Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:16:39:00 | WinXP | 69.193.74.22 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | EE:www.starman.ee EE:195.50.195.10:443 |
135 | pcap | raw alerts ruleset |
http 24 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:16:49:00 | WinXP | 173.168.58.239 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:17:00:00 | Win2K-f | 70.182.0.138 (COX.NET): COX COMMUNICATIONS, ANNANDALE, VIRGINIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 356 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 39 | ce28648035 NEW |
126d2f4655 [0] | ASM:Graph |
none|none | lines=546 | trace | |
T:17:34:00 | WinXP | 186.10.16.24 (IMOVIL.ENTELPCS.CL): ENTEL PCS TELECOMUNICACIONES S.A, CL. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | ef979a8dbc NEW |
cc39f5811f [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
T:17:57:00 | WinXP | 69.171.163.193 (-): CRICKET COMMUNICATIONS INC, FLORIDA, US. (DSL) |
n/a | EE:www.starman.ee EE:195.50.195.10:443 |
135 | pcap | raw alerts ruleset |
http 19 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:18:07:00 | WinXP | 209.163.118.196 (CORETEL.NET): CORETEL AMERICA INC, BALTIMORE, MARYLAND, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:18:09:00 | WinXP | 95.246.174.11 (BUSINESS.TELECOMITALIA.IT): TELECOM ITALIA WIRELINE SERVICES, ROME, LAZIO, IT. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:18:21:00 | Win2K-f | 194.19.234.252 (-): BTG, RIGA, RIGA, LV. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:28:00 | WinXP | 115.65.38.214 (WAKWAK.NE.JP): NTT-ME CORPORATION, TOKYO, TOKYO, JP. (DSL) |
n/a | EE:www.starman.ee FI:194.215.38.3:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:20:59:00 | WinXP | 112.203.15.150 (PLDT.NET): IPG, LAS PINAS CITY, MANILA, PH. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:21:19:00 | Win2K-f | 180.65.94.180 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
60.190.222.139:65520 | US:microsoft.com CN:proxima.ircgalaxy.pl MD:ad.ghura.pl CN:ku1.installstorm.com CN:down.installstorm.com US:sendinvest.com :findhobbits.com US:search.toptravellingtips.com US:search.articleswave.co.uk :www.searchour.com US:estimatedliability.com :nl.travelzip.co.uk :leftnor.com CA:fistpoker.info US:domainislam.com |
135 | pcap | raw alerts ruleset |
irc http 404 lines |
Yeah : 1.8 profile |
none | summary tarball |
0 of 41 27 of 41 17 of 41 13 of 41 6 of 41 39 of 41 31 of 33 20 of 41 |
0be234dd21 NEW 5c6c70b905 NEW 9405784738 NEW 9f5205c55e NEW ab0bc0267c NEW ab9c4b5f21 NEW d789c8d157 NEW e2a8c34ba9 NEW |
none[none] none [none] none [none] none [none] none [none] 5fe48b2dcc[0] 5f6572479f[0] none [none] |
none:none none:none none:none none:none none:none ASM:Graph ASM:Graph none:none |
none|none none|none none|none none|none none|none Armadillo| PolyEnE| none|none |
none none none none none lines=42 lines=113 embedded dns none |
none none none none none trace trace none |
T:21:32:00 | Win2K-f | 196.25.215.194 (CHOSEN.CO.ZA): AFRINIC, PRETORIA, GAUTENG, ZA. (DSL) |
n/a | US:geologsit.com US:images.smartname.com US:drugstoys.com US:search.musicforher.com :fr.travelzip.co.uk US:132.30.0.36:707 |
135 | pcap | raw alerts ruleset |
http irc 182 lines |
Argh : 0.3 profile |
none | summary tarball |
11 of 41 | 2b2cddb636 NEW |
none[none] | none:none |
none|none | none | none |
T:21:37:00 | WinXP | 172.130.212.50 (AOL.COM): AMERICA ONLINE, RESTON, VIRGINIA, US. (DSL) |
n/a | FI:194.215.38.3:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:22:03:00 | WinXP | 122.146.240.135 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:05:00 | Win2K-f | 95.24.70.238 (CORBINA.RU): INVESTELEKTROSVIAZ LTD, MOSCOW, MOSCOW CITY, RU. (DSL) |
60.190.222.139:65520 | US:search.biduplinks.co.uk US:search.smarturl.co.uk CN:down.installstorm.com CN:proxima.ircgalaxy.pl CN:ku1.installstorm.com US:microsoft.com |
445 | pcap | raw alerts ruleset |
http irc 73 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 41 | 9f5205c55e NEW |
none[none] | none:none |
none|none | none | none |
T:22:37:00 | WinXP | 117.39.101.122 (163DATA.COM.CN): CHINANET SHANXI(SN) PROVINCE NETWORK, BEIJING, BEIJING, CN. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 3ae357d17b NEW |
none[0] | none:none |
PolyEnE| | lines=73 | trace |
T:22:41:00 | WinXP | 114.206.8.57 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
83.133.119.206:65520 | CN:proxima.ircgalaxy.pl US:microsoft.com CN:ku1.installstorm.com CN:down.installstorm.com US:sendinvest.com :findhobbits.com US:search.toptravellingtips.com US:search.articleswave.co.uk :www.searchour.com :nl.travelzip.co.uk US:stockarab.com US:fluctuatingprice.com :www.backblogs.com :www.focusdrink.com :www.sellbloom.com :growonupon.info :halaesurance.info US:insurancehelpers.com US:incease.com US:landlday.com US:footballoil.com US:search.musicforher.com :fr.travelzip.co.uk :search.creativeblackandwhitephotography.com |
135 | pcap | raw alerts ruleset |
irc http 383 lines |
Yeah : 1.8 profile |
none | summary tarball |
31 of 33 27 of 41 31 of 33 13 of 41 18 of 41 13 of 41 0 of 41 20 of 41 |
168aab35a3 NEW 5c6c70b905 NEW 667f0c59f3 NEW 8ac0f64e91 NEW 9d17cbfc42 NEW 9f5205c55e NEW deae288e0e NEW e2a8c34ba9 NEW |
60b730b97e [0] none [none] 8fe2be2095[0] none [none] none [none] none [none] none [none] none [none] |
ASM:Graph none:none ASM:Graph none:none none:none none:none none:none none:none |
tElock| none|none Armadillo| none|none none|none none|none none|none none|none |
lines=120 embedded dns none lines=91 none none none none none |
trace none trace none none none none none |
T:22:43:00 | Win2K-f | 64.175.160.91 (PACBELL.NET): AT&T INTERNET SERVICES, CARLSBAD, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:23:38:00 | Win2K-f | 209.205.108.40 (CIPHERKEY.NET): CIPHERKEY EXCHANGE CORP, SURREY, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:23:58:00 | WinXP | 219.115.209.158 (ZAQ.NE.JP): J:COM WEST CO. LTD, TOYONAKA, OSAKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 18 of 35 |
07fabc79ef NEW 218ce30f5c NEW |
none[0] none [3] |
none:none none:none |
Armadillo| none|none |
lines=90 none |
trace trace |