Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:03:26:00 | Win2K-f | 69.145.121.84 (BRESNAN.NET): BRESNAN COMMUNICATIONS LLC, BUTTE, MONTANA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:08:12:00 | Win2K-f | 211.20.222.150 (HINET.NET): XUN HANG TECHNOLOGY CO. LTD, TAIPEI, T'AI-PEI, TW. (100Mbps) |
n/a | FR:cx10man.weedns.com DE:fx010413.whyI.org FR:62.193.249.122:3305 |
135 | pcap | raw alerts ruleset |
irc 690 lines |
Yeah : 1.3 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:09:46:00 | WinXP | 70.182.94.31 (COX.NET): COX COMMUNICATIONS, OKLAHOMA CITY, OKLAHOMA, US. (DSL) |
60.190.222.139:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com EU:updatemania.info US:sendinvest.com :findhobbits.com CN:ku.installstorm.com EU:img.ub8.net US:search.toptravellingtips.com US:208.43.250.167:80 US:66.96.221.102:80 DE:83.133.119.206:65520 |
135 | pcap | raw alerts ruleset |
irc http 209 lines |
Yeah : 1.8 profile |
none | summary tarball |
15 of 42 14 of 42 0 of 42 6 of 42 19 of 42 32 of 36 14 of 42 35 of 36 |
2c13cb6bcf NEW 43a72692f0 NEW 5a9c12d714 NEW 5df537b034 NEW a6e81f92e5 NEW bea8cb1865 NEW e68762e3aa NEW fac78fde16 NEW |
none[none] none [none] none [none] none [none] none [none] 154de51a66[0] none [none] 882896ab05[0] |
none:none none:none none:none none:none none:none ASM:Graph none:none ASM:Graph |
none|none none|none none|none none|none none|none Armadillo| none|none tElock| |
none none none none none lines=91 none lines=126 embedded dns |
none none none none none trace none trace |
T:17:18:00 | WinXP | 186.97.116.86 (-): . |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 8015c2d45f NEW |
749cbc2739 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
18:30:00 | Win2K-f | 218.22.143.165 (CNDATA.COM): CHINANET ANHUI PROVINCE NETWORK, ANQING, ANHUI, CN. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org EU:getmyip.co.uk GB:www.vouchercodez.com :checkip.dyndns.org 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 GB:80.82.121.239:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
20:35:00 | WinXP | 186.97.116.86 (-): . |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 8015c2d45f NEW |
749cbc2739 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:22:13:00 | WinXP | 61.62.63.98 (SO-NET.NET.TW): SONY NETWORK TAIWAN LIMITED, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:22:15:00 | Win2K-f | 75.15.231.187 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, BAKERSFIELD, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
1e12f5145a NEW f208493e65 NEW |
617af909de [0] 5100adb4f9[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
23:16:00 | Win2K-f | 77.104.69.99 (-): RESPINA NETWORKS & BEYOND, IR. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org EU:getmyip.co.uk GB:www.vouchercodez.com :checkip.dyndns.org DE:131.220.6.26:80 208.78.70.70:80 US:75.126.138.202:80 GB:80.82.121.239:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |