Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:05:00 | WinXP | 61.62.22.89 (SO-NET.NET.TW): SONY NETWORK TAIWAN LIMITED, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:03:57:00 | WinXP | 119.234.196.139 (-): SINGTEL MOBILE, SG. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:04:07:00 | WinXP | 151.81.170.192 (51-151.NET24.IT): IUNET-BNET, IT. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:04:46:00 | WinXP | 61.62.63.98 (SO-NET.NET.TW): SONY NETWORK TAIWAN LIMITED, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:06:36:00 | Win2K-f | 96.8.150.85 (GVTC.COM): GUADALUPE VALLEY TELEPHONE COOPERATIVE INC, NEW BRAUNFELS, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
5 of 41 0 of 32 |
a0806dc832 NEW d41d8cd98f NEW |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
T:06:59:00 | WinXP | 79.19.255.197 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA NET, ROME, LAZIO, IT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:08:09:00 | WinXP | 111.188.139.251 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:08:53:00 | WinXP | 89.194.103.160 (-): ORANGE HIGH SPEED INTERNET, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:08:54:00 | Win2K-f | 125.4.244.103 (ZAQ.NE.JP): J:COM WEST CO. LTD, TOKYO, TOKYO, JP. (DSL) |
62.193.249.122:3305 | JP:cx10man.weedns.com FR:fx010413.whyI.org KR:gynoman.weedns.com FR:62.193.249.122:3305 |
135 | pcap | raw alerts ruleset |
irc 695 lines |
Yeah : 1.8 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
10:13:00 | WinXP | 71.100.197.171 (VERIZON.NET): VERIZON INTERNET SERVICES INC, LAKELAND, FLORIDA, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:11:37:00 | Win2K-f | 174.1.204.53 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 893 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace | |
T:13:06:00 | WinXP | 61.218.191.251 (-): LIAN HONG BUSINESS CO. LTD, TAIPEI, T'AI-PEI, TW. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
5 of 41 0 of 32 |
836a29bbae NEW d41d8cd98f NEW |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
T:13:35:00 | WinXP | 203.193.135.11 (SOFT.NET): SOFTWARE TECHNOLOGY PARKS OF INDIA, PONDICHERRY, PONDICHERRY, IN. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:13:59:00 | WinXP | 186.9.204.124 (IMOVIL.ENTELPCS.CL): ENTEL PCS TELECOMUNICACIONES S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:14:25:00 | WinXP | 222.149.123.147 (OCN.NE.JP): OPEN COMPUTER NETWORK, HIROSHIMA, HIROSHIMA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:15:49:00 | Win2K-f | 4.136.108.166 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, ATLANTA, GEORGIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 853 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace | |
T:15:52:00 | Win2K-f | 218.119.176.169 (BBTEC.NET): JAPAN NATION-WIDE NETWORK OF SOFTBANK BB CORP, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 79 lines |
Yeah : 1.3 profile |
none | summary tarball |
2 of 40 0 of 32 |
106fcb5aec NEW d41d8cd98f NEW |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
T:16:32:00 | Win2K-f | 4.152.243.156 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, ASHEVILLE, NORTH CAROLINA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 171 lines |
Yeah : 1.3 profile |
none | summary tarball |
5 of 41 0 of 32 |
14bd26c63b NEW d41d8cd98f NEW |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
16:41:00 | WinXP | 115.81.165.145 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:16:53:00 | Win2K-f | 113.255.184.149 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HK. (DSL) |
70.107.249.167:7000 | US:dns.aswend.com | 135 | pcap | raw alerts ruleset |
irc 468 lines |
Yeah : 1.8 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:18:01:00 | WinXP | 219.105.117.95 (ADACHI.NE.JP): CABLE TELEVISION ADACHI CORP, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:19:29:00 | WinXP | 186.9.24.209 (IMOVIL.ENTELPCS.CL): ENTEL PCS TELECOMUNICACIONES S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:19:54:00 | WinXP | 211.25.206.162 (TIME.NET.MY): TIME TELECOMMUNICATIONS SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
62.193.249.122:3305 | IT:httpw.cz.cc | 135 | pcap | raw alerts ruleset |
irc 697 lines |
Yeah : 1.8 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:20:08:00 | WinXP | 118.86.78.50 (ODWR.J-CNET.JP): ODAWARA CABLETV INTERNET SERVICE, ODAWARA, KANAGAWA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 122 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:20:28:00 | WinXP | 4.242.174.230 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, PORTLAND, OREGON, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 156 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace | |
T:20:54:00 | Win2K-f | 216.188.245.13 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS WACO HUB, WACO, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:22:03:00 | Win2K-f | 70.166.136.154 (COX.NET): COX COMMUNICATIONS, SPRINGDALE, ARKANSAS, US. (DSL) |
60.190.222.139:65520 | US:microsoft.com DE:proxim.ircgalaxy.pl :ghucom.com |
135 | pcap | raw alerts ruleset |
irc http 138 lines |
Yeah : 1.8 profile |
none | summary tarball |
0 of 32 none |
d41d8cd98f NEW e1517a73de NEW |
none[3] none [none] |
ASM:Graph none:none |
none|none none|none |
lines=0 none |
trace none |
T:22:05:00 | WinXP | 151.83.171.161 (SER-PR2-MAX.IUNET.IT): INFOSTRADA, IT. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:22:26:00 | Win2K-f | 95.28.39.68 (CORBINA.RU): INVESTELEKTROSVIAZ LTD, MOSCOW, MOSCOW CITY, RU. (100Mbps) |
83.133.119.206:65520 | DE:proxim.ircgalaxy.pl | 445 | pcap | raw alerts ruleset |
irc 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:23:35:00 | WinXP | 4.153.67.170 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, COLUMBIA, TENNESSEE, US. (DIAL) |
n/a | :siliconfireware.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:23:45:00 | WinXP | 114.48.87.122 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |