Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:10:00 | Win2K-f | 190.3.87.236 (TECHTELNET.NET): TECHTEL LMDS COMUNICACIONES INTERACTIVAS S.A, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk US:www.getmyip.org :checkip.dyndns.org DE:131.220.6.26:80 208.78.70.70:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:00:11:00 | WinXP | 70.241.194.128 (SWBELL.NET): AT&T INTERNET SERVICES, ST. LOUIS, MISSOURI, US. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com SE:kavkazcenter.com SE:kavkazcenter.net FI:kavkazchat.com :chechenpress.info GB:chechenpress.co.uk :shaheeds.org :daymohk.info :chripress.org :marsho.dk GB:www.chechenpress.co.uk 174.46.45.151:80 GB:217.194.210.198:80 EU:78.47.200.154:80 FI:80.81.183.162:80 |
445 | pcap | raw alerts ruleset |
http http 33 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | ab5e47bf8d NEW |
67fb5eff61 [0] | none:none |
ASPack| | none | trace |
T:02:01:00 | WinXP | 121.84.173.30 (EONET.NE.JP): K-OPTICOM CORPORATION, OSAKA, OSAKA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 36 | 1bfebad740 NEW |
none[none] | none:none |
none|none | none | none | |
T:03:24:00 | WinXP | 117.104.53.218 (T-COM.NE.JP): TOKAI CORPORATION, SHIZUOKA, SHIZUOKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 41 |
6b315f5dbc NEW 7938865f8c NEW |
7604b94520 [0] a9b9e4904b[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:05:21:00 | Win2K-f | 112.200.57.9 (PLDT.NET): IPG, LAS PINAS CITY, MANILA, PH. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1002 lines |
Yeah : 1.3 profile |
none | summary tarball |
21 of 41 | 672d73ec08 NEW |
none[3] | none:none |
none|none | none | trace | |
T:05:38:00 | WinXP | 174.39.174.109 (WINDSTREAM.NET): ALLTEL MIP CUSTOMERS - OMAHA, NORTH PLATTE, NEBRASKA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 115 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 41 |
53aa804019 NEW 95ddd4a823 NEW |
29c6cdbf45 [none] 9e78315a6d[none] |
none:none none:none |
tElock| Armadillo| |
none none |
none none |
T:06:44:00 | Win2K-f | 98.141.163.84 (CAVTEL.NET): CAVALIER TELEPHONE, PHILADELPHIA, PENNSYLVANIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:07:40:00 | Win2K-f | 173.200.73.19 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:09:05:00 | Win2K-f | 75.82.186.218 (RR.COM): ROAD RUNNER HOLDCO LLC, FONTANA, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:10:06:00 | WinXP | 24.78.179.0 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 123 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 38 of 41 |
34cbe7a593 NEW 3e83a2d4d7 NEW |
d38cb78003 [0] b97fd63d29[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:11:03:00 | Win2K-f | 75.60.205.140 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, COLUMBUS, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:33:00 | WinXP | 193.250.134.114 (-): NSDIJ116 DIJON, PARIS, ILE-DE-FRANCE, FR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
13:39:00 | Win2K-f | 173.45.113.190 (XLHOST.COM): ENET INC, COLUMBUS, OHIO, US. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org EU:getmyip.co.uk :checkip.dyndns.org DE:131.220.6.26:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:14:02:00 | WinXP | 124.195.32.214 (-): PT INDOSAT TBK, JAKARTA, JAKARTA RAYA, ID. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
73f1082158 NEW 97fef473b9 NEW |
none[0] ff4e7d6992[0] |
none:none none:none |
Armadillo| tElock| |
lines=90 none |
trace trace |
T:14:45:00 | Win2K-f | 207.5.121.144 (MICROLNK.COM): MICROLNK LLC, OMAHA, NEBRASKA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:15:06:00 | Win2K-f | 70.232.66.161 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, LITTLE ROCK, ARKANSAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:04:00 | Win2K-f | 66.80.80.135 (MEGAPATH.NET): MEGAPATH NETWORKS INC, SAN DIEGO, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 39 of 41 |
5403724951 NEW 6494cbd582 NEW |
44ee5f83ba [0] adcb56d0cb[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
16:08:00 | Win2K-f | 77.56.84.240 (HISPEED.CH): CH-CABLECOM, ZURICH, ZURICH, CH. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org EU:getmyip.co.uk GB:www.vouchercodez.com :checkip.dyndns.org 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 GB:80.82.121.239:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:16:11:00 | Win2K-f | 98.141.30.67 (CAVTEL.NET): CAVALIER TELEPHONE, NORFOLK, VIRGINIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:16:19:00 | Win2K-f | 77.56.84.240 (HISPEED.CH): CH-CABLECOM, ZURICH, ZURICH, CH. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org US:www.getmyip.org EU:getmyip.co.uk DE:131.220.6.26:80 208.78.70.70:80 US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:16:34:00 | Win2K-f | 4.226.9.99 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DESOTO, TEXAS, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:46:00 | Win2K-f | 220.216.53.171 (THN.NE.JP): TOKAI CORPORATION, SHIZUOKA, SHIZUOKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 40 of 41 |
6a6aaa5b73 NEW 8bde6dd126 NEW |
63889c9976 [0] 885c68f500[0] |
none:none none:none |
tElock| tElock| |
none none |
trace trace |
T:16:51:00 | Win2K-f | 74.214.47.11 (METROCAST.NET): METROCAST COMMUNICATIONS, KING GEORGE, VIRGINIA, US. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 100 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 | e30fb27bda NEW |
90ee26f451 [0] | ASM:Graph |
MEW| | lines=185 embedded dns |
trace | |
T:17:52:00 | Win2K-f | 4.177.18.156 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, SAN DIEGO, CALIFORNIA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 36 of 40 |
47d3548e36 NEW d8722af110 NEW |
ab13346633 [0] ab30a55931[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:21:30:00 | Win2K-f | 70.184.2.53 (COX.NET): COX COMMUNICATIONS, WARNER ROBINS, GEORGIA, US. (DSL) |
83.133.119.206:65520 | US:microsoft.com DE:proxim.ircgalaxy.pl CN:down0129.iwillhavesexygirls.com CN:122.224.6.48:88 DE:83.133.119.206:65520 |
135 | pcap | raw alerts ruleset |
irc 131 lines |
Yeah : 1.8 profile |
none | summary tarball |
32 of 33 29 of 33 |
87e1117f2a NEW b4fe4581c3 NEW |
3ff643aae6 [0] 599b835896[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:21:38:00 | WinXP | 217.202.245.221 (-): TELECOM ITALIA MOBILE, ROME, LAZIO, IT. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | e15cecba87 NEW |
none[none] | none:none |
none|none | none | none |
T:22:13:00 | Win2K-f | 122.146.252.192 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
22:17:00 | WinXP | 114.137.241.37 (HINET.NET): MOBILE BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | aed8dc8962 NEW |
none[none] | none:none |
none|none | none | none |
T:22:38:00 | Win2K-f | 72.184.202.251 (RR.COM): ROAD RUNNER HOLDCO LLC, CLEARWATER, FLORIDA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 39 |
4ec3f2d8bc NEW 7e9a831b58 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:23:22:00 | Win2K-f | 70.184.248.143 (COX.NET): COX COMMUNICATIONS, TULSA, OKLAHOMA, US. (DSL) |
218.93.201.51:65520 83.133.119.206:65520 | US:microsoft.com DE:proxim.ircgalaxy.pl CN:down0129.iwillhavesexygirls.com CN:122.224.6.48:88 |
135 | pcap | raw alerts ruleset |
irc 130 lines |
Yeah : 1.8 profile |
none | summary tarball |
32 of 33 29 of 33 |
87e1117f2a NEW b4fe4581c3 NEW |
3ff643aae6 [0] 599b835896[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:23:23:00 | WinXP | 4.158.204.12 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DELANO, MINNESOTA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:23:28:00 | Win2K-f | 220.216.53.171 (THN.NE.JP): TOKAI CORPORATION, SHIZUOKA, SHIZUOKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 40 of 41 |
6a6aaa5b73 NEW 8bde6dd126 NEW |
63889c9976 [0] 885c68f500[0] |
none:none none:none |
tElock| tElock| |
none none |
trace trace |
T:23:50:00 | Win2K-f | 99.164.23.178 (SBCGLOBAL.NET): RANI PAL LLC, PLANO, TEXAS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 402 lines |
Yeah : 1.3 profile |
none | summary tarball |
11 of 36 | c4c5a56ffe NEW |
8bef2f9170 [0] | none:none |
StarForce| | none | trace | |
T:23:59:00 | Win2K-f | 202.60.70.41 (INTERVOLVE.NET.AU): DEDICATED SERVERS, BRISBANE, QUEENSLAND, AU. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 98 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 34 of 36 |
73f1082158 NEW e4ed4df0f0 NEW |
none[0] de471fc380[0] |
none:none none:none |
Armadillo| tElock| |
lines=90 none |
trace trace |