Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:02:13:00 | WinXP | 77.254.84.215 (INETIA.PL): INTERNETIA, SZCZECIN, ZACHODNIOPOMORSKIE, PL. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 2b9bc1463d NEW |
7978e0f6fb [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:02:16:00 | Win2K-f | 211.215.180.246 (HANANET.NET): HANARO TELECOM INC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
83.133.119.206:65520 | DE:proxim.ircgalaxy.pl CN:ku1.installstorm.com US:sendinvest.com US:findhobbits.com CN:sky.installstorm.com CN:test.installstorm.com :xz.ub9.net :in.7cy.net US:search.toptravellingtips.com US:search.articleswave.co.uk :www.searchour.com :nl.travelzip.co.uk US:otherbudget.com :www.backblogs.com :www.focusdrink.com US:8.5.1.45:8392 |
139 | pcap | raw alerts ruleset |
irc http 270 lines |
Yeah : 1.3 profile |
none | summary tarball |
17 of 40 0 of 40 25 of 40 37 of 40 34 of 40 26 of 40 14 of 40 21 of 40 |
40fa21a42b NEW 4620e81f19 NEW 499936bbb0 NEW 55c3df1817 NEW 72e3100fa7 NEW 7577dd1d67 NEW 981b2b06d5 NEW de0a6d9482 NEW |
none[none] none [none] none [none] none [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none none|none none|none none|none |
none none none none none none none none |
none none none none none none none none |
02:27:00 | WinXP | 211.215.180.246 (HANANET.NET): HANARO TELECOM INC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
60.190.222.139:65520 | CN:ku1.installstorm.com CN:222.170.127.203:88 |
139 | pcap | raw alerts ruleset |
irc 24 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:02:54:00 | Win2K-f | 202.68.165.100 (SPECTRUM.COM.AU): MULTI HOMED MULTI PEERED INTERNET AND DATA, SYDNEY, NEW SOUTH WALES, AU. (DSL) |
n/a | :www.confisy.com US:tianwebs.257.asklots.com US:www.yourretaildepot.com CA:media.yourretaildepot.com CA:media.oranges88.com US:sendinvest.com US:search.thefreewebsitedirectory.co.uk :parkems.com US:8.5.1.45:8392 |
445 | pcap | raw alerts ruleset |
http irc http 47 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:06:19:00 | Win2K-f | 119.228.174.101 (EONET.NE.JP): K-OPTICOM CORPORATION, KOBE, HYOGO, JP. (DSL) |
n/a | US:microsoft.com US:trafficconverter.biz FI:194.215.38.3:80 US:204.152.184.139:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
irc http 14 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:06:34:00 | Win2K-f | 218.220.250.30 (ZAQ.NE.JP): J:COM WEST CO. LTD, OSAKA, OSAKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:45:00 | Win2K-f | 173.31.104.245 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, MIDDLETOWN, NEW YORK, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 40 |
474acf88e5 NEW 68f0c14692 NEW |
1f53944b24 [0] ccc1b24d53[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
T:08:39:00 | Win2K-f | 70.182.0.19 (COX.NET): COX COMMUNICATIONS, ANNANDALE, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:08:46:00 | WinXP | 202.183.52.54 (-): TOWNKANZAKI, KANZAKI, SAGA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:10:50:00 | WinXP | 69.193.68.239 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:12:54:00 | WinXP | 71.101.50.69 (VERIZON.NET): VERIZON INTERNET SERVICES INC, WINTER HAVEN, FLORIDA, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:12:54:00 | WinXP | 65.27.58.251 (RR.COM): ROAD RUNNER HOLDCO LLC, KANSAS CITY, MISSOURI, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 3ae357d17b NEW |
none[0] | none:none |
PolyEnE| | lines=73 | trace |
T:13:38:00 | WinXP | 75.24.90.190 (SBCGLOBAL.NET): K Q E D INC ATTN, PLANO, TEXAS, US. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:194.215.38.3:80 EE:195.50.195.10:443 |
135 | pcap | raw alerts ruleset |
http 10 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:14:33:00 | WinXP | 78.58.93.97 (ZEBRA.LT): LIETUVOS, VILNIUS, VILNIAUS APSKRITIS, LT. (DSL) |
n/a | EE:www.starman.ee FI:194.215.38.3:80 EE:195.50.195.10:443 |
135 | pcap | raw alerts ruleset |
http 12 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:14:45:00 | WinXP | 65.27.58.251 (RR.COM): ROAD RUNNER HOLDCO LLC, KANSAS CITY, MISSOURI, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 3ae357d17b NEW |
none[0] | none:none |
PolyEnE| | lines=73 | trace |
T:15:04:00 | WinXP | 207.5.200.227 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 84 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
15:13:00 | Win2K-f | 190.3.87.236 (TECHTELNET.NET): TECHTEL LMDS COMUNICACIONES INTERACTIVAS S.A, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:15:18:00 | WinXP | 72.128.22.28 (RR.COM): ROAD RUNNER HOLDCO LLC, KANSAS CITY, KANSAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:19:03:00 | WinXP | 68.250.129.231 (AMERITECH.NET): AT&T INTERNET SERVICES, CLEVELAND, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:19:37:00 | Win2K-f | 218.211.147.131 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:03:00 | WinXP | 64.188.192.125 (-): WINDJAMMER COMMUNICATIONS LLC, BOSTON, MASSACHUSETTS, US. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |