Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:18:00 | Win2K-f | 202.107.247.8 (CNINFO.NET): CHINANET-ZJ QUZHOU NODE NETWORK, QUZHOU, ZHEJIANG, CN. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:42:00 | Win2K-f | 98.112.33.152 (VERIZON.NET): VERIZON INTERNET SERVICES INC, LONG BEACH, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com EE:www.starman.ee FI:194.215.38.3:80 EE:62.65.192.24:80 |
135 | pcap | raw alerts ruleset |
irc 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:05:37:00 | WinXP | 66.81.160.118 (O1.COM): O1 DIALUP SERVICES, LINCOLN, CALIFORNIA, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:06:41:00 | WinXP | 74.115.73.181 (MTCBROADBAND.NET): MTC BROADBAND INC, US. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com US:new.egg.com :wpad :www.proxy-socks.net |
445 | pcap | raw alerts ruleset |
http http http http 52 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:07:09:00 | WinXP | 115.165.80.12 (CATV02.ITSCOM.JP): ITS COMMUNICATIONS INC, KAWASAKI, KANAGAWA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:07:14:00 | WinXP | 60.249.200.66 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:07:57:00 | WinXP | 186.10.33.206 (IMOVIL.ENTELPCS.CL): ENTEL PCS TELECOMUNICACIONES S.A, CL. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru :adult-empire.com |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
08:21:00 | Win2K-f | 123.213.5.12 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | CN:sys.zief.pl CN:av.lometr.pl FR:updatemania.info CN:ku1.installstorm.com US:sendinvest.com US:findhobbits.com CN:test.installstorm.com US:396d6f87.linkbucks.com US:caf18cd7.linkbucks.com GR:img.ub8.net US:9c200c62.linkbucks.com US:7e30432a.linkbucks.com US:30b877c3.linkbucks.com :static.linkbucks.com CA:74.117.63.90:80 US:8.5.1.45:8392 |
139 | pcap | raw alerts ruleset |
http 147 lines |
Yeah : 0.8 profile |
none | summary tarball |
9 of 40 25 of 40 25 of 40 33 of 40 23 of 40 36 of 40 |
2977c2f719 NEW 816b3349e9 NEW 8d2b4a8503 NEW a4d3ff3ac9 NEW a6771e6318 NEW ba9120ddd6 NEW |
none[none] none [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none none|none |
none none none none none none |
none none none none none none |
08:29:00 | Win2K-f | 85.122.60.78 (ZAPPMOBILE.RO): SC TEHNOCONSTRUCT SRL, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | US:rts.sparkstudios.com :www.google-analytics.com :vimby.com US:edge.quantserve.com :static.vimby.com :www.vimby.com US:search.yahoo.com US:www.search.com CN:www.baidu.com :www.google.com :www.dogpile.com |
445 | pcap | raw alerts ruleset |
http 134 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
08:39:00 | Win2K-f | 79.125.180.8 (-): ONNET ADSL IP SUBNET, OHRID, OHRID, MK. (DSL) |
n/a | US:search.toptravellingtips.com US:search.articleswave.co.uk :www.articleswave.co.uk :www.searchour.com :nl.travelzip.co.uk US:8.5.1.45:8392 |
445 | pcap | raw alerts ruleset |
http 168 lines |
Argh : 0.3 profile |
none | summary tarball |
0 of 40 17 of 40 15 of 40 17 of 40 |
2c0fca7ec3 NEW 7a39f79672 NEW befbb0d73e NEW ea257adc9f NEW |
none[none] none [none] none [none] none [none] |
none:none none:none none:none none:none |
none|none none|none none|none none|none |
none none none none |
none none none none |
08:58:00 | Win2K-f | 186.56.146.186 (COM.AR): TELEFONICA DE ARGENTINA, AR. (DSL) |
n/a | CN:sys.zief.pl CN:ku1.installstorm.com CN:test.installstorm.com US:396d6f87.linkbucks.com :img.ub8.net :static.linkbucks.com US:rts.sparkstudios.com :www.google-analytics.com US:edge.quantserve.com US:pixel.quantserve.com :vimby.com :static.vimby.com :www.vimby.com :www.google.com US:caf18cd7.linkbucks.com US:7e30432a.linkbucks.com US:9c200c62.linkbucks.com US:30b877c3.linkbucks.com CA:74.117.63.90:80 |
445 | pcap | raw alerts ruleset |
http 184 lines |
Yeah : 0.8 profile |
none | summary tarball |
9 of 40 25 of 40 25 of 40 23 of 40 |
33505e2aae NEW 816b3349e9 NEW 8d2b4a8503 NEW a6771e6318 NEW |
none[none] none [none] none [none] none [none] |
none:none none:none none:none none:none |
none|none none|none none|none none|none |
none none none none |
none none none none |
T:10:27:00 | Win2K-f | 24.79.209.49 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
n/a | EE:www.starman.ee US:microsoft.com FI:194.215.38.3:80 US:204.152.184.139:80 EE:62.65.192.24:80 |
135 | pcap | raw alerts ruleset |
irc 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:11:15:00 | WinXP | 211.135.56.34 (ZAQ.NE.JP): J:COM WEST CO. LTD, OSAKA, OSAKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:11:51:00 | Win2K-f | 118.83.134.2 (NKNO.J-CNET.JP): CITY TV NAKANO LIMITED, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 133 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 36 34 of 36 |
0b951c2832 NEW e4ed4df0f0 NEW |
5fe761661a [0] de471fc380[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:13:07:00 | Win2K-f | 69.193.68.239 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:09:00 | WinXP | 186.97.237.175 (-): . |
n/a | RU:citi-bank.ru :parex-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | d6d08b8238 NEW |
none[none] | none:none |
none|none | none | none |
15:19:00 | Win2K-f | 173.45.68.171 (XLHOST.COM): ENET INC, COLUMBUS, OHIO, US. (100Mbps) |
n/a | US:www.maxmind.com EU:getmyip.co.uk US:www.getmyip.org :checkip.dyndns.org DE:131.220.6.26:80 208.78.70.70:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:15:28:00 | Win2K-f | 173.45.68.171 (XLHOST.COM): ENET INC, COLUMBUS, OHIO, US. (100Mbps) |
n/a | US:www.maxmind.com US:www.getmyip.org EU:getmyip.co.uk GB:www.vouchercodez.com :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 8 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:17:17:00 | Win2K-f | 152.48.222.12 (UNC.EDU): NORTH CAROLINA RESEARCH AND EDUCATION NETWORK, DURHAM, NORTH CAROLINA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:19:27:00 | Win2K-f | 70.184.154.68 (COX.NET): COX COMMUNICATIONS, YUKON, OKLAHOMA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:20:00 | WinXP | 110.12.207.151 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | EE:www.starman.ee US:microsoft.com FI:194.215.38.3:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:20:57:00 | Win2K-f | 76.88.13.127 (RR.COM): ROAD RUNNER HOLDCO LLC, SAN DIEGO, CALIFORNIA, US. (100Mbps) |
n/a | **:169.254.217.34:707 FI:194.215.38.3:80 EE:62.65.192.24:80 |
135 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:21:13:00 | Win2K-f | 202.78.146.124 (TELSTRACLEAR.NET): TELSTRACLEAR WELLINGTON CABLE CUSTOMERS, WELLINGTON, WELLINGTON, NZ. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
21:54:00 | Win2K-f | 118.69.213.68 (VSIONGLOBAL.COM): IP RANGE FOR XDSL IPTV FIXED PHONE SERVICE AT HCMC, VN. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk US:www.getmyip.org :checkip.dyndns.org US:67.15.94.80:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:22:04:00 | Win2K-f | 118.69.213.68 (VSIONGLOBAL.COM): IP RANGE FOR XDSL IPTV FIXED PHONE SERVICE AT HCMC, VN. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk US:www.getmyip.org :checkip.dyndns.org US:67.15.94.80:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |