Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:26:00 | WinXP | 4.143.163.177 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, MINNEAPOLIS, MINNESOTA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 120 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 41 |
5af05bec2e NEW ff34a1caa4 NEW |
ec2138d5b2 [0] 979a6569d4[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
T:01:08:00 | WinXP | 203.81.201.145 (WORLDCALL.NET.PK): WORLDCALL MULTIMEDIA LTD, KARACHI, SINDH, PK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | a3c82ff952 NEW |
none[none] | none:none |
none|none | none | none |
T:01:26:00 | WinXP | 186.40.110.53 (E-CORPNET.ORG): TELEFONICA MOVIL DE CHILE S.A, CL. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 6455904435 NEW |
none[none] | none:none |
none|none | none | none |
T:03:21:00 | WinXP | 117.20.179.53 (-): STARHUB HSPA, SINGAPORE, SINGAPORE, SG. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 42 | 8a2553433c NEW |
none[none] | none:none |
none|none | none | none |
T:04:04:00 | WinXP | 188.173.59.76 (RIPE.NET): EUROPEAN REGIONAL REGISTRY, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 88f3393e20 NEW |
none[none] | none:none |
none|none | none | none |
T:04:52:00 | WinXP | 119.154.97.227 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, ISLAMABAD, ISLAMABAD, PK. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:05:41:00 | WinXP | 87.205.137.145 (INETIA.PL): INTERNETIA, PL. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 43 | 987c4ac702 NEW |
none[none] | none:none |
none|none | none | none |
T:07:04:00 | WinXP | 164.132.42.85 (-): IUNET S.P.A, MILANO, LOMBARDIA, IT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 95d1a78f0d NEW |
none[none] | none:none |
none|none | none | none |
T:07:20:00 | WinXP | 186.180.20.194 (-): . |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:08:25:00 | WinXP | 212.171.210.170 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A, ROME, LAZIO, IT. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:08:38:00 | WinXP | 186.180.80.10 (-): . |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 24137d8412 NEW |
73a916deb4 [0] | none:none |
PolyEnE| | none | trace |
T:09:09:00 | WinXP | 202.125.56.63 (CTT.NE.JP): CABLE TELEVISION TOYAMA INCORPORETED, TOYAMA, TOYAMA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:10:28:00 | WinXP | 208.88.70.103 (-): BBW 4 ACES TOWER CUSTOMER SUBNET, SHREVEPORT, LOUISIANA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:06:00 | WinXP | 208.3.14.71 (ARDMORE.NET): INTEGRITY ONLINE, ARDMORE, OKLAHOMA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 667 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 14 of 43 |
7ef9d19abe NEW b7fdcd329a NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
|
T:16:14:00 | WinXP | 188.73.204.25 (CAMPUSEAI.ORG): EUROPEAN REGIONAL REGISTRY, UK. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:17:15:00 | WinXP | 166.237.168.137 (MFGNW.COM): SERVICE PROVIDER CORPORATION, BEDMINSTER, NEW JERSEY, US. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:18:33:00 | WinXP | 184.74.74.92 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 85 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:19:24:00 | WinXP | 65.78.218.88 (WVFIBERNET.NET): FIBERNET, GRANTSVILLE, WEST VIRGINIA, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 43 | bf2aac9051 NEW |
none[none] | none:none |
none|none | none | none | |
T:22:11:00 | WinXP | 118.219.16.69 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
60.190.222.139:65520 | CN:proxima.ircgalaxy.pl US:microsoft.com CN:image.perfectexe.com CN:exe4.perfectexe.com EU:kdddaber.com EU:bestkind.ru EU:anotherdomainname.in :www.lddwj.com |
135 | pcap | raw alerts ruleset |
irc http 497 lines |
Yeah : 1.8 profile |
none | summary tarball |
17 of 42 42 of 43 28 of 42 5 of 43 0 of 42 34 of 36 29 of 32 29 of 43 25 of 42 none |
09aeb0e717 NEW 38501fdeb3 NEW 725c99b61d NEW 746fc23ab4 NEW 87e8ecb8a7 NEW 99b248336f NEW 9d677c3f70 NEW b34e640329 NEW cf056e2c90 NEW ef5a8c4985 NEW |
none[none] none [none] none [none] none [none] none [none] c64bd1a776[0] 77e75ff10f[0] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none ASM:Graph ASM:Graph none:none none:none none:none |
none|none none|none none|none none|none none|none Armadillo| tElock| none|none none|none none|none |
none none none none none lines=91 lines=120 embedded dns none none none |
none none none none none trace trace none none none |