Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:25:00 | Win2K-f | 86.46.133.28 (EIRCOM.NET): EIRCOM, GALWAY, GALWAY, IE. (DSL) |
60.190.222.139:65520 | US:microsoft.com CN:proxim.ircgalaxy.pl CN:ku.installstorm.com CN:222.170.127.203:88 CN:60.190.222.139:65520 |
445 | pcap | raw alerts ruleset |
irc 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:01:47:00 | WinXP | 193.248.45.249 (ABO.WANADOO.FR): NSLIL205 LILLE, MONTPELLIER, LANGUEDOC-ROUSSILLON, FR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:03:11:00 | Win2K-f | 148.233.150.147 (-): H AYUNTAMIENTO DE MERIDA, MEXICO, DISTRITO FEDERAL, MX. (100Mbps) |
n/a | US:microsoft.com US:130.10.36.141:64081 DE:131.220.6.26:80 |
135 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:03:20:00 | WinXP | 95.239.163.80 (BUSINESS.TELECOMITALIA.IT): TELECOM ITALIA WIRELINE SERVICES, ROME, LAZIO, IT. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:03:31:00 | WinXP | 222.230.153.161 (VECTANT.NE.JP): SEIKA CORPORATION, YOKOHAMA, KANAGAWA, JP. (100Mbps) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:05:08:00 | Win2K-f | 61.105.154.166 (KRLINE.NET): KRNIC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 41 33 of 33 |
8b41cb7a41 NEW 97fef473b9 NEW |
ef18d720f3 [0] ff4e7d6992[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=90 lines=64 embedded dns |
trace trace |
T:05:10:00 | Win2K-f | 69.112.116.104 (OPTONLINE.NET): OPTIMUM ONLINE (CABLEVISION SYSTEMS), BROOKLYN, NEW YORK, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:05:25:00 | WinXP | 69.193.78.147 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:05:35:00 | Win2K-f | 211.20.222.150 (HINET.NET): XUN HANG TECHNOLOGY CO. LTD, TAIPEI, T'AI-PEI, TW. (100Mbps) |
62.193.249.122:3305 | KR:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 696 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:05:58:00 | Win2K-f | 4.176.244.247 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, TUCSON, ARIZONA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 228 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 36 of 40 |
47d3548e36 NEW d8722af110 NEW |
ab13346633 [0] ab30a55931[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:06:36:00 | Win2K-f | 110.93.97.183 (CABLENET.NE.JP): CABLENET SAITAMA CO. LTD, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 41 |
5bbb57c115 NEW 75ac189d9e NEW |
03e5cb3c4a [0] 705dbaa801[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:06:40:00 | Win2K-f | 196.202.232.249 (OKALLA-AHANDA.COM): AFRINIC, DOUALA, LITTORAL, CM. (DSL) |
n/a | US:www.getmyip.org EU:getmyip.co.uk GB:www.vouchercodez.com :checkip.dyndns.org US:microsoft.com DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 7 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:07:37:00 | WinXP | 61.221.237.252 (-): HUNG REN SHIN IE CO. LTD. PINGTUNG BRANCH COMPANY, TAIPEI, T'AI-PEI, TW. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 1002 lines |
Yeah : 1.3 profile |
none | summary tarball |
17 of 41 | e1693609f9 NEW |
none[3] | none:none |
none|none | none | trace | |
07:51:00 | WinXP | 88.31.235.64 (RIMA-TDE.NET): TELEFONICA MOVILES ESPANA (NCC#2007041930), PALMA DE MALLORCA, ISLAS BALEARES, ES. (DSL) |
n/a | EU:citi-bank.ru EU:91.207.7.82:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | f45285574e NEW |
d984958bf9 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:10:02:00 | Win2K-f | 65.184.62.164 (RR.COM): ROAD RUNNER HOLDCO LLC, WILMINGTON, NORTH CAROLINA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 36 of 41 |
84ace068d1 NEW c584af4fcd NEW |
c822a7d0e4 [0] bdfcf0a930[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
T:11:01:00 | Win2K-f | 75.77.70.210 (NUVOX.NET): NUVOX COMMUNICATIONS INC, SUMMERVILLE, SOUTH CAROLINA, US. (DSL) |
n/a | US:www.getmyip.org EU:getmyip.co.uk GB:www.vouchercodez.com :checkip.dyndns.org US:67.15.94.80:80 US:75.126.138.202:80 |
135 | pcap | raw alerts ruleset |
http 3 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:11:36:00 | Win2K-f | 203.198.218.17 (NETVIGATOR.COM): CCC046 INTERNET ACCESS IBS, HONG KONG, HONG KONG (SAR), HK. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 123 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 39 of 41 |
2b47f2f06e NEW d02ed5d41f NEW |
59b80dc1ac [0] 9e3f05fdb0[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:13:31:00 | Win2K-f | 218.119.176.169 (BBTEC.NET): JAPAN NATION-WIDE NETWORK OF SOFTBANK BB CORP, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
14:33:00 | WinXP | 190.208.109.11 (-): TELMEX CHILE S.A HFC, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
n/a | EU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:15:30:00 | WinXP | 174.44.221.148 (BRESNAN.NET): BRESNAN COMMUNICATIONS LLC, PURCHASE, NEW YORK, US. (DSL) |
91.207.7.82:80 | EU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:20:52:00 | Win2K-f | 71.96.69.59 (VERIZON.NET): VERIZON INTERNET SERVICES INC, CARROLLTON, TEXAS, US. (DSL) |
n/a | US:www.maxmind.com US:204.152.184.139:80 US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:21:30:00 | Win2K-f | 113.252.100.140 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1002 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 41 | 559acaa271 NEW |
none[3] | none:none |
none|none | none | trace | |
T:21:52:00 | Win2K-f | 124.181.210.130 (BIGPOND.NET.AU): TELSTRAINTERNET44, MELBOURNE, VICTORIA, AU. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 39 38 of 39 |
c9b55806df NEW cc9f84d129 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:22:00:00 | Win2K-f | 207.5.161.171 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |