Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:49:00 | WinXP | 61.62.22.89 (SO-NET.NET.TW): SONY NETWORK TAIWAN LIMITED, TAIPEI, T'AI-PEI, TW. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:02:05:00 | Win2K-f | 4.138.0.181 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DULUTH, GEORGIA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 81 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:49:00 | Win2K-f | 122.196.46.11 (ZAQ.NE.JP): J:COM WEST CO. LTD, OSAKA, OSAKA, JP. (DSL) |
n/a | JP:122.196.46.11:707 FI:194.215.38.3:80 EE:62.65.192.24:80 |
135 | pcap | raw alerts ruleset |
irc 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:04:26:00 | WinXP | 64.188.192.125 (-): WINDJAMMER COMMUNICATIONS LLC, BOSTON, MASSACHUSETTS, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:04:57:00 | WinXP | 87.173.102.215 (T-DIALIN.NET): DEUTSCHE TELEKOM AG, MAGDEBURG, SACHSEN-ANHALT, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
07:52:00 | WinXP | 61.62.22.89 (SO-NET.NET.TW): SONY NETWORK TAIWAN LIMITED, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:10:56:00 | Win2K-f | 85.67.218.213 (BACS-NET.HU): FIBERNET COMMUNICATION CO, BUDAPEST, BUDAPEST, HU. (DSL) |
121.162.255.65:3921 | KR:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 22 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 23fb271769 NEW |
none[none] | none:none |
none|none | none | none |
T:11:02:00 | Win2K-f | 113.252.183.19 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
121.162.255.65:3921 | KR:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 26 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 3ed74d68ef NEW |
none[none] | none:none |
none|none | none | none |
T:11:31:00 | Win2K-f | 217.68.178.118 (PRIMACOM.NET): PRIMACOM-HEADENDS, LEIPZIG, SACHSEN, DE. (DSL) |
121.162.255.65:3921 | KR:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 22 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 0d97d83064 NEW |
none[none] | none:none |
none|none | none | none |
T:12:23:00 | Win2K-f | 70.122.217.51 (RR.COM): ROAD RUNNER HOLDCO LLC, TEXAS CITY, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:30:00 | WinXP | 112.110.96.36 (-): ICL-NET, DELHI, DELHI, IN. (DIAL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 010426cc3f NEW |
none[none] | none:none |
none|none | none | none |
T:12:37:00 | WinXP | 79.101.55.239 (MAIL.KTI.RS): KOPERNIKUS TECHNOLOGY, CS. (DSL) |
121.162.255.65:3921 | KR:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 28 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 36aae71ce2 NEW |
none[none] | none:none |
none|none | none | none |
T:14:08:00 | Win2K-f | 82.247.49.2 (PROXAD.NET): PROXAD / FREE SAS, PARIS, ILE-DE-FRANCE, FR. (DSL) |
121.162.255.65:3921 | KR:m.DRD3H.COM KR:121.162.255.65:3921 |
139 | pcap | raw alerts ruleset |
ftp irc 22 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 36aae71ce2 NEW |
none[none] | none:none |
none|none | none | none |
T:15:12:00 | Win2K-f | 24.77.243.165 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 123 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 38 of 41 |
34cbe7a593 NEW 3e83a2d4d7 NEW |
d38cb78003 [0] b97fd63d29[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:15:51:00 | WinXP | 69.205.144.162 (RR.COM): ROAD RUNNER HOLDCO LLC, FULTON, NEW YORK, US. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a0139d7ad8 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:16:27:00 | WinXP | 89.167.18.13 (-): NPLAY ISP NETWORK LUBLIN POLAND, LUBLIN, LUBELSKIE, PL. (DSL) |
121.162.255.65:3921 | KR:m.DRD3H.COM KR:121.162.255.65:3921 |
139 | pcap | raw alerts ruleset |
ftp irc 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | d253befda0 NEW |
none[none] | none:none |
none|none | none | none |
T:18:19:00 | Win2K-f | 24.77.135.149 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
121.162.255.65:3921 | KR:m.DRD3H.COM KR:121.162.255.65:3921 |
139 | pcap | raw alerts ruleset |
ftp irc 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | e4d39f4342 NEW |
none[none] | none:none |
none|none | none | none |
T:20:32:00 | Win2K-f | 24.164.94.229 (RR.COM): ROAD RUNNER HOLDCO LLC, DAYTON, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:50:00 | WinXP | 173.168.112.118 (RR.COM): ROAD RUNNER HOLDCO LLC, BRADENTON, FLORIDA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
1da4193446 NEW 6278c9374a NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:22:05:00 | Win2K-f | 173.28.213.5 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, CHANHASSEN, MINNESOTA, US. (DSL) |
n/a | US:microsoft.com US:204.152.184.139:80 |
135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:23:52:00 | WinXP | 218.220.150.75 (ZAQ.NE.JP): J:COM WEST CO. LTD, OSAKA, OSAKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 18 of 35 |
07fabc79ef NEW 218ce30f5c NEW |
none[0] none [3] |
none:none none:none |
Armadillo| none|none |
lines=90 none |
trace trace |