Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:03:51:00 | Win2K-f | 24.76.1.26 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SELKIRK, MANITOBA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1016 lines |
Yeah : 1.3 profile |
none | summary tarball |
15 of 41 | 770a04a72c NEW |
none[3] | none:none |
none|none | none | trace | |
T:03:53:00 | Win2K-f | 60.250.246.160 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 38 35 of 38 |
38ed850a0e NEW b9297745a1 NEW |
46990f37cd [0] 4294884d84[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:05:21:00 | Win2K-f | 4.143.154.67 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, OBERLIN, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:03:00 | Win2K-f | 24.77.42.23 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 123 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 38 of 41 |
34cbe7a593 NEW 3e83a2d4d7 NEW |
d38cb78003 [0] b97fd63d29[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:07:05:00 | Win2K-f | 63.246.125.200 (ALTUSCGI.NET): PRIVATE CABLE ISP SUBSCRIBER (GEORGETOWN SC MARKET), GEORGETOWN, SOUTH CAROLINA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:08:44:00 | WinXP | 114.51.12.152 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:10:21:00 | WinXP | 112.110.7.75 (-): GPRS VAS SERVICES, DELHI, DELHI, IN. (DSL) |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | d42c1cc7c0 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=54 | trace |
T:10:45:00 | Win2K-f | 76.189.246.117 (RR.COM): ROAD RUNNER HOLDCO LLC, TWINSBURG, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:15:00 | Win2K-f | 200.111.101.36 (ENTELCHILE.NET): ENTEL CHILE S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
83.133.119.206:65520 | DE:proxim.ircgalaxy.pl CN:file0129.iwillhavesexygirls.com CN:122.224.6.48:88 |
139 | pcap | raw alerts ruleset |
irc 6 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | a140a4a475 NEW |
none[none] | none:none |
none|none | none | none |
11:28:00 | WinXP | 200.111.101.36 (ENTELCHILE.NET): ENTEL CHILE S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
83.133.119.206:65520 | CN:file0129.iwillhavesexygirls.com US:bfkq.com :jsactivity.com :img.ub8.net US:search.toptravellingtips.com US:64.120.176.66:8392 98.126.9.219:80 |
139 | pcap | raw alerts ruleset |
irc http 98 lines |
Yeah : 1.3 profile |
none | summary tarball |
18 of 41 16 of 41 10 of 41 0 of 41 10 of 40 |
1d724365c7 NEW 42fc2ea920 NEW 8b5475cafd NEW f2b5faee04 NEW f691aab72f NEW |
none[none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none |
none none none none none |
none none none none none |
T:12:14:00 | WinXP | 173.2.49.43 (OPTONLINE.NET): OPTIMUM ONLINE (CABLEVISION SYSTEMS), NORWALK, CONNECTICUT, US. (DSL) |
194.109.11.65:6556 194.109.11.65:1023 | NL:0x80.online-software.org | 135 | pcap | raw alerts ruleset |
other 267 lines |
Yeah : 1.8 profile |
none | summary tarball |
32 of 32 | 15d4d85dc0 NEW |
4c95ae4b3d [0] | ASM:Graph |
StarForce| | lines=212 embedded dns |
trace |
T:12:35:00 | Win2K-f | 96.10.90.90 (RR.COM): ROAD RUNNER HOLDCO LLC, RALEIGH, NORTH CAROLINA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 116 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 41 |
53aa804019 NEW 95ddd4a823 NEW |
29c6cdbf45 [none] 9e78315a6d[none] |
none:none none:none |
tElock| Armadillo| |
none none |
none none |
T:12:57:00 | Win2K-f | 98.141.30.67 (CAVTEL.NET): CAVALIER TELEPHONE, NORFOLK, VIRGINIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
15:32:00 | Win2K-f | 203.166.220.2 (NOVA.NET.CN): NOVA ISP SERVICE, HK. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | d60e538e72 NEW |
none[3] | none:none |
UPX| | none | trace |
T:15:38:00 | Win2K-f | 98.141.161.39 (CAVTEL.NET): CAVALIER TELEPHONE, PHILADELPHIA, PENNSYLVANIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:15:41:00 | Win2K-f | 203.166.220.2 (NOVA.NET.CN): NOVA ISP SERVICE, HK. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | d60e538e72 NEW |
none[3] | none:none |
UPX| | none | trace |
16:10:00 | Win2K-f | 201.212.25.235 (NET.AR): PRIMA S.A, SANTA FE, SANTA FE, AR. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk GB:www.vouchercodez.com :checkip.dyndns.org DE:131.220.6.26:80 GB:80.82.121.239:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:16:19:00 | Win2K-f | 201.212.25.235 (NET.AR): PRIMA S.A, SANTA FE, SANTA FE, AR. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:16:28:00 | WinXP | 70.134.224.49 (SBCGLOBAL.NET): PRIVATE CUSTOMER - SBC INTERNET SERVICES, WALLINGFORD, CONNECTICUT, US. (DSL) |
n/a | :www.google.com.au US:www.altavista.com :jbeegvia.ru DE:kavkaz.co.uk US:www.worldbank.org :yoiayoi.ru :wcqahzhzn.ru :iirpryry.ru :rihafvu.ru :ryryodokm.ru :wpad :uvjiis.ru :gwvwka.ru :jqsbnyzkp.ru :pvygdo.ru :fxkyagpnw.ru :knclvdz.ru :trsqeigw.ru :odokeqy.ru :kelmpsjp.ru :edjiesp.ru :vllcdvv.ru :nuksdln.ru :tmmeno.ru :zoxdgqx.ru :pwvbfz.ru :nuzbcp.ru :bqpuqt.ru :okskyyn.ru :pnlkria.ru :kargai.ru RU:prodexteam.net :kfwfceki.ru :nhuwxyuw.ru RU:alfabank.ru :udluzuq.ru RU:www.viruslist.com :fiazpvnne.ru :ppxuub.ru :lvwgdhwlj.ru GB:www.candidateverifier.com :crime-research.ru :raxeqajrf.ru :dhagunb.ru :zpwmktjv.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | bb7681eca8 NEW |
none[3] | none:none |
tElock| | none | trace |
T:16:39:00 | WinXP | 186.10.11.145 (IMOVIL.ENTELPCS.CL): ENTEL PCS TELECOMUNICACIONES S.A, CL. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 07191c6c59 NEW |
c92263241a [none] | none:none |
PolyEnE| | none | none |
T:16:43:00 | WinXP | 202.60.70.41 (INTERVOLVE.NET.AU): DEDICATED SERVERS, BRISBANE, QUEENSLAND, AU. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 98 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 34 of 36 |
73f1082158 NEW e4ed4df0f0 NEW |
none[0] de471fc380[0] |
none:none none:none |
Armadillo| tElock| |
lines=90 none |
trace trace |
T:17:14:00 | Win2K-f | 208.84.249.250 (INFINITECOM.NET): INFINITE COMMUNICATION LLC, PHILADELPHIA, PENNSYLVANIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 41 |
3569154ead NEW ee315d58a6 NEW |
491aa22d23 [0] none [none] |
none:none none:none |
tElock| none|none |
none none |
trace none |
T:21:05:00 | Win2K-f | 124.195.32.214 (-): PT INDOSAT TBK, JAKARTA, JAKARTA RAYA, ID. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
73f1082158 NEW 97fef473b9 NEW |
none[0] ff4e7d6992[0] |
none:none none:none |
Armadillo| tElock| |
lines=90 none |
trace trace |
T:22:09:00 | Win2K-f | 75.15.177.104 (PACBELL.NET): AT&T INTERNET SERVICES, BAKERSFIELD, CALIFORNIA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
1e12f5145a NEW f208493e65 NEW |
617af909de [0] 5100adb4f9[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:22:44:00 | Win2K-f | 218.32.97.134 (SDTV.NET.TW): SAN DA CATV CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 115 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 37 of 41 |
a205366bef NEW efaef2451a NEW |
82bbbe4789 [0] 5382f9a037[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:22:48:00 | Win2K-f | 99.148.255.34 (PACBELL.NET): AT&T INTERNET SERVICES, HOUSTON, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:22:48:00 | Win2K-f | 64.178.128.142 (-): GRANDE PRAIRIE CPE, GRANDE PRAIRIE, ALBERTA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:23:17:00 | Win2K-f | 24.77.45.54 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 123 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 38 of 41 |
34cbe7a593 NEW 3e83a2d4d7 NEW |
d38cb78003 [0] b97fd63d29[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |