Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
02:08:00 | Win2K-f | 79.36.255.27 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA NET, ROME, LAZIO, IT. (DSL) |
n/a | US:msn.com US:yahoo.com US:trafficconverter.biz CN:proxim.ircgalaxy.pl 174.133.57.140:80 US:204.152.184.139:80 DE:88.198.228.238:65520 |
445 | pcap | raw alerts ruleset |
http 18 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
02:39:00 | Win2K-f | 195.34.116.130 (-): DELTANET, SOFIA, GRAD SOFIYA, BG. (DSL) |
88.198.228.238:65520 | :google.com US:cnn.com CN:proxim.ircgalaxy.pl CN:giopnon.cn CN:q.kfgrtjer.cn 174.133.57.140:80 US:204.152.184.139:80 CN:210.51.36.215:88 CN:218.93.205.19:80 |
445 | pcap | raw alerts ruleset |
irc 24 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
02:52:00 | Win2K-f | 121.32.147.131 (163DATA.COM.CN): CHINANET GUANGDONG PROVINCE NETWORK, GUANGZHOU, GUANGDONG, CN. (DSL) |
n/a | :google.com :www.google.com US:etesjkgji.org US:fmfeynmgzp.org :wlzibbm.org :eterqglfytu.org :azzjirkoob.biz :xirqgtkn.com :exjaxmpayc.com US:lnnfrthqmiv.org :qmrpshau.biz US:ucwqsskeydq.org :ynpyyzwh.com :ugzjgrwi.com :wpktbcvg.biz :ahyfpwhc.net US:gbeojfih.org US:pxusathbcz.org US:jsegqig.info US:xdnmqvwjske.info :ggvihcvdeb.com US:ktwzipyahn.info 174.133.57.140:80 US:204.152.184.139:80 US:74.208.64.145:80 |
445 | pcap | raw alerts ruleset |
irc http 32 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
07:34:00 | Win2K-f | 77.104.69.99 (-): RESPINA NETWORKS & BEYOND, IR. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org US:www.getmyip.org EU:getmyip.co.uk DE:131.220.6.26:80 208.78.70.70:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
09:42:00 | Win2K-f | 186.18.201.252 (186.IN-ADDR.ARPA): TELECENTRO S.A. - CLIENTES RESIDENCIALES, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org EU:getmyip.co.uk :checkip.dyndns.org 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:10:04:00 | Win2K-f | 77.104.69.99 (-): RESPINA NETWORKS & BEYOND, IR. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk GB:www.vouchercodez.com :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 7 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:10:10:00 | Win2K-f | 186.18.201.252 (186.IN-ADDR.ARPA): TELECENTRO S.A. - CLIENTES RESIDENCIALES, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:10:35:00 | Win2K-f | 70.72.5.248 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 21e8d2c711 NEW |
none[none] | none:none |
none|none | none | none | |
T:11:05:00 | WinXP | 186.9.46.28 (IMOVIL.ENTELPCS.CL): ENTEL PCS TELECOMUNICACIONES S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [none] | none:none |
PolyEnE| | none | trace |
T:13:16:00 | WinXP | 70.182.68.25 (COX.NET): COX COMMUNICATIONS, NORMAN, OKLAHOMA, US. (DSL) |
218.93.205.30:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:giopnon.cn CN:www.liagand.cn CA:maxdomzhit.com EU:colopin.cn :lsxcl.com CN:www.petdoso.com |
135 | pcap | raw alerts ruleset |
irc http 140 lines |
Yeah : 1.8 profile |
none | summary tarball |
11 of 41 3 of 41 8 of 41 32 of 33 29 of 33 41 of 41 6 of 41 18 of 41 23 of 40 |
493fe47d6d NEW 8080eeef6b NEW 82769f26d2 NEW 87e1117f2a NEW b4fe4581c3 NEW dece7e8313 NEW e5772d7d3f NEW f22223e96e NEW fd5d639b8d NEW |
none[none] none [none] none [none] 3ff643aae6[0] 599b835896[0] d505dbcbf1[none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none none:none none:none none:none |
none|none none|none none|none tElock| Armadillo| ASProtect| none|none none|none StarForce| |
none none none none none none none none none |
none none none trace trace trace none none trace |
14:39:00 | Win2K-f | 66.44.10.183 (RCN.COM): RCN CORPORATION, ROCKVILLE, MARYLAND, US. (DIAL) |
n/a | :google.com US:fluttertops.com :xz.ub9.net :recordnes.com US:searchportal.information.com US:spi.domainsponsor.com US:microsoft.com US:204.152.184.139:80 US:64.38.232.180:80 |
445 | pcap | raw alerts ruleset |
http 29 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
14:46:00 | Win2K-f | 201.58.131.196 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | US:msn.com US:www.getmyip.org EU:getmyip.co.uk GB:www.vouchercodez.com :checkip.dyndns.org 208.78.70.70:80 CN:218.93.205.30:65520 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
15:20:00 | Win2K-f | 186.18.193.215 (186.IN-ADDR.ARPA): TELECENTRO S.A. - CLIENTES RESIDENCIALES, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | US:msn.com GB:www.vouchercodez.com :checkip.dyndns.org :google.com 208.78.70.70:80 DE:88.198.228.238:65520 |
445 | pcap | raw alerts ruleset |
http 22 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
15:41:00 | Win2K-f | 94.52.37.168 (-): NEW COM TELECOMUNICATII SA, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | :google.com GB:www.vouchercodez.com US:www.getmyip.org US:yahoo.com US:75.126.138.202:80 DE:88.198.228.238:65520 |
445 | pcap | raw alerts ruleset |
http 23 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:15:55:00 | WinXP | 76.166.145.44 (RR.COM): ROAD RUNNER HOLDCO LLC, LOS ANGELES, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:16:17:00 | Win2K-f | 174.0.20.158 (KODIAKPETROLEUM.COM): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 222 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 38 of 41 |
4180c19d91 NEW b6e91e001c NEW |
9f3f2de385 [0] d2275a6cf5[0] |
none:none none:none |
Armadillo| PolyEnE| |
none none |
trace trace |
T:16:47:00 | Win2K-f | 4.225.17.65 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, ALEXANDRIA, INDIANA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:17:03:00 | Win2K-f | 113.253.100.222 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1002 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 41 | 559acaa271 NEW |
none[none] | none:none |
none|none | none | none | |
T:17:13:00 | WinXP | 92.40.160.63 (THREE.CO.UK): MOBILE BROADBAND SERVICE, MANCHESTER, ENGLAND, UK. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:17:59:00 | Win2K-f | 70.184.102.222 (COX.NET): COX COMMUNICATIONS, PHOENIX, ARIZONA, US. (100Mbps) |
88.198.228.238:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:q.kfgrtjer.cn CA:maxdomzhit.com EU:colopin.cn CN:config1130.iwillhavesexygirls.com CN:russia.2288.org :wws.mobiec.net :xz.ub9.net CN:www.petdoso.com :in.7cy.net |
135 | pcap | raw alerts ruleset |
irc http 151 lines |
Yeah : 1.8 profile |
none | summary tarball |
18 of 41 11 of 41 8 of 41 32 of 36 26 of 41 6 of 41 35 of 36 |
717ccc949c NEW 7fdb32dec7 NEW 82769f26d2 NEW bea8cb1865 NEW dd96e88e03 NEW e5772d7d3f NEW fac78fde16 NEW |
none[none] none [none] none [none] 154de51a66[0] 6f87541765[0] none [none] 882896ab05[0] |
none:none none:none none:none ASM:Graph none:none none:none none:none |
none|none none|none none|none Armadillo| StarForce| none|none tElock| |
none none none lines=91 none none none |
none none none trace trace none trace |
T:18:05:00 | Win2K-f | 173.20.140.66 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, ALBANY, GEORGIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 39 of 41 |
5e3a9c2d9d NEW 630308d06b NEW |
dbc48b815a [0] 847d302e37[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:18:28:00 | Win2K-f | 222.154.166.230 (XTRA.CO.NZ): TELECOM XTRA, AUCKLAND, AUCKLAND, NZ. (DSL) |
n/a | :xz.ub9.net CA:goholidaytravelinsurance.com :abankingsite.com 69.64.147.243:80 |
445 | pcap | raw alerts ruleset |
http 36 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:18:56:00 | Win2K-f | 4.168.168.172 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, PASADENA, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 175 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 39 of 41 |
932dbb4b69 NEW f6e5daee26 NEW |
dd4d9c7adf [0] 413c524714[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:19:14:00 | WinXP | 66.72.70.62 (AMERITECH.NET): DIAL POOL - TNT2 BLOOMINGTON, NASHVILLE, INDIANA, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:19:33:00 | Win2K-f | 71.177.154.52 (VERIZON.NET): VERIZON INTERNET SERVICES INC, ONTARIO, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
20:23:00 | Win2K-f | 209.218.255.2 (TRANSEDGE.COM): NEW EDGE NETWORKS, CHERRY HILL, NEW JERSEY, US. (DSL) |
n/a | :google.com FR:193.104.94.11:65520 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 20 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:20:34:00 | Win2K-f | 112.206.147.96 (PLDT.NET): IPG, PH. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
20:41:00 | Win2K-f | 217.23.5.80 (WORLDSTREAM.NL): WORLDSTREAM, NL. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:21:28:00 | Win2K-f | 24.84.40.29 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, VANCOUVER, BRITISH COLUMBIA, CA. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
21:37:00 | Win2K-f | 92.242.79.11 (KIS.RU): BUSINESS COMMUNICATION AGENCY LTD, MOSCOW, MOSCOW CITY, RU. (DSL) |
88.198.228.238:65520 | US:microsoft.com CN:giopnon.cn US:msn.com EU:colopin.cn US:204.152.184.139:80 CN:218.93.205.19:80 EU:91.206.201.39:80 |
445 | pcap | raw alerts ruleset |
irc 27 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:21:48:00 | Win2K-f | 70.71.230.45 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, LANGLEY, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1012 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 41 | 39a59010ee NEW |
none[none] | none:none |
none|none | none | none | |
T:22:24:00 | Win2K-f | 112.202.163.149 (PLDT.NET): IPG, PH. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1006 lines |
Yeah : 1.3 profile |
none | summary tarball |
20 of 41 | 1866844e35 NEW |
none[none] | none:none |
none|none | none | none | |
T:23:03:00 | Win2K-f | 96.8.242.42 (GVTC.COM): GUADALUPE VALLEY TELEPHONE COOPERATIVE INC, NEW BRAUNFELS, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:23:51:00 | Win2K-f | 64.144.35.70 (MEGAPATH.NET): MEGAPATH NETWORKS INC, JERSEY CITY, NEW JERSEY, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |