Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:30:00 | WinXP | 121.120.0.40 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:01:05:00 | Win2K-f | 58.234.87.182, 173.192.153.178 (INVALID IPV4 ADDRESS): INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS. (INVALID IPV4 ADDRESS) |
60.190.222.139:65520 | DE:proxim.ircgalaxy.pl LV:ad.ghura.pl :sb.perfectexe.com LV:kdert.com CN:exe.perfectexe.com CN:2b.perfectexe.com CN:sb.iwillhavebigdick.com CN:3b.iwillhavebigdick.com :in.7cy.net 174.123.157.154:80 CN:222.170.127.203:88 |
139 | pcap | raw alerts ruleset |
irc http 144 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:01:15:00 | Win2K-f | 95.27.199.87 (CORBINA.NET): INVESTELEKTROSVIAZ LTD, RU. (DSL) |
n/a | US:netsunion.com US:www.hostmonster.com :www.google-analytics.com US:www.bhdefaultparking.com US:searchportal.information.com :cdn.dsultra.com US:domdex.com :b.collective-media.net :segment-pixel.invitemedia.com CA:idcs.interclick.com :ad.doubleclick.net US:ib.adnxs.com :a.collective-media.net US:64.210.61.208:80 CA:74.122.140.23:80 74.125.19.148:80 |
445 | pcap | raw alerts ruleset |
http 84 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:01:58:00 | Win2K-f | 123.212.118.163, 173.192.153.178 (INVALID IPV4 ADDRESS): INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS. (INVALID IPV4 ADDRESS) |
60.190.222.139:65520 | CN:proxima.ircgalaxy.pl US:microsoft.com LV:ad.ghura.pl :sb.perfectexe.com LV:kdert.com CN:exe.perfectexe.com CN:2b.perfectexe.com CN:sy2.perfectexe.com CN:122.224.6.48:255 DE:83.133.119.206:65520 |
135 | pcap | raw alerts ruleset |
irc http 145 lines |
Yeah : 1.8 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:02:31:00 | Win2K-f | 211.23.226.98, 173.192.153.178 (INVALID IPV4 ADDRESS): INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS. (INVALID IPV4 ADDRESS) |
n/a | :in.7cy.net :in1.7cy.net CN:sb.iwillhavebigdick.com CN:3b.iwillhavebigdick.com CN:sy3.perfectexe.com US:infromer.com US:searchportal.information.com :cdn.dsultra.com US:domdex.com US:ads1.revenue.net US:panther1.cpxinteractive.com :ad.doubleclick.net :b.collective-media.net :segment-pixel.invitemedia.com CA:idcs.interclick.com :ads.undertone.com US:ib.adnxs.com CA:osmdcs.interclick.com :a.collective-media.net US:content.pulse360.com US:hubmodems.net US:book-hunters.net :diamondsarts.info |
135 | pcap | raw alerts ruleset |
irc http 167 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:02:33:00 | WinXP | 119.234.198.168 (-): SINGTEL MOBILE, SG. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:02:35:00 | WinXP | 115.165.82.69 (CATV02.ITSCOM.JP): ITS COMMUNICATIONS INC, KAWASAKI, KANAGAWA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:03:23:00 | WinXP | 72.187.106.67 (RR.COM): ROAD RUNNER HOLDCO LLC, NEW PORT RICHEY, FLORIDA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:03:45:00 | Win2K-f | 113.254.148.228 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | CN:proxima.ircgalaxy.pl US:microsoft.com CN:60.190.222.139:65520 DE:83.133.119.206:65520 |
135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:04:34:00 | Win2K-f | 166.164.114.223 (MYVZW.COM): SERVICE PROVIDER CORPORATION, CHARLES CITY, IOWA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:04:48:00 | WinXP | 112.197.11.14 (-): SAIGON TOURIST CABLE TELEVISION, VN. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:04:50:00 | WinXP | 118.83.4.88 (HTOJ.J-CNET.JP): JCN-HTMNET, HACHIOJI, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 122 lines |
Yeah : 1.3 profile |
none | summary tarball |
none 0 of 32 |
238d13b01e NEW d41d8cd98f NEW |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
T:04:51:00 | Win2K-f | 61.198.101.132 (THN.NE.JP): TOKAI CORPORATION, FUJI, SHIZUOKA, JP. (DSL) |
210.127.253.90:3305 | IT:cx10man.weedns.com FR:fx010413.whyI.org KR:gynoman.weedns.com KR:g.0x20.biz :c010x1.co.cc :commgr.co.cc KR:telephone.dd.blueline.be 114.207.244.143:3305 FR:62.193.249.122:3305 |
135 | pcap | raw alerts ruleset |
irc 695 lines |
Yeah : 1.8 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:05:56:00 | WinXP | 64.33.132.26 (AIRSTREAMCOMM.NET): TRI COUNTY TELEPHONE, WISCONSIN, US. (DIAL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:06:37:00 | WinXP | 178.92.183.179 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:07:21:00 | WinXP | 121.121.3.143 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:07:37:00 | WinXP | 88.85.19.90 (NET2000.CH): BROADBAND CUSTOMER, NEUCHATEL, NEUCHATEL, CH. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
08:59:00 | Win2K-f | 200.71.99.192 (COLDECON.COM): COLDECON, CALI, VALLE DEL CAUCA, CO. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk :www.getmyip.org US:checkip.dyndns.org US:67.15.94.80:80 EU:78.40.35.134:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:10:04:00 | WinXP | 70.126.154.4 (RR.COM): ROAD RUNNER HOLDCO LLC, BRADENTON, FLORIDA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
2 of 36 0 of 32 |
ca832de942 NEW d41d8cd98f NEW |
none[3] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
trace trace |
T:10:35:00 | WinXP | 151.81.181.237 (51-151.NET24.IT): IUNET-BNET, IT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:12:25:00 | WinXP | 89.152.114.74 (CPE.NETCABO.PT): TVCABO-PORTUGAL CABLE MODEM NETWORK, PT. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:05:00 | WinXP | 174.39.241.97 (WINDSTREAM.NET): ALLTEL MIP CUSTOMERS - OMAHA, YORK, NEBRASKA, US. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:13:11:00 | WinXP | 208.34.236.169 (ESINC.NET): ELECTRONIC SOLUTION INC, ROXBORO, NORTH CAROLINA, US. (DSL) |
n/a | :siliconfireware.ru RU:www.bbin.ru RU:www.binbank.ru :wpad |
445 | pcap | raw alerts ruleset |
http http 22 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:14:00:00 | Win2K-f | 173.171.122.246 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
62.193.249.122:3305 | EU:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 607 lines |
Yeah : 1.8 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:14:29:00 | WinXP | 174.39.229.87 (WINDSTREAM.NET): ALLTEL MIP CUSTOMERS - OMAHA, SCHUYLER, NEBRASKA, US. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
15:03:00 | WinXP | 174.39.229.87 (WINDSTREAM.NET): ALLTEL MIP CUSTOMERS - OMAHA, SCHUYLER, NEBRASKA, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
15:41:00 | Win2K-f | 200.125.73.97 (200.IN-ADDR.ARPA): TELECENTRO S.A. - CLIENTES RESIDENCIALES, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | US:www.maxmind.com :www.getmyip.org EU:checkip.dyndns.org US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:15:50:00 | Win2K-f | 200.125.73.97 (200.IN-ADDR.ARPA): TELECENTRO S.A. - CLIENTES RESIDENCIALES, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk :www.vouchercodes.com :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 44 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:15:54:00 | Win2K-f | 4.167.93.62 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, NEW ORLEANS, LOUISIANA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 126 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:16:07:00 | WinXP | 173.168.81.7 (RR.COM): ROAD RUNNER HOLDCO LLC, LUTZ, FLORIDA, US. (DSL) |
62.193.249.122:3305 | FR:cx10man.weedns.com JP:fx010413.whyI.org FR:62.193.249.122:3305 |
135 | pcap | raw alerts ruleset |
irc 607 lines |
Yeah : 1.8 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
16:22:00 | WinXP | 201.93.91.180 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:16:43:00 | Win2K-f | 60.249.37.247 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:18:14:00 | Win2K-f | 216.210.87.84 (SPEAKEASY.NET): US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:18:21:00 | Win2K-f | 122.196.16.65 (ZAQ.NE.JP): J:COM WEST CO. LTD, OSAKA, OSAKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:21:09:00 | Win2K-f | 175.115.103.112 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 232 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:21:29:00 | Win2K-f | 4.164.213.173 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, LAS VEGAS, NEVADA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
21:31:00 | WinXP | 69.85.144.120 (O1.COM): O1.COM, SAN DIEGO, CALIFORNIA, US. (DIAL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:21:51:00 | Win2K-f | 116.122.234.33 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:microsoft.com DE:proxim.ircgalaxy.pl CN:60.190.222.139:65520 DE:83.133.119.206:65520 |
135 | pcap | raw alerts ruleset |
other 174 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:22:06:00 | WinXP | 66.60.106.38 (FIRSTDIGITAL.COM): FIRSTDIGITAL COMMUNICATIONS LLC, ROSEVILLE, CALIFORNIA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
none 0 of 32 |
19ca92cb15 NEW d41d8cd98f NEW |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
T:22:25:00 | WinXP | 71.49.163.107 (EMBARQHSD.NET): EMBARQ CORPORATION, HUMBLE, TEXAS, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:22:26:00 | Win2K-f | 61.205.153.136 (ZAQ.NE.JP): J:COM WEST CO. LTD, OSAKA, OSAKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:22:39:00 | WinXP | 97.89.9.121 (CHARTER.COM): CHARTER COMMUNICATIONS, MCDONOUGH, GEORGIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f NEW |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:23:30:00 | WinXP | 79.163.60.141 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:23:44:00 | WinXP | 98.102.100.133 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 11 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |