Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:11:00 | Win2K-f | 173.27.245.182 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, STREAMWOOD, ILLINOIS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 109 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 40 |
474acf88e5 NEW 68f0c14692 NEW |
1f53944b24 [0] ccc1b24d53[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
|
T:00:44:00 | Win2K-f | 172.130.137.202 (AOL.COM): AMERICA ONLINE, RESTON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 158 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:01:15:00 | Win2K-f | 70.183.2.149 (COX.NET): COX COMMUNICATIONS, FAIRFAX, VIRGINIA, US. (DSL) |
83.133.119.206:65520 | US:microsoft.com DE:proxim.ircgalaxy.pl CN:down0129.iwillhavesexygirls.com EU:pozeml.com CN:122.224.6.48:88 |
135 | pcap | raw alerts ruleset |
irc 119 lines |
Yeah : 1.8 profile |
none | summary tarball |
32 of 33 29 of 33 |
87e1117f2a NEW b4fe4581c3 NEW |
3ff643aae6 [0] 599b835896[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:02:39:00 | Win2K-f | 64.179.167.78 (IW.NET): PRAIRIEWAVE CABLE MODEM DHCP, HARRISBURG, SOUTH DAKOTA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 40 |
67f1a33096 NEW 724cf0dc37 NEW |
148e04eaab [none] 901dd267d4[none] |
none:none none:none |
Armadillo| tElock| |
none none |
none none |
T:02:53:00 | Win2K-f | 116.123.221.141 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
83.133.119.206:65520 | DE:proxim.ircgalaxy.pl US:microsoft.com CN:down0129.iwillhavesexygirls.com EU:pozeml.com CN:122.224.6.48:88 |
135 | pcap | raw alerts ruleset |
irc 138 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 40 38 of 40 |
89f410e7cc NEW 909270c172 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:03:25:00 | WinXP | 200.100.212.93 (TELESP.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, SãO PAULO, SAO PAULO, BR. (DIAL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | f2a8dafb30 NEW |
1d0f660523 [0] | none:none |
PolyEnE| | none | trace |
T:04:29:00 | WinXP | 116.126.215.24 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
83.133.119.206:65520 | DE:proxima.ircgalaxy.pl US:microsoft.com CN:stashonline.info CN:down0129.iwillhavesexygirls.com EU:pozeml.com :pozemle.cn CN:122.224.6.48:88 93.174.92.220:80 |
135 | pcap | raw alerts ruleset |
irc http 125 lines |
Yeah : 1.8 profile |
none | summary tarball |
31 of 33 11 of 41 39 of 41 5 of 41 |
168aab35a3 NEW a2ce42b73d NEW aa6d257461 NEW b6cd57d0d4 NEW |
60b730b97e [0] 7a3b0aaf43[none] 6aca567868[none] 85badb652a[none] |
ASM:Graph none:none none:none none:none |
tElock| none|none Armadillo| none|none |
lines=120 embedded dns none none none |
trace none none none |
T:04:39:00 | WinXP | 113.253.100.222 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1002 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 41 | 7552be3fb7 NEW |
none[3] | none:none |
none|none | none | trace | |
T:05:09:00 | Win2K-f | 113.254.195.141 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 38 | 92e29a98bd NEW |
none[none] | none:none |
none|none | none | none | |
T:06:35:00 | WinXP | 95.236.34.197 (BUSINESS.TELECOMITALIA.IT): TELECOM ITALIA WIRELINE SERVICES, ROME, LAZIO, IT. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | ASM:Graph |
none|none | lines=61 | trace | |
T:06:58:00 | WinXP | 4.162.171.72 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, MILLINGTON, TENNESSEE, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 86 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:09:28:00 | Win2K-f | 4.152.207.169 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, GREENVILLE, SOUTH CAROLINA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 146 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:09:34:00 | Win2K-f | 59.120.228.224 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 58 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 | 57ce4acac2 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:09:35:00 | WinXP | 67.242.200.16 (RR.COM): ROAD RUNNER HOLDCO LLC, SCHENECTADY, NEW YORK, US. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | aa298099d5 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:11:05:00 | WinXP | 67.244.138.242 (RR.COM): ROAD RUNNER HOLDCO LLC, ROCHESTER, NEW YORK, US. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com US:new.egg.com :wpad US:204.13.161.51:80 DE:217.11.54.126:80 |
445 | pcap | raw alerts ruleset |
http http http http 32 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:11:44:00 | Win2K-f | 174.39.182.217 (WINDSTREAM.NET): ALLTEL MIP CUSTOMERS - OMAHA, GLENROCK, WYOMING, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 41 |
53aa804019 NEW 95ddd4a823 NEW |
29c6cdbf45 [none] 9e78315a6d[none] |
none:none none:none |
tElock| Armadillo| |
none none |
none none |
T:11:55:00 | Win2K-f | 98.141.160.56 (CAVTEL.NET): CAVALIER TELEPHONE, PHILADELPHIA, PENNSYLVANIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:12:51:00 | Win2K-f | 125.4.7.171 (ZAQ.NE.JP): J:COM WEST CO. LTD, OSAKA, OSAKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=75 embedded dns |
trace trace |
T:13:22:00 | Win2K-f | 76.184.82.140 (RR.COM): ROAD RUNNER HOLDCO LLC, DALLAS, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:13:24:00 | Win2K-f | 174.3.243.139 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:04:00 | WinXP | 75.82.186.218 (RR.COM): ROAD RUNNER HOLDCO LLC, FONTANA, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:15:58:00 | Win2K-f | 70.182.243.177 (COX.NET): COX COMMUNICATIONS, HUTCHINSON, KANSAS, US. (DSL) |
218.93.201.51:65520 | US:microsoft.com DE:proxim.ircgalaxy.pl CN:av.lometr.pl CN:down0129.iwillhavesexygirls.com EU:pozeml.com :pozemle.cn CN:122.224.6.48:88 93.174.92.220:80 |
135 | pcap | raw alerts ruleset |
irc http 137 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 41 11 of 41 28 of 41 38 of 41 |
55067eaeb2 NEW a2ce42b73d NEW c125dd19c3 NEW d441b3f319 NEW |
b625785b95 [0] 7a3b0aaf43[none] deda591015[none] e33b328c50[0] |
none:none none:none none:none none:none |
PolyEnE| none|none UPX| Armadillo| |
none none none none |
trace none none trace |
T:15:59:00 | Win2K-f | 203.118.238.245 (-): GRAND TAINAN TECHNOLOGY CO.LTD, TAINAN, T'AI-WAN, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:12:00 | WinXP | 98.141.9.117 (CAVTEL.NET): CAVALIER TELEPHONE, VIRGINIA BEACH, VIRGINIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 19 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
16:39:00 | WinXP | 186.9.160.115 (IMOVIL.ENTELPCS.CL): ENTEL PCS TELECOMUNICACIONES S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:16:42:00 | Win2K-f | 72.184.206.181 (RR.COM): ROAD RUNNER HOLDCO LLC, SPRING HILL, FLORIDA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:19:34:00 | Win2K-f | 4.224.141.101 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, INDIANAPOLIS, INDIANA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:20:28:00 | Win2K-f | 121.202.50.154 (SMARTONE-VODAFONE.COM): SMARTONE MOBILE COMMUNICATIONS LTD, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 12 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:20:39:00 | Win2K-f | 67.150.85.130 (MDSG-PACWEST.COM): PAC-WEST MANAGED MODEM NAS POOL, NASHVILLE, TENNESSEE, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 177 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:42:00 | WinXP | 110.11.212.185 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 5 of 41 |
14f47ffd1e NEW 50437008d9 NEW |
90bf4b99ff [0] c1b09ac5d7[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:21:48:00 | WinXP | 4.171.6.22 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, ORLANDO, FLORIDA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 120 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:23:45:00 | Win2K-f | 173.31.81.156 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, MIDDLETOWN, NEW YORK, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 39 of 41 |
10759405e0 NEW d08e00dfaf NEW |
292d343248 [0] 854c49d8c4[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:23:56:00 | WinXP | 190.4.229.130 (E-CORPNET.ORG): TELEFONICA MOVIL DE CHILE S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | b773ceb02c NEW |
4938ec4b17 [0] | none:none |
PolyEnE| | none | trace |
23:57:00 | WinXP | 4.224.141.247 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, INDIANAPOLIS, INDIANA, US. (DIAL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a0139d7ad8 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |