Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
05:54:00 | Win2K-f | 83.97.219.160 (CM-83-97-218-10.TELECABLE.ES): TELECABLE, BARCELONA, CATALONIA, ES. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org US:www.getmyip.org EU:getmyip.co.uk GB:www.vouchercodez.com 208.78.70.70:80 US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
10:46:00 | Win2K-f | 124.10.2.66 (TFN.NET.TW): TAIWAN FIXED NETWORK CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org EU:getmyip.co.uk GB:www.vouchercodez.com US:www.getmyip.org DE:131.220.6.26:80 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
13:38:00 | Win2K-f | 212.62.108.66 (-): BROADBAND, RIYADH, AR RIYAD, SA. (DSL) |
n/a | US:msn.com US:www.ask.com :kefog.biz US:pflvrxpquqk.info :hlmtmwsh.net US:itizxd.org :avqhfs.net :cmemnkrmjl.com :uapdd.org NL:grpywhlukhg.info :cxiuliqq.net :btszcn.net :kigltsoa.net US:mfkgwessy.org US:ihrnirzm.info US:ixapsdop.info :nvexpfjej.biz :bdigzgik.net :ecjrltydf.com :lrtrfloozp.biz :pprbmdl.biz US:rkzumao.org :nwsxhafrag.net :nemgmhx.com US:urvlr.info US:ygzvadzs.org :eypkml.biz :ymifggh.biz :gqscgzwabx.biz :hawhvxwuvzn.com :gffiwgrlobz.com US:fjsgz.org US:204.152.184.139:80 GB:212.117.177.140:80 US:74.208.64.145:80 |
445 | pcap | raw alerts ruleset |
http 13 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
13:43:00 | Win2K-f | 212.15.155.179 (EUROCOM.OD.UA): EC-PPPOE-DYNAMIC, ODESSA, ODES'KA OBLAST', UA. (DSL) |
n/a | US:microsoft.com US:204.152.184.139:80 GB:212.117.177.140:80 |
445 | pcap | raw alerts ruleset |
http 19 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
15:34:00 | Win2K-f | 196.30.127.13 (TELKOMADSL.CO.ZA): AFRINIC, JOHANNESBURG, GAUTENG, ZA. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk US:www.getmyip.org :checkip.dyndns.org 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
16:25:00 | Win2K-f | 213.63.88.31 (NET.ARTELECOM.PT): JAZZTEL, LISBON, LISBOA, PT. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org EU:getmyip.co.uk 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
16:53:00 | Win2K-f | 64.79.71.28 (-): . |
n/a | US:www.maxmind.com :checkip.dyndns.org US:www.getmyip.org EU:getmyip.co.uk GB:www.vouchercodez.com DE:131.220.6.26:80 208.78.70.70:80 |
445 | pcap | raw alerts ruleset |
http 7 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
21:48:00 | Win2K-f | 212.150.16.103 (BARAK.NET.IL): NETVISION, TEL AVIV, TEL AVIV, IL. (DSL) |
n/a | US:microsoft.com US:cnn.com EE:www.starman.ee EE:www.online.if.ee FI:194.215.38.3:80 EE:195.50.195.10:443 US:204.152.184.139:80 GB:212.117.177.140:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 16 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
22:33:00 | Win2K-f | 124.81.110.34 (INDOSAT.NET.ID): INDOSATM2 DEDICATED EMERALD CUSTOMER, JAKARTA, JAKARTA RAYA, ID. (100Mbps) |
n/a | EE:www.starman.ee US:microsoft.com :google.com FI:194.215.38.3:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |