Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:03:49:00 | WinXP | 24.76.49.120 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, STEINBACH, MANITOBA, CA. (DSL) |
n/a | CN:proxim.ircgalaxy.pl US:microsoft.com CN:av.lometr.pl :pozemle.cn EU:updatemania.info :frensomo.com CN:file0129.iwillhavesexygirls.com :dglanudcj.com :pozeml.com US:ivo.com CN:122.224.6.48:88 EU:91.212.198.133:80 |
135 | pcap | raw alerts ruleset |
irc http 766 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 41 4 of 42 41 of 41 11 of 42 41 of 42 |
0c27ab8679 NEW 5fc40655c2 NEW a0d26c8223 NEW acfa97b99a NEW f33c5df10a NEW |
366466a774 [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none |
none none none none none |
none none none none none |
T:07:29:00 | Win2K-f | 70.183.164.197 (COX.NET): COX COMMUNICATIONS, PROVIDENCE, RHODE ISLAND, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:24:00 | WinXP | 70.92.246.76 (RR.COM): ROAD RUNNER HOLDCO LLC, MILWAUKEE, WISCONSIN, US. (100Mbps) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 042774a2b7 NEW |
none[0] | none:none |
PolyEnE| | lines=69 embedded dns |
trace |
T:13:01:00 | WinXP | 78.38.190.211 (-): INFORMATION TECHNOLOGY COMPANY (ITC), IR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:16:17:00 | Win2K-f | 174.5.112.93 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 39 | ce28648035 NEW |
126d2f4655 [0] | ASM:Graph |
none|none | lines=546 | trace | |
20:39:00 | Win2K-f | 60.170.113.2 (CNDATA.COM): CHINANET ANHUI PROVINCE NETWORK, HEFEI, ANHUI, CN. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:23:40:00 | Win2K-f | 174.6.136.121 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, VANCOUVER, BRITISH COLUMBIA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 40 of 41 |
30ea3706f2 NEW 6c0e65f982 NEW |
f237e2db22 [0] 895bc4c44d[0] |
none:none ASM:Graph |
Armadillo| tElock| |
none lines=64 embedded dns |
trace trace |