Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:02:26:00 | WinXP | 110.165.212.44 (SANNET.NE.JP): NTT DATA SANYO SYSTEM CORPORATION, KANAZAWA, ISHIKAWA, JP. (DSL) |
n/a | DE:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | 3d1e7feff2 NEW |
b4ff90bf86 [none] | none:none |
PolyEnE| | none | none |
T:05:36:00 | WinXP | 61.62.22.89 (SO-NET.NET.TW): SONY NETWORK TAIWAN LIMITED, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:06:45:00 | WinXP | 98.101.106.156 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | DE:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:06:58:00 | WinXP | 85.138.184.241 (CPE.NETCABO.PT): TVCABO-PORTUGAL CABLE MODEM NETWORK, AMORA, SETUBAL, PT. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com RU:ebookfinaltrash.ru :wpad DE:217.11.54.126:80 |
445 | pcap | raw alerts ruleset |
http http http http 23 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:09:43:00 | Win2K-f | 24.213.238.119 (RR.COM): ROAD RUNNER HOLDCO LLC, BALLSTON SPA, NEW YORK, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:11:15:00 | WinXP | 208.110.57.45 (-): PRIVATE CABLE ISP SUBSCRIBER (SCHAUMBURG IL MARKET), JONESBORO, GEORGIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 71 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 33 | 73ce2b74da NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:12:29:00 | Win2K-f | 61.250.125.120 (KRLINE.NET): KRNIC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 40 33 of 33 |
27b17a2724 NEW 53bfe15e91 NEW |
a1d5ac965b [0] 1473091351[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=42 lines=75 embedded dns |
trace trace |
T:14:16:00 | WinXP | 77.255.255.68 (INETIA.PL): INTERNETIA, LUBLIN, LUBELSKIE, PL. (DSL) |
n/a | DE:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:14:22:00 | WinXP | 208.103.155.213 (CORETEL.NET): CORETEL AMERICA INC, MYERSTOWN, PENNSYLVANIA, US. (DIAL) |
n/a | DE:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 72134e4b44 NEW |
28c60e99a7 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:18:12:00 | Win2K-f | 24.167.191.87 (RR.COM): ROAD RUNNER HOLDCO LLC, HIGH POINT, NORTH CAROLINA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:32:00 | Win2K-f | 4.177.219.211 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, SAN DIEGO, CALIFORNIA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 178 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | 47d3548e36 NEW |
ab13346633 [0] | ASM:Graph |
Armadillo| | lines=91 | trace | |
T:22:08:00 | Win2K-f | 125.4.234.190 (ZAQ.NE.JP): J:COM WEST CO. LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1010 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 14 of 40 |
15953b80a1 NEW def7923243 NEW |
e0972bc7eb [0] none [3] |
ASM:Graph none:none |
StarForce| StarForce| |
lines=45 none |
trace trace |
|
T:22:14:00 | Win2K-f | 98.141.163.84 (CAVTEL.NET): CAVALIER TELEPHONE, PHILADELPHIA, PENNSYLVANIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |