Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:38:00 | Win2K-f | 59.125.210.63 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (100Mbps) |
n/a | US:www.maxmind.com :checkip.dyndns.org US:www.getmyip.org EU:getmyip.co.uk 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:01:03:00 | Win2K-f | 202.150.119.64 (-): KOL-DIAL, AUCKLAND, AUCKLAND, NZ. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 60 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:01:20:00 | WinXP | 95.220.8.118 (-): FAIRLIE HOLDING & FINANCE LIMITED, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | ASM:Graph |
none|none | lines=61 | trace | |
T:02:05:00 | Win2K-f | 113.255.113.22 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 41 33 of 33 |
1cc5b253e9 NEW 53bfe15e91 NEW |
a87d3afae8 [0] 1473091351[0] |
none:none ASM:Graph |
tElock| tElock| |
none lines=75 embedded dns |
trace trace |
T:03:44:00 | Win2K-f | 113.252.100.140 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 38 of 41 |
a5ceb6c29d NEW adadfc0e1c NEW |
d64cd9d18b [0] 0f57439d82[0] |
none:none ASM:Graph |
tElock| tElock| |
none lines=64 embedded dns |
trace trace |
T:03:59:00 | Win2K-f | 207.5.194.120 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 60 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
04:13:00 | WinXP | 93.156.59.3 (CM-93-156-59-10.TELECABLE.ES): TELECABLE, OVIEDO, ASTURIAS, ES. (DSL) |
n/a | :moscow-advokat.ru :lia.zanet.net :washington.dc.us.undernet.org SE:viking.dal.net SE:qis.md.us.dal.net SE:coins.dal.net :caen.fr.eu.undernet.org SE:ozbytes.dal.net :brussels.be.eu.undernet.org :flanders.be.eu.undernet.org :lulea.se.eu.undernet.org |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:09:25:00 | WinXP | 70.182.94.31 (COX.NET): COX COMMUNICATIONS, OKLAHOMA CITY, OKLAHOMA, US. (DSL) |
88.198.228.238:65520 | DE:proxim.ircgalaxy.pl US:microsoft.com CN:av.lometr.pl CN:www.liagand.cn EU:pozeml.com :pozemle.cn EU:streq.cn :horobl.cn CN:down1130.iwillhavesexygirls.com CN:210.51.36.215:88 DE:88.198.228.238:65520 |
135 | pcap | raw alerts ruleset |
irc http 137 lines |
Yeah : 1.8 profile |
none | summary tarball |
23 of 41 4 of 41 11 of 41 32 of 36 35 of 36 |
357486dae7 NEW 8e7cffa818 NEW a2ce42b73d NEW bea8cb1865 NEW fac78fde16 NEW |
none[none] none [none] none [none] 154de51a66[0] 882896ab05[0] |
none:none none:none none:none ASM:Graph none:none |
StarForce| none|none none|none Armadillo| tElock| |
none none none lines=91 none |
trace none none trace trace |
T:10:17:00 | WinXP | 151.81.59.23 (51-151.NET24.IT): IUNET-BNET, MILANO, LOMBARDIA, IT. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | c44169f401 NEW |
64d22c5c02 [0] | none:none |
PolyEnE| | none | trace |
T:10:31:00 | WinXP | 87.173.75.53 (T-DIALIN.NET): DEUTSCHE TELEKOM AG, MAGDEBURG, SACHSEN-ANHALT, DE. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:10:36:00 | WinXP | 24.79.84.103 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
n/a | FR:ilo.brenz.pl US:gg.arrancar.org :monstersoftware.info CN:av.lometr.pl CN:www.liagand.cn CN:down1130.iwillhavesexygirls.com CN:210.51.36.215:88 US:72.20.40.25:555 |
135 | pcap | raw alerts ruleset |
http 421 lines |
Yeah : 1.3 profile |
none | summary tarball |
23 of 41 32 of 41 3 of 41 |
357486dae7 NEW 4a637e05be NEW 5fd50c7369 NEW |
none[none] none [none] none [none] |
none:none none:none none:none |
StarForce| none|none none|none |
none none none |
trace none none |
T:11:29:00 | Win2K-f | 66.63.77.1 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
11:47:00 | WinXP | 151.81.59.23 (51-151.NET24.IT): IUNET-BNET, MILANO, LOMBARDIA, IT. (DSL) |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | c44169f401 NEW |
64d22c5c02 [0] | none:none |
PolyEnE| | none | trace |
T:11:52:00 | WinXP | 217.203.182.38 (-): TELECOM ITALIA MOBILE, ROME, LAZIO, IT. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | ef979a8dbc NEW |
none[none] | none:none |
none|none | none | none |
T:12:52:00 | Win2K-f | 61.106.29.130 (KRLINE.NET): KRNIC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
88.198.228.238:65520 | DE:proxim.ircgalaxy.pl CN:av.lometr.pl CN:www.liagand.cn CN:down1130.iwillhavesexygirls.com CN:210.51.36.215:88 |
139 | pcap | raw alerts ruleset |
irc http 11 lines |
Yeah : 1.3 profile |
none | summary tarball |
23 of 41 39 of 41 |
357486dae7 NEW b9ecc08ab2 NEW |
none[none] none [none] |
none:none none:none |
StarForce| none|none |
none none |
trace none |
T:13:11:00 | WinXP | 204.181.140.244 (SPRINTLINK.NET): SPRINT, BETHEL, CONNECTICUT, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 38 of 41 |
4d4b7efca2 NEW 539d61fc06 NEW |
ec83dac222 [0] c3af874c93[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:13:57:00 | WinXP | 4.90.23.247 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, ATHENS, TEXAS, US. (DIAL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | c1868a3b2b NEW |
05bc798a8d [none] | none:none |
PolyEnE| | none | trace |
T:17:07:00 | Win2K-f | 75.49.7.7 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, COLUMBUS, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:01:00 | Win2K-f | 202.137.187.238 (CCNET-AI.NE.JP): COMMUNITY NETWORK CENTER INC, TOYOKAWA, AICHI, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 80 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=75 embedded dns |
trace trace |
T:19:50:00 | Win2K-f | 208.125.40.154 (RR.COM): ROAD RUNNER HOLDCO LLC, ROCHESTER, NEW YORK, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:06:00 | Win2K-f | 204.181.140.247 (SPRINTLINK.NET): SPRINT, BETHEL, CONNECTICUT, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 38 of 41 |
4d4b7efca2 NEW 539d61fc06 NEW |
ec83dac222 [0] c3af874c93[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:20:25:00 | Win2K-f | 174.5.163.127 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 114 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 41 |
15b89b9fda NEW 631bd3e5f4 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:21:10:00 | Win2K-f | 99.164.23.178 (SBCGLOBAL.NET): RANI PAL LLC, PLANO, TEXAS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 402 lines |
Yeah : 1.3 profile |
none | summary tarball |
11 of 36 | c4c5a56ffe NEW |
8bef2f9170 [0] | none:none |
StarForce| | none | trace | |
T:21:22:00 | Win2K-f | 4.226.39.61 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, CHESTER, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 161 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:07:00 | WinXP | 208.125.168.68 (RR.COM): ROAD RUNNER HOLDCO LLC, CLIFTON PARK, NEW YORK, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:23:13:00 | Win2K-f | 113.255.114.192 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 40 33 of 33 |
27b17a2724 NEW 53bfe15e91 NEW |
a1d5ac965b [0] 1473091351[0] |
none:none ASM:Graph |
tElock| tElock| |
none lines=75 embedded dns |
trace trace |