Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:49:00 | Win2K-f | 75.60.216.87 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, COLUMBUS, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:01:50:00 | Win2K-f | 63.24.111.194 (UU.NET): UUNET TECHNOLOGIES INC, BOISE, IDAHO, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 169 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | 73f1082158 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:02:07:00 | WinXP | 114.51.159.218 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:09:19:00 | WinXP | 109.87.7.148 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:10:10:00 | WinXP | 74.51.42.169 (TELNETCOMMUNICATIONS.COM): TELNET COMMUNICATIONS, SUDBURY, ONTARIO, CA. (100Mbps) |
67.228.26.154:3305 | PL:cx10man.weedns.com KR:fx010413.whyI.org PL:83.2.139.1:3305 |
135 | pcap | raw alerts ruleset |
shell ftp irc 26 lines |
Yeah : 1.8 profile |
none | summary tarball |
41 of 41 | 88c7adbc7c NEW |
ca34455cae [none] | none:none |
StarForce| | none | none |
T:12:13:00 | Win2K-f | 173.168.162.214 (RR.COM): ROAD RUNNER HOLDCO LLC, CLEARWATER, FLORIDA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:22:00 | Win2K-f | 207.5.161.171 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:48:00 | Win2K-f | 69.193.68.239 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:56:00 | WinXP | 24.77.129.233 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 123 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 38 of 41 |
34cbe7a593 NEW 3e83a2d4d7 NEW |
d38cb78003 [0] b97fd63d29[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:13:21:00 | Win2K-f | 71.83.87.111 (CHARTER.COM): CHARTER COMMUNICATIONS, RIVERSIDE, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
13:44:00 | WinXP | 81.198.145.8 (-): ADDRESS POOL FOR LTC-HOME CUSTOMERS, RIGA, RIGA, LV. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | aab1b56620 NEW |
3b2e1c5b9d [0] | ASM:Graph |
PolyEnE| | lines=63 | trace |
14:00:00 | Win2K-f | 125.231.186.70 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk US:www.getmyip.org :checkip.dyndns.org DE:131.220.6.26:80 208.78.70.70:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:14:08:00 | Win2K-f | 70.122.209.6 (RR.COM): ROAD RUNNER HOLDCO LLC, TEXAS CITY, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:25:00 | Win2K-f | 4.188.162.233 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, TOLEDO, OHIO, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:16:06:00 | WinXP | 213.39.168.100 (HANSENET.DE): HANSENET-ADSL, HAMBURG, HAMBURG, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:16:12:00 | Win2K-f | 69.108.67.54 (PACBELL.NET): IRVNCA INTERNAL, LOS ANGELES, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:25:00 | WinXP | 4.153.65.219 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, NASHVILLE, TENNESSEE, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 64 lines |
Yeah : 1.3 profile |
none | summary tarball |
1 of 42 | fbeab6cc57 NEW |
none[none] | none:none |
none|none | none | none | |
17:30:00 | Win2K-f | 186.18.182.76 (186.IN-ADDR.ARPA): TELECENTRO S.A. - CLIENTES RESIDENCIALES, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org EU:getmyip.co.uk US:www.getmyip.org 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
18:35:00 | Win2K-f | 58.60.106.123 (-): ZHONGGUODIANXINIW, SHENZHEN, GUANGDONG, CN. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org EU:getmyip.co.uk :checkip.dyndns.org DE:131.220.6.26:80 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:21:53:00 | Win2K-f | 216.66.129.143 (LOOK.CA): LOOK COMMUNICATIONS INC, MILTON, ONTARIO, CA. (DSL) |
n/a | JP:cx10man.weedns.com :fx010413.whyI.org :gynoman.weedns.com US:g.0x20.biz :c010x1.co.cc RU:commgr.co.cc FI:telephone.dd.blueline.be :phonewire.dd.blueline.be :phonelogin.dd.blueline.be JP:ufospace.etowns.net KR:theforums.bbsindex.com :phonewire.dnip.net :phonelogin.dnip.net :koopa.dnip.net JP:210.166.223.51:3305 67.228.26.154:3305 PL:83.2.139.1:3305 PL:83.2.139.1:3308 RU:89.208.33.88:3305 92.240.234.164:3305 |
135 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | 88c7adbc7c NEW |
ca34455cae [none] | none:none |
StarForce| | none | none |
T:22:29:00 | WinXP | 99.145.139.60 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, HOUSTON, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:23:23:00 | Win2K-f | 83.185.100.59 (TELE2.SE): TELE2-MOBILE-INTERNET, SE. (DSL) |
67.228.26.154:3305 | KR:cx10man.weedns.com PL:fx010413.whyI.org PL:83.2.139.1:3305 |
135 | pcap | raw alerts ruleset |
shell ftp irc 26 lines |
Yeah : 1.8 profile |
none | summary tarball |
42 of 42 | 9dc348bf48 NEW |
none[none] | none:none |
none|none | none | none |