Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:34:00 | Win2K-f | 88.48.103.219 (BUSINESS.TELECOMITALIA.IT): COMUNE DELLA SPEZIA, ROME, LAZIO, IT. (100Mbps) |
92.240.234.164:3305 | JP:cx10man.weedns.com KR:fx010413.whyI.org :gynoman.weedns.com FI:g.0x20.biz 67.228.26.154:3305 PL:83.2.139.1:3305 |
135 | pcap | raw alerts ruleset |
shell ftp irc 23 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:00:56:00 | Win2K-f | 114.150.170.126 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. (DSL) |
92.240.234.164:3305 | KR:cx10man.weedns.com :fx010413.whyI.org PL:gynoman.weedns.com JP:g.0x20.biz 67.228.26.154:3305 PL:83.2.139.1:3305 |
135 | pcap | raw alerts ruleset |
shell ftp irc 24 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 41 | 3e30dc90de NEW |
d5e7d16040 [0] | none:none |
StarForce| | none | trace |
T:02:17:00 | Win2K-f | 74.248.103.198 (BELLSOUTH.NET): BELLSOUTH.NET INC, BATON ROUGE, LOUISIANA, US. (DSL) |
67.228.26.154:3305 | :cx10man.weedns.com PL:fx010413.whyI.org PL:83.2.139.1:3305 |
135 | pcap | raw alerts ruleset |
shell ftp irc 26 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:03:30:00 | Win2K-f | 94.197.87.195 (THREE.CO.UK): MOBILE BROADBAND SERVICE, UK. (DSL) |
n/a | PL:cx10man.weedns.com :fx010413.whyI.org DE:gynoman.weedns.com 67.228.26.154:3305 PL:83.2.139.1:3305 |
135 | pcap | raw alerts ruleset |
shell ftp irc 23 lines |
Yeah : 1.3 profile |
none | summary tarball |
22 of 40 | 59617f9be3 NEW |
35722f3350 [0] | none:none |
StarForce| | none | trace |
T:07:09:00 | Win2K-f | 212.106.48.230 (KALUGA.RU): JSC CENTERTELECOM KALUGA BRANCH, MOSCOW, MOSCOW CITY, RU. (DIAL) |
n/a | JP:cx10man.weedns.com JP:fx010413.whyI.org :gynoman.weedns.com TH:c010x1.co.cc :commgr.co.cc US:g.0x20.biz PL:telephone.dd.blueline.be AR:phonewire.dd.blueline.be :phonelogin.dd.blueline.be JP:ufospace.etowns.net 67.228.26.154:3305 PL:83.2.139.1:3305 RU:89.208.33.88:3305 92.240.234.164:3305 |
135 | pcap | raw alerts ruleset |
shell ftp irc 22 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 | 70ec5c4b3f NEW |
f697adabdd [0] | none:none |
StarForce| | none | trace |
07:33:00 | WinXP | 114.51.155.141 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:08:33:00 | Win2K-f | 175.112.65.172 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 41 33 of 33 |
8b41cb7a41 NEW 97fef473b9 NEW |
ef18d720f3 [0] ff4e7d6992[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:10:34:00 | Win2K-f | 216.66.143.21 (LOOK.CA): LOOK COMMUNICATIONS INC, MILTON, ONTARIO, CA. (DSL) |
67.228.26.154:3305 | KR:cx10man.weedns.com KR:fx010413.whyI.org PL:83.2.139.1:3305 |
135 | pcap | raw alerts ruleset |
shell ftp irc 26 lines |
Yeah : 1.8 profile |
none | summary tarball |
41 of 41 | 88c7adbc7c NEW |
none[none] | none:none |
none|none | none | none |
T:11:08:00 | WinXP | 70.61.157.51 (RR.COM): ROAD RUNNER HOLDCO LLC, CINCINNATI, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:16:00 | Win2K-f | 216.66.138.99 (LOOK.CA): LOOK COMMUNICATIONS INC, MILTON, ONTARIO, CA. (DSL) |
83.2.139.1:3305 | :cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
shell ftp irc 23 lines |
Yeah : 1.8 profile |
none | summary tarball |
41 of 41 | 88c7adbc7c NEW |
none[none] | none:none |
none|none | none | none |
T:11:50:00 | Win2K-f | 68.143.26.108 (NUVOX.NET): NUVOX COMMUNICATIONS INC, NEW YORK, NEW YORK, US. (DSL) |
n/a | PL:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
shell ftp irc 23 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | ae6c45c2b3 NEW |
e196ebb167 [0] | none:none |
StarForce| | none | trace |
12:08:00 | Win2K-f | 186.18.165.8 (186.IN-ADDR.ARPA): TELECENTRO S.A. - CLIENTES RESIDENCIALES, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk GB:www.vouchercodez.com US:www.getmyip.org :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 8 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:12:17:00 | Win2K-f | 186.18.165.8 (186.IN-ADDR.ARPA): TELECENTRO S.A. - CLIENTES RESIDENCIALES, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org DE:131.220.6.26:80 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:12:32:00 | Win2K-f | 202.107.247.8 (CNINFO.NET): CHINANET-ZJ QUZHOU NODE NETWORK, QUZHOU, ZHEJIANG, CN. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:48:00 | WinXP | 70.74.219.93 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, EDMONTON, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 11 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:12:52:00 | WinXP | 67.212.60.21 (SCCOAST.NET): HTC, NORTH MYRTLE BEACH, SOUTH CAROLINA, US. (DSL) |
n/a | JP:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
shell ftp irc 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 42 | ee49de2635 NEW |
none[none] | none:none |
none|none | none | none |
T:12:57:00 | Win2K-f | 96.8.227.19 (GVTC.COM): GUADALUPE VALLEY TELEPHONE COOPERATIVE INC, NEW BRAUNFELS, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 40 |
9bdd2c95b1 NEW cd456ac095 NEW |
d1bbd693ba [0] d75caee680[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:13:01:00 | Win2K-f | 212.106.43.133 (KALUGA.RU): JSC CENTERTELECOM KALUGA BRANCH, MOSCOW, MOSCOW CITY, RU. (DIAL) |
n/a | KR:cx10man.weedns.com :fx010413.whyI.org JP:gynoman.weedns.com AR:c010x1.co.cc RU:commgr.co.cc AR:g.0x20.biz PL:telephone.dd.blueline.be :phonewire.dd.blueline.be :phonelogin.dd.blueline.be JP:ufospace.etowns.net KR:theforums.bbsindex.com :phonewire.dnip.net :phonelogin.dnip.net :koopa.dnip.net KR:210.127.253.90:3305 JP:210.166.223.51:3305 67.228.26.154:3305 PL:83.2.139.1:3305 PL:83.2.139.1:3308 RU:89.208.33.88:3305 92.240.234.164:3305 |
135 | pcap | raw alerts ruleset |
shell ftp 23 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 | 70ec5c4b3f NEW |
f697adabdd [0] | none:none |
StarForce| | none | trace |
T:13:55:00 | WinXP | 76.180.52.184 (RR.COM): ROAD RUNNER HOLDCO LLC, BUFFALO, NEW YORK, US. (DSL) |
n/a | EU:siliconfireware.ru US:searchportal.information.com :pagead2.googlesyndication.com :googleads.g.doubleclick.net US:spi.domainsponsor.com RU:www.bbin.ru :wpad RU:195.200.213.54:80 |
445 | pcap | raw alerts ruleset |
http http http 65 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:15:11:00 | Win2K-f | 118.128.82.235 (-): LG DACOM CORPORATION, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
210.166.223.51:3305 | :cx10man.weedns.com PL:fx010413.whyI.org KR:gynoman.weedns.com :c010x1.co.cc JP:commgr.co.cc :g.0x20.biz FI:telephone.dd.blueline.be AR:phonewire.dd.blueline.be :phonelogin.dd.blueline.be JP:ufospace.etowns.net 67.228.26.154:3305 PL:83.2.139.1:3305 RU:89.208.33.88:3305 92.240.234.164:3305 |
135 | pcap | raw alerts ruleset |
shell ftp irc 23 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 40 | 70ec5c4b3f NEW |
f697adabdd [0] | none:none |
StarForce| | none | trace |
T:16:27:00 | Win2K-f | 84.177.215.94 (T-DIALIN.NET): DEUTSCHE TELEKOM AG, DE. (DIAL) |
67.228.26.154:3305 | PL:cx10man.weedns.com :fx010413.whyI.org :gynoman.weedns.com 67.228.26.154:3305 PL:83.2.139.1:3305 |
135 | pcap | raw alerts ruleset |
shell ftp irc 26 lines |
Yeah : 1.8 profile |
none | summary tarball |
31 of 41 | cc88f4f016 NEW |
3d17903825 [0] | none:none |
StarForce| | none | trace |
17:07:00 | WinXP | 201.32.137.235 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 | cdfc97be37 NEW |
48cdfeed00 [0] | none:none |
PolyEnE| | none | trace |
T:18:09:00 | Win2K-f | 70.232.68.150 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, LITTLE ROCK, ARKANSAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:25:00 | Win2K-f | 122.146.242.165 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:19:28:00 | Win2K-f | 4.90.6.88 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, MARSHALL, TEXAS, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 90 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
20:27:00 | Win2K-f | 12.71.196.46 (SPEAKEASY.NET): MICROSOFT CORPORATION, FARMERSVILLE, TEXAS, US. (100Mbps) |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org EU:getmyip.co.uk 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:20:37:00 | Win2K-f | 12.71.196.46 (SPEAKEASY.NET): MICROSOFT CORPORATION, FARMERSVILLE, TEXAS, US. (100Mbps) |
n/a | US:www.maxmind.com US:www.getmyip.org EU:getmyip.co.uk :checkip.dyndns.org DE:131.220.6.26:80 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:21:59:00 | Win2K-f | 60.249.37.247 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 38 35 of 38 |
38ed850a0e NEW b9297745a1 NEW |
46990f37cd [0] 4294884d84[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:23:13:00 | Win2K-f | 4.165.144.126 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, HOLLAND, MICHIGAN, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:23:45:00 | WinXP | 174.39.170.186 (WINDSTREAM.NET): ALLTEL MIP CUSTOMERS - OMAHA, NORTH PLATTE, NEBRASKA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 217 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 95ddd4a823 NEW |
9e78315a6d [none] | none:none |
Armadillo| | none | trace | |
T:23:53:00 | Win2K-f | 24.106.128.158 (RR.COM): ROAD RUNNER HOLDCO LLC, CUYAHOGA FALLS, OHIO, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 11 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |