Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:54:00 | Win2K-f | 60.195.117.74 (IAPCM.AC.CN): BEIJING TELETRON TELECOM ENGINEERING CO. LTD, BEIJING, BEIJING, CN. (DSL) |
n/a | :google.com GB:www.businesstomb.com US:msn.com :jsactivity.com US:microsoft.com US:trafficconverter.biz US:cnn.com 173.45.105.218:8392 US:204.152.184.139:80 GB:212.117.177.140:80 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
10 of 40 | 2d2974d822 NEW |
none[none] | none:none |
none|none | none | none |
01:04:00 | Win2K-f | 122.122.117.197 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com :google.com US:cnn.com US:204.152.184.139:80 GB:212.117.177.140:80 |
445 | pcap | raw alerts ruleset |
other 74 lines |
Argh : 0.3 profile |
none | summary tarball |
0 of 40 | 28f87cfdaa NEW |
none[none] | none:none |
none|none | none | none |
01:21:00 | Win2K-f | 188.129.136.183 (DSL.ONLINE.GE): GOL GELINK NET, GE. (DSL) |
n/a | :google.com US:search.toptravellingtips.com US:204.152.184.139:80 US:208.43.250.167:80 GB:212.117.177.140:80 |
445 | pcap | raw alerts ruleset |
http 19 lines |
Argh : 0.3 profile |
none | summary tarball |
6 of 41 | d61a351c60 NEW |
none[none] | none:none |
none|none | none | none |
01:28:00 | Win2K-f | 69.232.201.147 (PACBELL.NET): AT&T INTERNET SERVICES, HAYWARD, CALIFORNIA, US. (DSL) |
n/a | US:msn.com US:trafficconverter.biz :search.creativeblackandwhitephotography.com US:204.152.184.139:80 US:208.43.250.167:80 GB:212.117.177.140:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
01:33:00 | Win2K-f | 77.40.32.27 (RELINFO.RU): OJSC VOLGATELECOM, YOSHKAR-OLA, MARIY-EL, RU. (DSL) |
n/a | US:microsoft.com :searchchocolates.com US:204.152.184.139:80 GB:212.117.177.140:80 69.197.161.10:80 |
445 | pcap | raw alerts ruleset |
http 53 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
01:39:00 | Win2K-f | 119.94.50.140 (PLDT.NET): IPG, LAS PINAS CITY, MANILA, PH. (DSL) |
n/a | US:msn.com :pictureper.com :trusearch.net :google.com US:204.152.184.139:80 GB:212.117.177.140:80 |
445 | pcap | raw alerts ruleset |
http 87 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
01:46:00 | Win2K-f | 89.186.97.102 (GLOBONET.HU): HUNGAROTEL RT. ADSL POOL IP, BUDAPEST, BUDAPEST, HU. (DSL) |
n/a | US:cnn.com US:search.thefreewebsitedirectory.co.uk US:microsoft.com FI:194.215.38.3:80 US:204.152.184.139:80 US:208.43.250.167:80 GB:212.117.177.140:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 38 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
03:20:00 | Win2K-f | 86.180.18.254 (BTCENTRALPLUS.COM): CENTRAL + MIGRATION TO 21CN, UK. (DSL) |
n/a | US:yahoo.com :www.senddebt.com US:204.152.184.139:80 GB:212.117.177.140:80 |
445 | pcap | raw alerts ruleset |
http 51 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
03:39:00 | Win2K-f | 78.106.182.85 (CORBINA.RU): BROADBAND CUSTOMERS IN MOSCOW, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | US:microsoft.com US:yahoo.com :seekstop.com US:204.152.184.139:80 GB:212.117.177.140:80 |
445 | pcap | raw alerts ruleset |
http 105 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
11:49:00 | Win2K-f | 83.69.36.74 (SCNET.CZ): LOSAN INTERNET S.R.O, PRAGUE, HLAVNI MESTO PRAHA, CZ. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | e3faefa56a NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace | |
12:58:00 | Win2K-f | 95.24.176.239 (CORBINA.RU): INVESTELEKTROSVIAZ LTD, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | US:yahoo.com US:www.w3.org US:microsoft.com US:bmofuwwmvsv.info :tgbejxrvv.com :xqgiybdhj.net :sbrbrg.biz :qtkra.com US:fkentmyz.org :jqvxrtd.com US:thlzz.org :erafvkkgdz.biz :dvfcqlc.biz NL:bxkksieg.info :nibbczepcgv.com :upoedffpg.biz :bnmwwlqp.net :wlmejfcs.biz US:svxhaiej.info :rjveb.biz :jsbhvp.net US:nfejqbv.info :whaasnli.net :fokwn.net US:dukynjb.info :oeihpjzacr.net US:qlsxwxe.org :jzlgbrxcwv.net US:vbieboam.org US:cyewem.info :nvoqdyoci.org NL:uhuzq.org :roqosneqh.net :zljmwjtwgru.net :csciuopt.com :wuemlucxjz.net :waiyjplo.com :oqreje.biz US:sdiyjiul.org :tzzgxbv.com :bkrxc.net US:fjkyzeo.org US:remlxtc.info :google.com :vjimnpj.net :afmqrfhf.biz :hozdsxn.com US:tsnzkll.org :gfhpv.net :izwiucfpjc.biz US:rcdul.info :xulzno.com US:pecpkvj.info :inofktvt.com GB:www.businesstomb.com :ogilk.net :yxsngjhijd.biz US:bdtefftii.org :pzqsfecxyo.biz NL:trqxhmu.org US:toywc.com US:jgdmuvnd.org :pdveensghi.com US:mzwhwtfi.info US:hwnfbbf.info GB:212.117.177.140:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
17:19:00 | Win2K-f | 60.175.222.100 (CNDATA.COM): CHINANET ANHUI PROVINCE NETWORK, HEFEI, ANHUI, CN. (DSL) |
n/a | US:microsoft.com US:204.152.184.139:80 GB:212.117.177.140:80 |
445 | pcap | raw alerts ruleset |
http 23 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:56:00 | Win2K-f | 122.160.88.122 (122.AIRTELBROADBAND.IN): ABTS-DSL-DEL, GURGAON, HARYANA, IN. (DSL) |
n/a | US:yahoo.com :google.com US:cnn.com US:204.152.184.139:80 GB:212.117.177.140:80 |
445 | pcap | raw alerts ruleset |
http 19 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:15:00 | Win2K-f | 59.114.248.22 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com US:204.152.184.139:80 69.197.161.10:17823 |
445 | pcap | raw alerts ruleset |
http http 12 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:21:00 | Win2K-f | 60.249.198.214 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:yahoo.com :google.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:28:00 | Win2K-f | 198.108.81.32 (ADRIAN.EDU): ADRIAN COLLEGE, ADRIAN, MICHIGAN, US. (100Mbps) |
n/a | US:yahoo.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:34:00 | Win2K-f | 59.120.218.178 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:cnn.com US:microsoft.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 19 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:42:00 | Win2K-f | 121.120.149.241 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | US:msn.com :google.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:54:00 | Win2K-f | 60.50.119.157 (TM.NET.MY): TELEKOM MALAYSIA BERHAD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | US:cnn.com US:yahoo.com US:msn.com US:microsoft.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
21:04:00 | Win2K-f | 59.125.236.48 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | :google.com US:cnn.com :commerceclick.co.uk US:microsoft.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 20 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
21:14:00 | Win2K-f | 210.98.247.100 (KRLINE.NET): KRNIC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:microsoft.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |