Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:10:00 | WinXP | 112.197.74.32 (-): SAIGON TOURIST CABLE TELEVISION, VN. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | 5818023061 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:01:17:00 | Win2K-f | 180.69.178.138 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
83.133.119.206:65520 | LV:proxim.ircgalaxy.pl US:microsoft.com LV:ad.ghura.pl NL:mejac.com LV:91.188.59.199:80 |
135 | pcap | raw alerts ruleset |
irc http 132 lines |
Yeah : 1.8 profile |
none | summary tarball |
30 of 33 28 of 33 8 of 42 |
533d15b5ce NEW 58c343a8d8 NEW d30209b0ff NEW |
c67adf46e2 [0] none [0] none [none] |
ASM:Graph none:none none:none |
tElock| Armadillo| none|none |
lines=126 embedded dns lines=91 none |
trace trace none |
T:02:20:00 | Win2K-f | 70.60.120.187 (RR.COM): ROAD RUNNER HOLDCO LLC, BENICIA, CALIFORNIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:02:22:00 | WinXP | 64.178.152.65 (-): BONNYVILLE CPE, COLD LAKE, ALBERTA, CA. (DSL) |
62.193.249.122:3305 | FR:cx10man.weedns.com KR:fx010413.whyI.org FR:62.193.249.122:3305 |
135 | pcap | raw alerts ruleset |
irc 696 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 41 | ecfbf321d3 NEW |
none[none] | none:none |
none|none | none | none |
T:03:01:00 | Win2K-f | 175.112.222.177 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 41 33 of 33 |
8b41cb7a41 NEW 97fef473b9 NEW |
ef18d720f3 [0] ff4e7d6992[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=90 lines=64 embedded dns |
trace trace |
04:21:00 | WinXP | 121.121.32.206 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
35 of 35 | 9716d7995a NEW |
c3a5354b6f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
04:58:00 | Win2K-f | 81.89.210.94 (-): CROSSNET DSL NETWORK, YEREVAN, YEREVAN, AM. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org EU:getmyip.co.uk :checkip.dyndns.org DE:131.220.6.26:80 208.78.70.70:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:05:06:00 | Win2K-f | 81.89.210.94 (-): CROSSNET DSL NETWORK, YEREVAN, YEREVAN, AM. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:05:34:00 | WinXP | 151.81.5.56 (51-151.NET24.IT): IUNET-BNET, MILANO, LOMBARDIA, IT. (DIAL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:05:35:00 | WinXP | 122.146.80.131 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 80 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:05:56:00 | WinXP | 80.29.250.243 (-): TELEFONICA MOVILES ESPANA (NCC#2006042768), BILBAO, PAIS VASCO, ES. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | c05290bb06 NEW |
dddfe6a7fe [0] | ASM:Graph |
PolyEnE| | lines=68 | trace | |
T:06:43:00 | WinXP | 113.254.210.211 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:07:12:00 | WinXP | 115.165.81.67 (CATV02.ITSCOM.JP): ITS COMMUNICATIONS INC, KAWASAKI, KANAGAWA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:07:22:00 | Win2K-f | 174.116.49.56 (ROGERS.COM): ROGERS CABLE COMMUNICATIONS INC, ST. JOHN'S, NEWFOUNDLAND AND LABRADOR, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:46:00 | WinXP | 110.226.15.232 (59.AIRTELBROADBAND.IN): BHARTI AIRTEL LTD, GURGAON, HARYANA, IN. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:07:56:00 | WinXP | 189.14.132.233 (PLUGIN.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | 5818023061 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
07:56:00 | Win2K-f | 190.49.175.54 (COM.AR): TELEFONICA DE ARGENTINA, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org EU:getmyip.co.uk :checkip.dyndns.org 208.78.70.70:80 US:67.15.94.80:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:07:59:00 | WinXP | 115.165.43.212 (CATV02.ITSCOM.JP): ITS COMMUNICATIONS INC, TOKYO, TOKYO, JP. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:09:26:00 | Win2K-f | 72.187.106.67 (RR.COM): ROAD RUNNER HOLDCO LLC, NEW PORT RICHEY, FLORIDA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 37 of 39 |
1da4193446 NEW 6278c9374a NEW |
8a97c8536a [none] cc7aaf6ea9[none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:10:52:00 | Win2K-f | 70.60.198.40 (RR.COM): ROAD RUNNER HOLDCO LLC, MONROE, NORTH CAROLINA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:17:00 | Win2K-f | 71.136.17.68 (-): MILANO DESIGN, PLANO, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 85 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 33 33 of 33 |
73ce2b74da NEW 79c01ec060 NEW |
none[0] 1bfd34056c[0] |
none:none ASM:Graph |
Armadillo| tElock| |
lines=90 lines=64 embedded dns |
trace trace |
T:11:55:00 | Win2K-f | 63.246.125.200 (ALTUSCGI.NET): PRIVATE CABLE ISP SUBSCRIBER (GEORGETOWN SC MARKET), GEORGETOWN, SOUTH CAROLINA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:12:12:00 | WinXP | 99.194.217.37 (CENTURYTEL.NET): CENTURYTEL INTERNET HOLDINGS INC, HINESVILLE, GEORGIA, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:13:53:00 | Win2K-f | 99.224.140.190 (ROGERS.COM): ROGERS CABLE INC. FLFRD, NEPEAN, ONTARIO, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
15:41:00 | WinXP | 93.102.221.179 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, PT. (DSL) |
38.97.225.135:6667 | US:00.devoid.us :moscow-advokat.ru US:38.97.225.135:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
39 of 42 | 51fb2278f3 NEW |
none[none] | none:none |
none|none | none | none |
16:25:00 | Win2K-f | 94.102.11.237 (NI.NET.TR): NETINTERNET BILGISAYAR VE TELEKOMUNIKASYAN SAN. VE TIC. LTD. STI, TR. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:16:34:00 | Win2K-f | 94.102.11.237 (NI.NET.TR): NETINTERNET BILGISAYAR VE TELEKOMUNIKASYAN SAN. VE TIC. LTD. STI, TR. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:17:01:00 | WinXP | 79.163.106.50 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 5c6df5141d NEW |
none[none] | none:none |
none|none | none | none |
T:17:36:00 | WinXP | 121.120.95.66 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:17:58:00 | Win2K-f | 173.168.58.18 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:09:00 | Win2K-f | 70.75.67.81 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:20:06:00 | WinXP | 4.224.141.57 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, INDIANAPOLIS, INDIANA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:20:06:00 | WinXP | 72.190.71.58 (RR.COM): ROAD RUNNER HOLDCO LLC, LEWISVILLE, TEXAS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1008 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 41 | 682a384fe9 NEW |
none[3] | none:none |
none|none | none | trace | |
T:20:20:00 | WinXP | 4.227.2.4 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, VAN BUREN, ARKANSAS, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:21:03:00 | Win2K-f | 76.177.151.118 (RR.COM): ROAD RUNNER HOLDCO LLC, LONDON, KENTUCKY, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:04:00 | WinXP | 69.119.69.118 (OPTONLINE.NET): OPTIMUM ONLINE (CABLEVISION SYSTEMS), BRONX, NEW YORK, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:19:00 | WinXP | 121.120.25.192 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
21:37:00 | Win2K-f | 190.153.121.193 (NET-UNO.NET): NET UNO C.A, CARACAS, DISTRITO FEDERAL, VE. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk :www.vouchercodes.com US:www.getmyip.org :checkip.dyndns.org DE:131.220.6.26:80 208.78.70.70:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 43 lines |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 3862324588 NEW |
none[3] | none:none |
UPX| | none | trace |
T:21:45:00 | Win2K-f | 190.153.121.193 (NET-UNO.NET): NET UNO C.A, CARACAS, DISTRITO FEDERAL, VE. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 3862324588 NEW |
none[3] | none:none |
UPX| | none | trace |
T:22:56:00 | Win2K-f | 218.117.136.11 (BBTEC.NET): JAPAN NATION-WIDE NETWORK OF SOFTBANK BB CORP, KITAKYUSHU, FUKUOKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:58:00 | Win2K-f | 4.227.249.7 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, LOVELAND, COLORADO, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 95 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |