Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:09:00 | WinXP | 117.254.232.197 (STERLINGSTUDENTS.NET): NIB (NATIONAL INTERNET BACKBONE), NEW DELHI, DELHI, IN. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
00:42:00 | WinXP | 77.41.9.225 (QWERTY.RU): NEOCENTEL-HOME-HIMKI-LOBNYA, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
00:53:00 | WinXP | 117.254.232.197 (STERLINGSTUDENTS.NET): NIB (NATIONAL INTERNET BACKBONE), NEW DELHI, DELHI, IN. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:01:27:00 | Win2K-f | 180.229.72.81 (-): . |
91.188.59.12:65520 | US:microsoft.com DE:proxim.ircgalaxy.pl LV:ad.ghura.pl |
135 | pcap | raw alerts ruleset |
irc http 162 lines |
Yeah : 1.8 profile |
none | summary tarball |
5 of 41 0 of 32 |
725fde013b NEW d41d8cd98f NEW |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
T:01:40:00 | WinXP | 188.176.70.162 (DSL.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, DK. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:02:05:00 | WinXP | 59.120.228.224 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 52 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace | |
T:02:26:00 | WinXP | 79.36.253.98 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA NET, ROME, LAZIO, IT. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:03:23:00 | Win2K-f | 4.240.233.54 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, CORNVILLE, ARIZONA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 90 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:03:52:00 | WinXP | 83.68.71.230 (TNP.PL): TELENETCENTRUM-NET, WARSAW, WARSZAWA, PL. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:03:53:00 | WinXP | 218.191.176.153 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
62.193.249.122:3305 | JP:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 578 lines |
Yeah : 1.8 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:03:55:00 | Win2K-f | 113.252.202.63 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
5 of 41 0 of 32 |
33b7574975 NEW d41d8cd98f NEW |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
T:05:26:00 | Win2K-f | 175.112.55.181 (-): . |
83.133.119.206:65520 | US:microsoft.com LV:proxima.ircgalaxy.pl LV:ad.ghura.pl EU:agrofee.com FR:slzzcom.com FR:streq.cn CN:cao.iwillhavebigdick.com FR:mskla.com :in.7cy.net :in1.7cy.net FR:193.105.207.31:80 |
135 | pcap | raw alerts ruleset |
irc http 128 lines |
Yeah : 1.8 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:05:55:00 | Win2K-f | 85.107.26.27 (TTNET.NET.TR): TURK TELEKOM ADSL-ALCATEL, IZMIR, IZMIR, TR. (DSL) |
91.188.59.12:65520 | :budulay.net :in.7cy.net FR:mskla.com LV:proxima.ircgalaxy.pl LV:ad.ghura.pl FR:slzzcom.com CN:cao.iwillhavebigdick.com FR:streq.cn CN:fuck.iwillhavebigdick.com CN:exe.perfectexe.com CN:122.224.6.48:250 |
445 | pcap | raw alerts ruleset |
http irc 31 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:06:07:00 | WinXP | 115.81.103.219 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:06:23:00 | WinXP | 186.9.95.176 (IMOVIL.ENTELPCS.CL): ENTEL PCS TELECOMUNICACIONES S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
06:24:00 | WinXP | 115.81.103.219 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:07:22:00 | WinXP | 208.126.64.227 (NETINS.NET): BROOKLYN MUTUAL TELEPHONE CO, BROOKLYN, IOWA, US. (DSL) |
n/a | LV:irc.zief.pl US:gg.arrancar.org LV:ad.ghura.pl FR:slzzcom.com CN:cao.iwillhavebigdick.com FR:streq.cn FR:mskla.com :in.7cy.net CN:fuck.iwillhavebigdick.com CN:exe.perfectexe.com CN:122.224.6.48:250 174.123.157.154:80 GB:194.8.251.142:80 US:69.43.160.145:555 |
135 | pcap | raw alerts ruleset |
irc http 620 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:08:07:00 | Win2K-f | 173.168.31.101 (RR.COM): ROAD RUNNER HOLDCO LLC, TAMPA, FLORIDA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1003 lines |
Yeah : 1.3 profile |
none | summary tarball |
14 of 41 | 4d4075d6e9 NEW |
none[none] | none:none |
none|none | none | none | |
T:09:37:00 | Win2K-f | 122.105.133.34 (OPTUSNET.COM.AU): OPTUS INTERNET - RETAIL, SYDNEY, NEW SOUTH WALES, AU. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
2 of 36 0 of 32 |
af1ff397ee NEW d41d8cd98f NEW |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
10:13:00 | Win2K-f | 200.7.206.114 (CYBW.NET): OTECEL S.A, MACHALA, EL ORO, EC. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk :checkip.dyndns.org DE:131.220.6.26:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:10:22:00 | Win2K-f | 200.7.206.114 (CYBW.NET): OTECEL S.A, MACHALA, EL ORO, EC. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:11:03:00 | Win2K-f | 99.139.51.204 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, SAN LEANDRO, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:11:04:00 | WinXP | 117.254.116.250 (STERLINGSTUDENTS.NET): NIB (NATIONAL INTERNET BACKBONE), NEW DELHI, DELHI, IN. (DSL) |
213.155.0.224:80 | DE:proxim.ircgalaxy.pl DE:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http irc 4 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:11:21:00 | WinXP | 113.255.142.41 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HK. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:11:36:00 | WinXP | 92.84.114.194 (-): SMALL CUSTOMERS, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:11:41:00 | Win2K-f | 4.158.198.59 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, CHILTON, WISCONSIN, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 714 lines |
Yeah : 1.3 profile |
none | summary tarball |
7 of 41 | 3b7fc5125d NEW |
none[none] | none:none |
none|none | none | none | |
T:11:42:00 | WinXP | 79.165.72.30 (QWERTY.RU): BRAS E-320-38 DHCP-POOL, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:11:50:00 | WinXP | 80.232.250.124 (-): ADDRESS POOL FOR LTC-HOME CUSTOMERS, RIGA, RIGA, LV. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:12:20:00 | WinXP | 88.85.6.185 (-): VIDEO 2000 SA 2000 NEUCHATEL, NEUCHATEL, NEUCHATEL, CH. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:12:46:00 | Win2K-f | 173.29.250.187 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, CHANHASSEN, MINNESOTA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:13:14:00 | Win2K-f | 58.85.252.196 (ZAQ.NE.JP): J:COM WEST CO. LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 3 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:26:00 | WinXP | 4.174.209.58 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, VINELAND, NEW JERSEY, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:32:00 | Win2K-f | 24.79.89.29 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 123 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
15:16:00 | Win2K-f | 93.110.13.206 (-): LASER COMPANY LTD, IR. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:15:24:00 | Win2K-f | 93.110.13.206 (-): LASER COMPANY LTD, IR. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:17:19:00 | WinXP | 186.10.6.124 (IMOVIL.ENTELPCS.CL): ENTEL PCS TELECOMUNICACIONES S.A, CL. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:17:38:00 | WinXP | 4.137.81.182 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, MADISON, ALABAMA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 134 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:17:41:00 | WinXP | 4.225.164.211 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, MESQUITE, TEXAS, US. (DIAL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:18:20:00 | WinXP | 66.66.100.198 (RR.COM): ROAD RUNNER HOLDCO LLC, WEBSTER, NEW YORK, US. (DSL) |
n/a | :siliconfireware.ru :www.proxy-socks.net :wpad |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:18:26:00 | Win2K-f | 69.166.87.129 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:20:09:00 | WinXP | 180.71.180.2 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
83.133.119.206:65520 | CN:proxima.ircgalaxy.pl US:microsoft.com LV:ad.ghura.pl EU:afretroactive.com FR:slzzcom.com FR:streq.cn CN:cao.iwillhavebigdick.com FR:mskla.com :in.7cy.net :in1.7cy.net :redirect.hotkeys.com US:searchportal.information.com US:spi.domainsponsor.com US:204.13.161.51:80 |
135 | pcap | raw alerts ruleset |
irc http 159 lines |
Yeah : 1.8 profile |
none | summary tarball |
0 of 32 5 of 41 |
d41d8cd98f NEW d60da43c1a NEW |
none[3] none [none] |
ASM:Graph none:none |
none|none none|none |
lines=0 none |
trace none |
20:16:00 | WinXP | 186.10.151.65 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:20:40:00 | WinXP | 174.3.30.214 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CA. (DSL) |
n/a | US:gg.arrancar.org US:69.43.160.145:555 |
135 | pcap | raw alerts ruleset |
other 158 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:20:48:00 | WinXP | 201.69.89.246 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:21:33:00 | Win2K-f | 175.112.87.99 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:22:46:00 | Win2K-f | 173.168.31.101 (RR.COM): ROAD RUNNER HOLDCO LLC, TAMPA, FLORIDA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1002 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |