Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:50:00 | WinXP | 79.179.14.79 (BEZEQINT.NET): ADSL-CUSTOMER-CONNECTION, BAT YAM, TEL AVIV, IL. (DSL) |
n/a | EU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:01:15:00 | WinXP | 4.153.68.241 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, FAIRVIEW, TENNESSEE, US. (DIAL) |
n/a | EU:citi-bank.ru EU:91.207.7.82:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 3ae357d17b NEW |
none[0] | none:none |
PolyEnE| | lines=73 | trace |
T:02:07:00 | WinXP | 94.52.176.218 (-): NEW COM TELECOMUNICATII SA, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | EU:citi-bank.ru EU:91.207.7.82:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:02:37:00 | Win2K-f | 4.248.72.152 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, KEASBEY, NEW JERSEY, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 107 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:43:00 | Win2K-f | 24.210.104.96 (RR.COM): ROAD RUNNER HOLDCO LLC, LIVONIA, MICHIGAN, US. (DSL) |
n/a | FI:194.215.38.3:80 EE:62.65.192.24:80 |
135 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:04:22:00 | Win2K-f | 67.125.140.230 (PACBELL.NET): AT&T INTERNET SERVICES, FRESNO, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com US:204.152.184.139:80 |
135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:04:29:00 | Win2K-f | 113.252.54.246 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1002 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 41 | 559acaa271 NEW |
none[3] | none:none |
none|none | none | trace | |
04:31:00 | WinXP | 94.52.176.218 (-): NEW COM TELECOMUNICATII SA, BUCHAREST, BUCURESTI, RO. (DSL) |
91.207.7.82:80 | EU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:04:51:00 | WinXP | 121.121.128.14 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | EU:citi-bank.ru EU:91.207.7.82:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:05:05:00 | WinXP | 24.58.224.115 (RR.COM): ROAD RUNNER HOLDCO LLC, MASSENA, NEW YORK, US. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com :wpad US:new.egg.com US:208.73.210.125:80 |
445 | pcap | raw alerts ruleset |
http http http http 27 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee NEW |
none[0] | none:none |
ASPack| | lines=298 embedded dns |
trace |
T:05:52:00 | Win2K-f | 68.147.20.191 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1016 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 41 | 682a384fe9 NEW |
none[3] | none:none |
none|none | none | trace | |
T:07:29:00 | Win2K-f | 173.168.58.239 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 11 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:07:48:00 | Win2K-f | 75.15.225.16 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, BAKERSFIELD, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
1e12f5145a NEW f208493e65 NEW |
617af909de [0] 5100adb4f9[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:08:08:00 | Win2K-f | 207.5.194.120 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:09:19:00 | Win2K-f | 68.147.22.102 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1028 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 39 34 of 39 |
0d69ab89ac NEW 97ce7f9768 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
|
T:10:17:00 | WinXP | 84.108.99.32 (BEZEQINT.NET): CABLES-CUSTOMERS-CONNECTION, PETAH TIQVA, HAMERKAZ, IL. (DSL) |
n/a | EU:citi-bank.ru EU:91.207.7.82:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:12:22:00 | Win2K-f | 206.135.214.71 (MEGAPATH.NET): MEGAPATH NETWORKS INC, GAITHERSBURG, MARYLAND, US. (DSL) |
68.178.232.100:80 | CN:www.baidu.com US:trafficconverter.biz :upcmgx.com US:omsohlbq.info :udbvvbbhpti.net US:diotgoqz.biz US:puzyk.com US:ngwbl.biz :vqgephjt.net US:mocubbtjla.info :esvoafacmfs.net US:svluqlkg.biz :djgzfzne.com :kxodbrgvi.com US:ezkpury.org US:ovhtcueg.biz :gabvvczvge.com :cmqirtrlpy.com US:twxlxy.info US:monohvc.org US:ibzulj.org US:gibaztiu.org US:xosiheg.org :opeoudymgo.com US:ahzbfg.org US:hgkvgartb.info US:jfdhugnjcy.biz :rpoffrcfn.com US:ehlnvgdw.info US:lvigwao.info US:rzvvmttz.info :mhpgbu.com :rfnlso.com US:xqwwp.info US:nuqlmgfs.info :ybysfyzkdtv.com US:hshgavka.biz US:mhtqepywkhe.org :nqhlqdtz.net :wkljdplr.net :ojjvtxiftey.net US:hnvla.biz :ipgcdbhe.com US:iwmttnprf.info US:fknnwpr.info US:fmtweoaf.biz US:lwlwhaprsg.info US:lmzqhvgnvd.info US:mtcjpjhyh.org US:hwstboeh.org :ypqehehr.com US:zuhinzts.org US:nmvkmbubosn.biz US:cylfplbo.biz US:olzppd.biz US:btxjmikgkoi.info US:smjgaozodnw.info US:ctuaarvj.biz :sngtqdpkus.net US:gfkbyhfyzly.org US:udjtjgek.biz US:hbtijwov.biz US:edogdta.info US:ylzctdmi.info :dbexvdkfze.net :zrmvttbyiwa.com :alvoiyde.net US:irblc.org US:vulbhgkz.biz US:esdgf.info US:sdeolbdn.biz US:hyekjwnzf.org US:204.152.184.139:80 US:74.208.64.145:80 |
445 | pcap | raw alerts ruleset |
http 10 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:13:04:00 | Win2K-f | 24.78.210.177 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 39 | e8cc68aaa0 NEW |
none[none] | none:none |
none|none | none | none | |
T:13:57:00 | WinXP | 122.146.252.192 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:17:10:00 | Win2K-f | 58.146.58.192 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:17:41:00 | Win2K-f | 202.78.146.124 (TELSTRACLEAR.NET): TELSTRACLEAR WELLINGTON CABLE CUSTOMERS, WELLINGTON, WELLINGTON, NZ. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
18:27:00 | Win2K-f | 61.134.64.166 (-): GANSU ZHANGYE THE USE OF NETWORK MANAGEMENT, ZHANGYE, GANSU, CN. (100Mbps) |
n/a | US:www.maxmind.com :checkip.dyndns.org US:www.getmyip.org EU:getmyip.co.uk 208.78.70.70:80 US:67.15.94.80:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
21:05:00 | Win2K-f | 61.134.64.166 (-): GANSU ZHANGYE THE USE OF NETWORK MANAGEMENT, ZHANGYE, GANSU, CN. (100Mbps) |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:21:46:00 | Win2K-f | 184.80.69.109 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:22:54:00 | WinXP | 114.44.124.242 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | EU:citi-bank.ru EU:91.207.7.82:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 39 | 97a4f70411 NEW |
none[none] | none:none |
none|none | none | none |
T:23:01:00 | Win2K-f | 98.141.163.84 (CAVTEL.NET): CAVALIER TELEPHONE, PHILADELPHIA, PENNSYLVANIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
23:38:00 | Win2K-f | 200.49.10.163 (-): COOP. PROV. OBRAS Y SERV. PCOS. Y A. V. Y C. SETUBAL, CORDOBA, CORDOBA, AR. (100Mbps) |
n/a | US:www.maxmind.com :checkip.dyndns.org US:www.getmyip.org EU:getmyip.co.uk 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |