Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:15:00 | WinXP | 121.121.229.109 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:00:34:00 | WinXP | 213.66.164.142 (TELIA.COM): TELIA NETWORK SERVICES, DANDERYD, STOCKHOLMS LAN, SE. (DSL) |
n/a | :siliconfireware.ru :www.proxy-socks.net :wpad GB:welcome3.smile.co.uk GB:195.92.84.198:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 6c21e2c88b NEW |
none[none] | none:none |
none|none | none | none |
T:00:54:00 | Win2K-f | 60.250.190.187 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1000 lines |
Yeah : 1.3 profile |
none | summary tarball |
6 of 42 | ccdecb6417 NEW |
none[none] | none:none |
none|none | none | none | |
T:01:22:00 | Win2K-f | 61.218.205.52 (HINET.NET): TAIWAN PROVINCE TAP-WATER CO. LTD, KAOHSIUNG, T'AI-WAN, TW. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:01:34:00 | WinXP | 99.165.194.239 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:02:37:00 | WinXP | 188.176.70.119 (DSL.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, DK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:03:05:00 | Win2K-f | 60.248.116.212 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:04:32:00 | Win2K-f | 112.206.119.63 (PLDT.NET): IPG, PH. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1023 lines |
Yeah : 1.3 profile |
none | summary tarball |
20 of 42 | 9809a6f3eb NEW |
none[none] | none:none |
none|none | none | none | |
T:05:36:00 | WinXP | 121.120.231.197 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:06:30:00 | WinXP | 201.69.155.137 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 7a10f959b5 NEW |
none[none] | none:none |
none|none | none | none |
06:58:00 | Win2K-f | 200.71.99.192 (COLDECON.COM): COLDECON, CALI, VALLE DEL CAUCA, CO. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:07:06:00 | Win2K-f | 200.71.99.192 (COLDECON.COM): COLDECON, CALI, VALLE DEL CAUCA, CO. (DSL) |
n/a | US:www.maxmind.com :www.getmyip.org EU:getmyip.co.uk :www.vouchercodes.com US:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 44 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
07:11:00 | Win2K-f | 116.111.166.84 (USER10-17.ENET.VN): ELECTRIC TELECOMMUNICATION COMPANY, HO CHI MINH CITY, HO CHI MINH, VN. (DSL) |
n/a | US:www.maxmind.com :www.getmyip.org EU:getmyip.co.uk :www.vouchercodes.com EU:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 44 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:07:20:00 | Win2K-f | 116.111.166.84 (USER10-17.ENET.VN): ELECTRIC TELECOMMUNICATION COMPANY, HO CHI MINH CITY, HO CHI MINH, VN. (DSL) |
n/a | US:www.maxmind.com :www.getmyip.org :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:07:52:00 | WinXP | 93.102.128.70 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, COIMBRA, COIMBRA, PT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | ba1a7eaa9a NEW |
none[none] | none:none |
none|none | none | none |
T:07:55:00 | WinXP | 121.121.186.40 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:08:11:00 | WinXP | 75.36.138.241 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, HAYWARD, CALIFORNIA, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
08:36:00 | WinXP | 92.115.193.24 (HOST-STATIC-92-115-28-10.MOLDTELECOM.MD): JSC MOLDTELECOM SA, CHISINAU, CHISINAU, MD. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:10:13:00 | Win2K-f | 122.149.81.211 (DODO.COM.AU): LAYER 2 BROADBAND CUSTOMER NETWORK, AU. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:03:00 | WinXP | 180.177.156.148 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:11:04:00 | WinXP | 69.193.68.239 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
11:11:00 | WinXP | 180.177.156.148 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:11:59:00 | Win2K-f | 174.6.140.142 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, VANCOUVER, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 189 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 39 | ffaaa273f1 NEW |
none[none] | none:none |
none|none | none | none | |
14:51:00 | WinXP | 66.81.171.128 (O1.COM): O1 DIALUP SERVICES, AUBURN, CALIFORNIA, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:15:04:00 | WinXP | 80.104.111.10 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A, UDINE, FRIULI-VENEZIA GIULIA, IT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:15:24:00 | WinXP | 186.10.7.159 (IMOVIL.ENTELPCS.CL): ENTEL PCS TELECOMUNICACIONES S.A, CL. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:15:26:00 | Win2K-f | 64.175.160.91 (PACBELL.NET): AT&T INTERNET SERVICES, CARLSBAD, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:15:39:00 | WinXP | 219.115.231.184 (ZAQ.NE.JP): K CABLE TELEVISION CORPORATION INC, OSAKA, OSAKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
none:none ASM:Graph |
Armadillo| tElock| |
lines=90 lines=75 embedded dns |
trace trace |
T:15:56:00 | WinXP | 87.103.37.231 (REV.VODAFONE.PT): VODAFONE PORTUGAL, PT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | c977438fd7 NEW |
none[none] | none:none |
none|none | none | none |
T:16:17:00 | Win2K-f | 116.126.210.2, 173.192.153.178 (INVALID IPV4 ADDRESS): INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS. (INVALID IPV4 ADDRESS) |
83.133.119.206:65520 | CN:proxima.ircgalaxy.pl US:microsoft.com :sb.perfectexe.com CN:exe.perfectexe.com CN:2b.perfectexe.com CN:sy2.perfectexe.com CN:sb.iwillhavebigdick.com CN:122.224.6.48:10167 |
135 | pcap | raw alerts ruleset |
irc http 278 lines |
Yeah : 1.8 profile |
none | summary tarball |
25 of 41 35 of 40 35 of 41 28 of 41 25 of 40 34 of 39 39 of 41 31 of 33 |
36bb7118f0 NEW 76d11b0ccc NEW 77fdf452dd NEW 8bf141d254 NEW 94ad543e34 NEW 9b5bd50972 NEW ab9c4b5f21 NEW d789c8d157 NEW |
none[none] none [none] none [none] none [none] none [none] none [none] 5fe48b2dcc[0] 5f6572479f[0] |
none:none none:none none:none none:none none:none none:none ASM:Graph ASM:Graph |
none|none none|none none|none none|none none|none none|none Armadillo| PolyEnE| |
none none none none none none lines=42 lines=113 embedded dns |
none none none none none none trace trace |
T:16:31:00 | Win2K-f | 76.236.180.105 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, GRAND RAPIDS, MICHIGAN, US. (DSL) |
n/a | :in.7cy.net :in1.7cy.net |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 40 | 7a1846f88c NEW |
none[none] | none:none |
none|none | none | none |
T:17:21:00 | Win2K-f | 173.170.67.239 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | a4497aa84e NEW |
d1b46a6ff9 [0] | ASM:Graph |
none|none | lines=546 | trace | |
17:59:00 | WinXP | 119.234.145.63 (-): SINGTEL MOBILE, SINGAPORE, SINGAPORE, SG. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:18:38:00 | Win2K-f | 4.191.47.51 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, ALBANY, OREGON, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 173 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 36 of 40 |
47d3548e36 NEW d8722af110 NEW |
ab13346633 [0] ab30a55931[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:20:15:00 | WinXP | 75.50.252.248 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, MILWAUKEE, WISCONSIN, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | 03f912899b NEW |
none[0] | none:none |
none|none | lines=64 | trace | |
T:20:42:00 | Win2K-f | 174.3.49.218 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 158 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 39 | 2e8bb50e90 NEW |
none[none] | none:none |
none|none | none | none | |
20:58:00 | WinXP | 90.137.144.162 (TELE2.HR): TELE2 INTERNET PROVIDER, HR. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:21:03:00 | Win2K-f | 99.153.105.77 (PACBELL.NET): AT&T INTERNET SERVICES, HOUSTON, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:21:10:00 | WinXP | 70.68.156.221 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, COQUITLAM, BRITISH COLUMBIA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:43:00 | Win2K-f | 72.187.106.67 (RR.COM): ROAD RUNNER HOLDCO LLC, NEW PORT RICHEY, FLORIDA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 37 of 39 |
1da4193446 NEW 6278c9374a NEW |
8a97c8536a [none] cc7aaf6ea9[none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:21:55:00 | WinXP | 27.97.22.186 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 8015c2d45f NEW |
749cbc2739 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:22:06:00 | WinXP | 121.120.128.71 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:22:29:00 | Win2K-f | 175.113.47.207 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 41 33 of 33 |
8b41cb7a41 NEW 97fef473b9 NEW |
ef18d720f3 [0] ff4e7d6992[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=90 lines=64 embedded dns |
trace trace |
T:22:35:00 | WinXP | 119.234.51.165 (-): SINGTEL MOBILE, SINGAPORE, SINGAPORE, SG. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 | 74411e8ce8 NEW |
none[none] | none:none |
none|none | none | none |
T:22:58:00 | Win2K-f | 4.226.132.245 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, HOUSTON, TEXAS, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 130 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 | a08f3b74a4 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:23:47:00 | Win2K-f | 112.203.246.246 (PLDT.NET): IPG, PH. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 341 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | 3ff6383287 NEW |
none[none] | none:none |
none|none | none | none |