Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:02:51:00 | WinXP | 206.166.195.205 (-): LIGHT HELICOPTER TURBINE, HUNTSVILLE, ALABAMA, US. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:05:00:00 | WinXP | 79.162.177.91 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
n/a | :proxim.ircgalaxy.pl RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 36 | 9bb68450cd NEW |
c2d5ac2315 [0] | ASM:Graph |
PolyEnE| | lines=73 embedded dns |
trace |
T:05:38:00 | WinXP | 208.110.61.5 (-): PRIVATE CABLE ISP SUBSCRIBER (SCHAUMBURG IL MARKET), JONESBORO, GEORGIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 71 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 33 | 73ce2b74da NEW |
none[0] | ASM:Graph |
Armadillo| | lines=81 | trace | |
T:07:29:00 | Win2K-f | 218.32.98.75 (SDTV.NET.TW): SAN DA CATV CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 179 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 37 of 41 |
a205366bef NEW efaef2451a NEW |
82bbbe4789 [0] 5382f9a037[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:08:10:00 | Win2K-f | 208.98.187.112 (DIRECTCOM.COM): DIRECT COMMUNICATIONS CABLE LLC, NEW YORK, NEW YORK, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 41 |
25a809fe89 NEW c28562f4f0 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:08:26:00 | WinXP | 218.210.68.92 (SPARQNET.NET): THEFAREASTERNGROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:08:47:00 | WinXP | 87.173.112.1 (T-DIALIN.NET): DEUTSCHE TELEKOM AG, BERLIN, BERLIN, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
09:13:00 | Win2K-f | 93.181.6.27 (TRIPLEPLUGANDPLAY.COM): MR.NET SERVICES GMBH & CO. KG, DE. (DSL) |
88.198.228.238:65520 | US:yahoo.com US:microsoft.com US:trafficconverter.biz :proxim.ircgalaxy.pl CN:ad.lometr.pl GB:www.businesstomb.com :commerceclick.co.uk US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
irc http http 31 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 41 | 43763172ed NEW |
none[none] | none:none |
none|none | none | none |
T:09:15:00 | Win2K-f | 61.215.151.76 (CABLENET.NE.JP): CABLENET SAITAMA CO. LTD, JP. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 65 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 | 57ce4acac2 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
09:19:00 | Win2K-f | 89.179.90.94 (CORBINA.NET): INVESTELEKTROSVIAZ LTD, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | US:cnn.com US:msn.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http irc 32 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
09:25:00 | Win2K-f | 84.3.198.34 (T-ONLINE.HU): HUNGARIAN TELECOM, BUDAPEST, BUDAPEST, HU. (DSL) |
n/a | US:microsoft.com US:msn.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http irc 32 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
09:31:00 | Win2K-f | 86.142.135.23 (BTCENTRALPLUS.COM): BT BROADBAND, EDINBURGH, SCOTLAND, UK. (DSL) |
n/a | US:yahoo.com US:microsoft.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http irc 31 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
09:38:00 | Win2K-f | 58.0.123.208 (INFOWEB.NE.JP): INFOWEB(FUJITSU LTD.), TOKYO, TOKYO, JP. (DIAL) |
n/a | US:cnn.com US:msn.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http irc 33 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
09:44:00 | Win2K-f | 212.34.114.177 (VSI.RU): JSC CENTERTELECOM, RU. (DSL) |
n/a | :google.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http irc 32 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
09:50:00 | Win2K-f | 82.144.178.192 (GLOBONET.HU): BROADBAND BRAS POOL, BUDAPEST, BUDAPEST, HU. (DSL) |
n/a | US:yahoo.com US:msn.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http irc 32 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
09:56:00 | Win2K-f | 91.124.197.97 (UKRTEL.NET): UKRTELECOM IP ACCESS NETWORK, KIEV, KYYIV, UA. (DSL) |
n/a | US:msn.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http irc http 32 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
10:03:00 | Win2K-f | 208.98.57.66 (SHARKTECH.NET): SHARKTECH INTERNET SERVICES, MISSOULA, MONTANA, US. (DSL) |
n/a | :google.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http irc 32 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
10:09:00 | Win2K-f | 217.202.49.116 (-): TELECOM ITALIA MOBILE, ROME, LAZIO, IT. (DSL) |
n/a | US:cnn.com US:microsoft.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http irc 31 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:10:20:00 | Win2K-f | 66.60.214.238 (NEWULMTEL.NET): NU-TELECOM, REDWOOD FALLS, MINNESOTA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 39 of 40 |
ae8f8ab2df NEW fd9f2ad922 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:13:49:00 | WinXP | 70.182.68.25 (COX.NET): COX COMMUNICATIONS, NORMAN, OKLAHOMA, US. (DSL) |
88.198.228.238:65520 | :proxim.ircgalaxy.pl US:microsoft.com |
135 | pcap | raw alerts ruleset |
irc 139 lines |
Yeah : 1.8 profile |
none | summary tarball |
32 of 33 29 of 33 |
87e1117f2a NEW b4fe4581c3 NEW |
3ff643aae6 [0] 599b835896[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:14:01:00 | Win2K-f | 4.240.12.24 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, PHOENIX, ARIZONA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 11 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:14:08:00 | WinXP | 95.239.164.61 (BUSINESS.TELECOMITALIA.IT): TELECOM ITALIA WIRELINE SERVICES, ROME, LAZIO, IT. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | ASM:Graph |
none|none | lines=61 | trace | |
T:15:22:00 | Win2K-f | 123.111.153.100 (-): HANARO TELECOM, JEJU, CHEJU-DO, KR. (DSL) |
88.198.228.238:65520 | US:microsoft.com :proxim.ircgalaxy.pl |
135 | pcap | raw alerts ruleset |
irc 117 lines |
Yeah : 1.8 profile |
none | summary tarball |
29 of 32 28 of 32 |
8a75955033 NEW 9276c8b36b NEW |
2bf3e548b9 [0] none [0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=126 embedded dns lines=81 |
trace trace |
15:47:00 | Win2K-f | 173.45.68.69 (XLHOST.COM): XLHOST.COM INC, COLUMBUS, OHIO, US. (100Mbps) |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:16:37:00 | WinXP | 67.10.69.136 (RR.COM): ROAD RUNNER HOLDCO LLC, MCALLEN, TEXAS, US. (DSL) |
194.109.11.65:6556 194.109.11.65:1023 | NL:0x80.online-software.org | 135 | pcap | raw alerts ruleset |
other 187 lines |
Yeah : 1.8 profile |
none | summary tarball |
32 of 32 | 15d4d85dc0 NEW |
4c95ae4b3d [0] | ASM:Graph |
StarForce| | lines=212 embedded dns |
trace |
16:59:00 | Win2K-f | 190.50.92.75 (COM.AR): TELEFONICA DE ARGENTINA, MAR DEL PLATA, BUENOS AIRES, AR. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk GB:www.vouchercodez.com US:www.getmyip.org :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 8 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
17:01:00 | Win2K-f | 109.115.15.52 (-): IP ADDRESSES ASSIGNED TO VF-IT MOBILE USERS, IVREA, PIEMONTE, IT. (DSL) |
n/a | US:msn.com DE:proxim.ircgalaxy.pl DE:131.220.6.26:80 GB:212.117.177.140:80 69.197.161.10:80 DE:88.198.228.238:65520 |
445 | pcap | raw alerts ruleset |
http 18 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
17:33:00 | Win2K-f | 201.29.111.81 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | :google.com :www.google.com US:trafficconverter.biz :tqxgnuxq.com US:rmsuqk.org :osdyhxfddn.net US:gurnlklzay.info :qlcvczvs.biz :cdsxoz.biz :eugyr.biz :ooyjzs.net US:hrkistwdnq.org :nvtivvbx.com US:204.152.184.139:80 GB:212.117.177.140:80 US:74.208.64.145:80 DE:88.198.228.238:65520 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:17:44:00 | WinXP | 186.9.184.87 (IMOVIL.ENTELPCS.CL): ENTEL PCS TELECOMUNICACIONES S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace | |
18:03:00 | Win2K-f | 79.149.13.23 (RIMA-TDE.NET): TELEFONICA MOVILES ESPANA (NCC#2008113582), MADRID, MADRID, ES. (DSL) |
n/a | US:msn.com :google.com EU:getmyip.co.uk GB:www.vouchercodez.com :checkip.dyndns.org US:www.getmyip.org 208.78.70.70:80 GB:212.117.177.140:80 69.197.161.10:80 US:75.126.138.202:80 DE:88.198.228.238:65520 |
445 | pcap | raw alerts ruleset |
http 18 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:18:04:00 | Win2K-f | 65.171.202.46 (EVERTEK.NET): FIBERCOMM L.C, DUBLIN, GEORGIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 226 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 | e6da4ba911 NEW |
none[none] | none:none |
none|none | none | none | |
18:16:00 | Win2K-f | 84.237.130.60 (-): ADDRESS POOL FOR LTC-HOME CUSTOMERS, RIGA, RIGA, LV. (DSL) |
n/a | US:microsoft.com US:www.getmyip.org :checkip.dyndns.org US:msn.com 208.78.70.70:80 GB:212.117.177.140:80 |
445 | pcap | raw alerts ruleset |
http 20 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:30:00 | Win2K-f | 118.195.145.47 (-): HAINAN NETWORK, SHANWEI, FUJIAN, CN. (DSL) |
n/a | US:www.getmyip.org EU:getmyip.co.uk GB:www.vouchercodez.com US:msn.com GB:212.117.177.140:80 DE:88.198.228.238:65520 |
445 | pcap | raw alerts ruleset |
http 20 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:44:00 | Win2K-f | 125.114.77.177 (163DATA.COM.CN): CHINANET-ZJ NINGBO NODE NETWORK, NINGBO, ZHEJIANG, CN. (DSL) |
n/a | US:msn.com :checkip.dyndns.org US:www.getmyip.org 208.78.70.70:80 GB:212.117.177.140:80 DE:88.198.228.238:65520 |
445 | pcap | raw alerts ruleset |
http 19 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:57:00 | Win2K-f | 201.69.213.145 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | :google.com US:www.getmyip.org EU:getmyip.co.uk GB:www.vouchercodez.com GB:212.117.177.140:80 DE:88.198.228.238:65520 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:18:58:00 | Win2K-f | 113.253.100.200 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1002 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 41 | 559acaa271 NEW |
none[none] | none:none |
none|none | none | none | |
T:19:59:00 | WinXP | 200.195.81.146 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:20:05:00 | WinXP | 207.5.121.144 (MICROLNK.COM): MICROLNK LLC, OMAHA, NEBRASKA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:19:00 | WinXP | 96.49.133.158 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:48:00 | Win2K-f | 96.8.226.199 (GVTC.COM): GUADALUPE VALLEY TELEPHONE COOPERATIVE INC, NEW BRAUNFELS, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 40 |
9bdd2c95b1 NEW cd456ac095 NEW |
d1bbd693ba [none] d75caee680[none] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:21:30:00 | WinXP | 122.49.244.141 (CCNET-AI.NE.JP): COMMUNITY NETWORK CENTER INC, TOYOKAWA, AICHI, JP. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 697 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | 3e0de43e46 NEW |
none[none] | none:none |
none|none | none | none | |
T:21:32:00 | WinXP | 125.4.23.53 (ZAQ.NE.JP): J:COM WEST CO. LTD, OSAKA, OSAKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=75 embedded dns |
trace trace |
23:14:00 | Win2K-f | 189.83.16.18 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, BELO HORIZONTE, MINAS GERAIS, BR. (DSL) |
n/a | :google.com :checkip.dyndns.org US:www.getmyip.org EU:getmyip.co.uk 208.78.70.70:80 GB:212.117.177.140:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 20 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:23:37:00 | Win2K-f | 98.141.160.56 (CAVTEL.NET): CAVALIER TELEPHONE, PHILADELPHIA, PENNSYLVANIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |