Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:07:00 | WinXP | 116.126.133.94 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | DE:proxima.ircgalaxy.pl US:microsoft.com |
135 | pcap | raw alerts ruleset |
other 98 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 33 31 of 33 |
168aab35a3 NEW 667f0c59f3 NEW |
60b730b97e [0] 8fe2be2095[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=120 embedded dns lines=91 |
trace trace |
T:00:09:00 | Win2K-f | 24.227.62.42 (RR.COM): ROAD RUNNER HOLDCO LLC, ORLANDO, FLORIDA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
00:17:00 | Win2K-f | 79.101.16.158 (ITSISP.NET): ITSOLUTION NIS, CS. (DSL) |
n/a | US:microsoft.com :proxim.ircgalaxy.pl GB:212.117.177.140:80 US:67.15.94.80:80 DE:88.198.228.238:65520 |
445 | pcap | raw alerts ruleset |
http 20 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:00:21:00 | WinXP | 95.220.63.214 (-): FAIRLIE HOLDING & FINANCE LIMITED, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | ASM:Graph |
none|none | lines=61 | trace | |
00:23:00 | Win2K-f | 208.96.184.68 (HELLO.COM): LITESTREAM HOLDINGS LLC, WEST PALM BEACH, FLORIDA, US. (DSL) |
n/a | US:microsoft.com US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:00:28:00 | WinXP | 12.75.78.151 (ATT.NET): AT&T WORLDNET SERVICES, COLUMBUS, OHIO, US. (DIAL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:00:52:00 | Win2K-f | 173.17.54.208 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, SAVAGE, MINNESOTA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 40 |
474acf88e5 NEW 68f0c14692 NEW |
1f53944b24 [0] ccc1b24d53[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:00:57:00 | Win2K-f | 67.203.240.252 (CENTENNIALPR.NET): CENTENNIAL DE PUERTO RICO, SAN JUAN, PUERTO RICO, PR. (DSL) |
67.43.236.67:10324 | :xx.enterhere.biz CA:xx.nadnadzz.info EU:idfc2.info |
135 | pcap | raw alerts ruleset |
irc http 187 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 41 | a894e6640a NEW |
2a62540340 [0] | none:none |
PolyEnE| | none | trace |
T:01:04:00 | Win2K-f | 110.13.108.166 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 41 33 of 33 |
8b41cb7a41 NEW 97fef473b9 NEW |
ef18d720f3 [0] ff4e7d6992[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:01:39:00 | Win2K-f | 4.248.75.220 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, PLAINFIELD, NEW JERSEY, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 79 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:01:41:00 | WinXP | 81.198.145.8 (-): ADDRESS POOL FOR LTC-HOME CUSTOMERS, RIGA, RIGA, LV. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | aab1b56620 NEW |
3b2e1c5b9d [0] | none:none |
PolyEnE| | none | trace |
T:01:54:00 | Win2K-f | 114.75.15.75 (OPTUSNET.COM.AU): OPTUS INTERNET - RETAIL, BENDIGO, VICTORIA, AU. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 39 of 41 |
0b5bc5ef27 NEW e394ef10a4 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:02:34:00 | WinXP | 110.8.228.112 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
88.198.228.238:65520 | DE:proxima.ircgalaxy.pl US:microsoft.com |
135 | pcap | raw alerts ruleset |
irc 123 lines |
Yeah : 1.8 profile |
none | summary tarball |
31 of 33 30 of 32 |
1509c8d024 NEW f23b040440 NEW |
none[4] f23b040440[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=82 |
trace trace |
T:03:47:00 | WinXP | 219.67.173.46 (ODN.AD.JP): OPEN DATA NETWORK(JAPAN TELECOM CO. LTD.), TOKYO, TOKYO, JP. (DSL) |
88.198.228.238:65520 | :proxim.ircgalaxy.pl | 445 | pcap | raw alerts ruleset |
http irc 24 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 39 | dab4da4e21 NEW |
e63b813015 [0] | ASM:Graph |
PolyEnE| | lines=134 | trace |
T:04:11:00 | Win2K-f | 75.49.23.61 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, COLUMBUS, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:05:16:00 | Win2K-f | 76.202.6.29 (PACBELL.NET): AT&T INTERNET SERVICES, HOUSTON, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:06:34:00 | WinXP | 92.41.83.73 (THREE.CO.UK): MOBILE BROADBAND SERVICE, UK. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
35 of 35 | 9716d7995a NEW |
c3a5354b6f [0] | none:none |
PolyEnE| | none | trace |
T:06:45:00 | Win2K-f | 203.114.106.149 (-): BAMNETNARONGWITAYAKOMSCHOOL, BANGKOK, KRUNG THEP, TH. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 79 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
|
T:07:25:00 | WinXP | 202.221.174.138 (BMOBILE.NE.JP): JAPAN COMMUNICATION INC, TOKYO, TOKYO, JP. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com US:new.egg.com :wpad |
445 | pcap | raw alerts ruleset |
http http http http 42 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 40 | d68a0cb1ba NEW |
none[none] | none:none |
none|none | none | none |
T:08:13:00 | Win2K-f | 4.173.252.114 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, ROCKVILLE CENTRE, NEW YORK, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:08:50:00 | WinXP | 119.77.158.125 (UBBN.NET): UNION BROADBAND NETWORK, TAIPEI, T'AI-PEI, TW. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 97e402001a NEW |
d65c34ce27 [none] | none:none |
PolyEnE| | none | trace |
T:10:28:00 | Win2K-f | 67.150.125.42 (MDSG-PACWEST.COM): PAC-WEST MANAGED MODEM NAS POOL, LA PUENTE, CALIFORNIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 46 lines |
Yeah : 1.3 profile |
none | summary tarball |
2 of 33 | 50cf31abc4 NEW |
none[none] | none:none |
none|none | none | none | |
T:10:31:00 | WinXP | 83.132.251.70 (CPE.NETCABO.PT): TVCABO-PORTUGAL CABLE MODEM NETWORK, BRAGA, BRAGA, PT. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | a1f992a08e NEW |
75ca0b4a8f [0] | none:none |
PolyEnE| | none | trace |
T:11:58:00 | Win2K-f | 24.213.224.238 (RR.COM): ROAD RUNNER HOLDCO LLC, AMSTERDAM, NOORD-HOLLAND, NL. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
12:15:00 | Win2K-f | 79.186.236.172 (TPNET.PL): NEOSTRADA PLUS, BYDGOSZCZ, KUJAWSKO-POMORSKIE, PL. (DSL) |
88.198.228.238:65520 | US:cnn.com US:204.152.184.139:80 GB:212.117.177.140:80 |
445 | pcap | raw alerts ruleset |
irc 26 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:12:21:00 | Win2K-f | 173.170.209.186 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
92.240.234.164:3305 | JP:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 608 lines |
Yeah : 1.8 profile |
none | summary tarball |
40 of 41 | 8213be74ea NEW |
none[none] | none:none |
none|none | none | none |
T:13:13:00 | WinXP | 186.9.209.91 (IMOVIL.ENTELPCS.CL): ENTEL PCS TELECOMUNICACIONES S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:14:22:00 | Win2K-f | 203.114.106.147 (-): BAMNETNARONGWITAYAKOMSCHOOL, BANGKOK, KRUNG THEP, TH. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
14:35:00 | WinXP | 186.9.209.91 (IMOVIL.ENTELPCS.CL): ENTEL PCS TELECOMUNICACIONES S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:15:48:00 | Win2K-f | 116.127.124.71 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
88.198.228.238:65520 | DE:proxim.ircgalaxy.pl US:microsoft.com |
135 | pcap | raw alerts ruleset |
irc 143 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 41 38 of 41 |
0e927ffe94 NEW 70d9f45041 NEW |
e9e756f828 [none] b91fd75bfa[none] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:17:11:00 | Win2K-f | 96.8.147.169 (GVTC.COM): GUADALUPE VALLEY TELEPHONE COOPERATIVE INC, NEW BRAUNFELS, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 96 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 3 of 40 |
cd456ac095 NEW fcda948226 NEW |
d75caee680 [none] none [none] |
none:none none:none |
tElock| none|none |
none none |
trace none |
18:37:00 | Win2K-f | 78.251.127.147 (PROXAD.NET): PROXAD INTERNET SERVICE PROVIDER IN FRANCE, FR. (DSL) |
n/a | US:msn.com US:yahoo.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:03:00 | Win2K-f | 93.80.162.137 (CORBINA.RU): BROADBAND CUSTOMERS IN MOSCOW, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | US:microsoft.com US:204.152.184.139:80 GB:212.117.177.140:80 69.197.161.10:49058 |
445 | pcap | raw alerts ruleset |
http 9 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:19:06:00 | WinXP | 201.88.89.209 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 912a073945 NEW |
7874c7f21e [0] | none:none |
PolyEnE| | none | trace |
T:19:55:00 | Win2K-f | 208.105.225.199 (RR.COM): ROAD RUNNER HOLDCO LLC, CINCINNATI, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:28:00 | Win2K-f | 71.117.15.21 (VERIZON.NET): VERIZON INTERNET SERVICES INC, BURLINGTON, WASHINGTON, US. (DSL) |
92.240.234.164:3305 | US:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 696 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:21:02:00 | Win2K-f | 172.163.13.212 (AOL.COM): AMERICA ONLINE, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
21:31:00 | WinXP | 4.235.141.10 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, TALLAHASSEE, FLORIDA, US. (DIAL) |
88.198.228.238:65520 | DE:proxim.ircgalaxy.pl CN:www.liagand.cn DE:88.198.228.238:65520 |
445 | pcap | raw alerts ruleset |
http irc 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
7 of 41 37 of 39 |
03886941be NEW dab4da4e21 NEW |
none[none] e63b813015[0] |
none:none ASM:Graph |
none|none PolyEnE| |
none lines=134 |
none trace |
T:22:19:00 | WinXP | 113.254.184.97 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 100 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 38 of 41 |
a5ceb6c29d NEW adadfc0e1c NEW |
d64cd9d18b [0] 0f57439d82[0] |
none:none none:none |
tElock| tElock| |
none none |
trace trace |
T:23:48:00 | WinXP | 187.99.125.227 (-): . |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 74b3d149e8 NEW |
cef0fa2981 [0] | none:none |
PolyEnE| | none | trace |
T:23:57:00 | Win2K-f | 172.162.180.233 (AOL.COM): AMERICA ONLINE, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 79 lines |
Yeah : 1.3 profile |
none | summary tarball |
18 of 35 0 of 33 |
218ce30f5c NEW a08f3b74a4 NEW |
none[3] none [0] |
none:none none:none |
none|none Armadillo| |
none lines=90 |
trace trace |