Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:51:00 | Win2K-f | 172.132.98.74 (AOL.COM): AMERICA ONLINE, RESTON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
02:09:00 | Win2K-f | 59.125.124.76 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org EU:getmyip.co.uk GB:www.vouchercodez.com :checkip.dyndns.org DE:131.220.6.26:80 US:75.126.138.202:80 GB:80.82.121.239:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:02:20:00 | Win2K-f | 59.125.124.76 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:trafficconverter.biz US:microsoft.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:03:03:00 | Win2K-f | 96.49.158.173 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:36:00 | Win2K-f | 95.26.139.154 (CORBINA.NET): INVESTELEKTROSVIAZ LTD, RU. (DSL) |
n/a | US:microsoft.com US:www.maxmind.com US:204.152.184.139:80 US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:03:57:00 | WinXP | 178.24.217.28 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
60.190.222.139:65520 | CN:proxim.ircgalaxy.pl EU:updatemania.info EU:pozeml.com EU:91.206.201.40:80 EU:91.212.198.133:80 |
445 | pcap | raw alerts ruleset |
http irc 30 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 42 | d169c8c5e6 NEW |
none[none] | none:none |
none|none | none | none |
T:06:09:00 | Win2K-f | 174.5.186.131 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1009 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 41 | 43b8f21924 NEW |
none[3] | none:none |
none|none | none | trace | |
T:06:49:00 | Win2K-f | 88.218.97.52 (-): AMALTHEIA EKDOTIKI A.E. NETWORK, ATHENS, ATTIKI, GR. (100Mbps) |
n/a | US:microsoft.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:08:25:00 | WinXP | 175.117.214.15 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 5 of 41 |
14f47ffd1e NEW 50437008d9 NEW |
90bf4b99ff [0] c1b09ac5d7[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=56 embedded dns lines=90 |
trace trace |
T:08:27:00 | WinXP | 70.138.10.1 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, WATERBURY, CONNECTICUT, US. (DSL) |
n/a | US:www.yahoo.com :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | bb7681eca8 NEW |
none[3] | none:none |
tElock| | none | trace |
T:11:09:00 | WinXP | 71.101.172.163 (VERIZON.NET): VERIZON INTERNET SERVICES INC, LAKELAND, FLORIDA, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:11:56:00 | Win2K-f | 200.175.210.241 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | US:microsoft.com US:www.maxmind.com DE:131.220.6.26:80 US:204.152.184.139:80 US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:14:48:00 | WinXP | 66.19.77.168 (MCLEODUSA.NET): PAETEC COMMUNICATIONS INC, TAMPA, FLORIDA, US. (DSL) |
60.190.222.139:65520 | CN:proxim.ircgalaxy.pl CN:av.lometr.pl CN:ku.installstorm.com EU:pozeml.com CN:222.170.127.203:88 CN:60.190.222.139:65520 EU:91.206.201.40:80 |
445 | pcap | raw alerts ruleset |
http irc 26 lines |
Yeah : 1.3 profile |
none | summary tarball |
4 of 42 37 of 39 |
5fc40655c2 NEW dab4da4e21 NEW |
none[3] e63b813015[0] |
none:none ASM:Graph |
none|none PolyEnE| |
none lines=134 |
trace trace |
T:15:12:00 | Win2K-f | 213.191.26.230 (UR.RU): DYNAMIC FTTB USERS BLOCK, EKATERINBURG, SVERDLOVSK, RU. (DSL) |
n/a | US:microsoft.com US:204.152.184.139:80 |
139 | pcap | raw alerts ruleset |
http 10 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:16:50:00 | WinXP | 75.119.96.196 (LDMI.COM): IDEAL TECHNOLOGY SOLUTIONS US INC, DETROIT, MICHIGAN, US. (100Mbps) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | f45285574e NEW |
d984958bf9 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:17:52:00 | Win2K-f | 222.233.99.112 (HANANET.NET): HANARO TELECOM INC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
60.190.222.139:65520 | CN:proxima.ircgalaxy.pl US:microsoft.com CN:ku.installstorm.com EU:pozeml.com US:sendinvest.com :findhobbits.com EU:img.ub8.net CN:test.installstorm.com :xz.ub9.net :in.7cy.net 173.45.105.218:8392 174.133.57.141:80 US:208.43.146.98:80 CN:60.190.222.139:65520 EU:91.206.201.40:80 |
135 | pcap | raw alerts ruleset |
irc http 331 lines |
Yeah : 1.8 profile |
none | summary tarball |
29 of 39 33 of 42 24 of 42 0 of 42 39 of 41 31 of 33 23 of 42 |
4691ac4856 NEW 4a7ac19475 NEW 4a7bbd7e0d NEW a7def8166c NEW ab9c4b5f21 NEW d789c8d157 NEW f43d0c50c6 NEW |
281da14e28 [0] none [none] none [none] none [none] 5fe48b2dcc[0] 5f6572479f[0] none [none] |
ASM:Graph none:none none:none none:none ASM:Graph ASM:Graph none:none |
StarForce| none|none none|none none|none Armadillo| PolyEnE| none|none |
lines=24 none none none lines=42 lines=113 embedded dns none |
trace none none none trace trace none |
T:19:43:00 | Win2K-f | 95.28.12.104 (CORBINA.RU): INVESTELEKTROSVIAZ LTD, MOSCOW, MOSCOW CITY, RU. (100Mbps) |
n/a | US:www.maxmind.com EU:getmyip.co.uk DE:131.220.6.26:80 US:204.152.184.139:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:20:15:00 | WinXP | 66.108.188.176 (RR.COM): ROAD RUNNER HOLDCO LLC, NEW YORK, NEW YORK, US. (100Mbps) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 3ae357d17b NEW |
none[0] | none:none |
PolyEnE| | lines=73 | trace |
T:21:01:00 | WinXP | 121.121.137.176 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 42 | 1bf2271bf5 NEW |
none[none] | none:none |
none|none | none | none |
T:22:26:00 | Win2K-f | 64.181.7.122 (WVFIBERNET.NET): FIBERNET OF WEST VIRGINIA, CHARLESTON, WEST VIRGINIA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 114 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 40 |
67f1a33096 NEW 724cf0dc37 NEW |
148e04eaab [0] 901dd267d4[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:22:39:00 | WinXP | 98.141.9.117 (CAVTEL.NET): CAVALIER TELEPHONE, VIRGINIA BEACH, VIRGINIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |