Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:07:00 | Win2K-f | 211.20.222.150 (HINET.NET): XUN HANG TECHNOLOGY CO. LTD, TAIPEI, T'AI-PEI, TW. (100Mbps) |
n/a | JP:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 695 lines |
Yeah : 1.3 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
02:08:00 | Win2K-f | 116.6.14.242 (163DATA.COM.CN): CHINANET GUANGDONG PROVINCE NETWORK, GUANGZHOU, GUANGDONG, CN. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org EU:getmyip.co.uk GB:www.vouchercodez.com US:www.getmyip.org DE:131.220.6.26:80 208.78.70.70:80 |
445 | pcap | raw alerts ruleset |
http 7 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:02:17:00 | Win2K-f | 116.6.14.242 (163DATA.COM.CN): CHINANET GUANGDONG PROVINCE NETWORK, GUANGZHOU, GUANGDONG, CN. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk US:www.getmyip.org :checkip.dyndns.org US:67.15.94.80:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:03:27:00 | Win2K-f | 113.254.179.54 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 38 of 41 |
a5ceb6c29d NEW adadfc0e1c NEW |
d64cd9d18b [0] 0f57439d82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=42 lines=64 embedded dns |
trace trace |
T:03:55:00 | Win2K-f | 211.44.208.14 (HANANET.NET): HANARO TELECOM INC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
60.190.222.139:65520 | CN:proxima.ircgalaxy.pl US:microsoft.com CN:av.lometr.pl CN:ku.installstorm.com CN:222.170.127.203:88 CN:60.190.222.131:81 |
135 | pcap | raw alerts ruleset |
irc 120 lines |
Yeah : 1.8 profile |
none | summary tarball |
31 of 33 31 of 33 |
168aab35a3 NEW 667f0c59f3 NEW |
60b730b97e [0] 8fe2be2095[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=120 embedded dns lines=91 |
trace trace |
T:12:13:00 | Win2K-f | 63.25.199.156 (UU.NET): UUNET TECHNOLOGIES INC, NEWCASTLE, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 119 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 38 of 41 |
02674c9a56 NEW 25eae40389 NEW |
0da2cae967 [0] 1e0aae0aeb[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
13:16:00 | Win2K-f | 188.173.79.155 (RIPE.NET): EUROPEAN REGIONAL REGISTRY, UK. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org EU:getmyip.co.uk GB:www.vouchercodez.com :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 8 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:13:25:00 | Win2K-f | 188.173.79.155 (RIPE.NET): EUROPEAN REGIONAL REGISTRY, UK. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org EU:getmyip.co.uk GB:www.vouchercodez.com 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 GB:80.82.121.239:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:15:28:00 | Win2K-f | 4.161.166.30 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, LEWISVILLE, TEXAS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:15:49:00 | WinXP | 114.205.182.250 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 124 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 41 of 42 |
2cafa36fad NEW 8350ad2ebd NEW |
3431b895f5 [none] efee2d97ff[none] |
none:none none:none |
PolyEnE| Armadillo| |
none none |
none none |
T:18:51:00 | Win2K-f | 66.81.255.159 (O1.COM): O1 DIALUP SERVICES, GLENDALE, CALIFORNIA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 127 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | 73f1082158 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:21:59:00 | WinXP | 117.254.168.136 (STERLINGSTUDENTS.NET): NIB (NATIONAL INTERNET BACKBONE), NEW DELHI, DELHI, IN. (DSL) |
n/a | EU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | f502585714 NEW |
none[0] | none:none |
PolyEnE| | lines=63 | trace |