.microsoft.com US:ad.adtegrity.net US:204.152.184.139:80 US:64.38.232.180:80 |
445 | pcap | raw alerts ruleset |
http irc 74 lines |
Argh : 0.3 profile |
none | summary tarball |
0 of 40 | c374d4a5ed NEW |
none[none] | none:none |
none|none | none | none |
06:14:00 | Win2K-f | 114.37.211.194 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:activex.microsoft.com US:codecs.microsoft.com FI:194.215.38.3:80 EE:62.65.192.24:80 66.114.48.53:80 |
445 | pcap | raw alerts ruleset |
http irc 97 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
07:59:00 | Win2K-f | 95.24.239.20 (CORBINA.RU): INVESTELEKTROSVIAZ LTD, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | :in1.7cy.net US:mortgagebanksloan.info FI:194.215.38.3:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
08:05:00 | Win2K-f | 189.121.170.83 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | US:amritaisland.com US:as.casalemedia.com :images.ddc.com :s7.addthis.com :b.collective-media.net :a.collective-media.net US:varickmm.demdex.net :pixel.vmm-satellite2.com :segment-pixel.invitemedia.com :ad.yieldmanager.com US:ad.adtegrity.net 174.129.137.196:80 US:204.152.184.139:80 66.114.48.11:80 US:66.94.242.24:80 67.202.29.105:80 |
445 | pcap | raw alerts ruleset |
http 45 lines |
Argh : 0.3 profile |
none | summary tarball |
0 of 41 | a8262c8483 NEW |
none[none] | none:none |
none|none | none | none |
09:15:00 | Win2K-f | 83.39.177.3 (RIMA-TDE.NET): TELEFONICA DE ESPANA, MADRID, MADRID, ES. (DSL) |
n/a | EE:www.starman.ee FI:194.215.38.3:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
09:36:00 | Win2K-f | 187.14.159.244 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, RIO DE JANEIRO, RIO DE JANEIRO, BR. (DSL) |
n/a | FI:194.215.38.3:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
09:46:00 | Win2K-f | 190.78.115.185 (CANTV.NET): CANTV SERVICIOS VENEZUELA, VALENCIA, CARABOBO, VE. (DSL) |
n/a | FI:194.215.38.3:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
10:16:00 | Win2K-f | 88.31.216.6 (RIMA-TDE.NET): TELEFONICA MOVILES ESPANA (NCC#2007041930), MADRID, MADRID, ES. (DSL) |
n/a | EE:www.starman.ee 174.133.57.140:80 FI:194.215.38.3:80 US:204.152.184.139:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
23:26:00 | Win2K-f | 115.84.178.105 (-): VIETTEL - CHT COMPANY LTD, VN. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org DE:131.220.6.26:80 208.78.70.70:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | 223d8089f8 NEW |
none[3] | none:none |
StarForce| | none | trace |