Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:02:50:00 | WinXP | 119.239.175.160 (MESH.AD.JP): NEC BIGLOBE LTD, TAKAMATSU, KAGAWA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:03:58:00 | Win2K-f | 70.74.243.33 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, EDMONTON, ALBERTA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 222 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 38 of 41 |
4180c19d91 NEW b6e91e001c NEW |
9f3f2de385 [0] d2275a6cf5[0] |
ASM:Graph ASM:Graph |
Armadillo| PolyEnE| |
lines=91 lines=64 embedded dns |
trace trace |
T:04:04:00 | Win2K-f | 70.184.9.121 (COX.NET): COX COMMUNICATIONS, SMITHFIELD, RHODE ISLAND, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1006 lines |
Yeah : 1.3 profile |
none | summary tarball |
17 of 41 | e4c1082a0d NEW |
none[none] | none:none |
none|none | none | none | |
T:04:24:00 | Win2K-f | 173.200.73.19 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:05:12:00 | WinXP | 187.80.105.44 (CAMPUSEAI.ORG): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 887b302405 NEW |
none[none] | none:none |
none|none | none | none |
T:06:04:00 | WinXP | 151.81.106.201 (51-151.NET24.IT): IUNET-BNET, IT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 42 | 33ffb2cb88 NEW |
none[none] | none:none |
none|none | none | none |
T:06:11:00 | WinXP | 121.121.228.242 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | b269b15ffd NEW |
none[none] | none:none |
none|none | none | none |
T:06:42:00 | WinXP | 78.55.114.45 (ALICEDSL.DE): HANSENET-ADSL, DORTMUND, NORDRHEIN-WESTFALEN, DE. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 500518ab72 NEW |
none[none] | none:none |
none|none | none | none |
T:06:58:00 | WinXP | 59.117.182.3 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 1096ba143e NEW |
none[none] | none:none |
none|none | none | none |
07:20:00 | WinXP | 78.55.114.45 (ALICEDSL.DE): HANSENET-ADSL, DORTMUND, NORDRHEIN-WESTFALEN, DE. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | 500518ab72 NEW |
none[none] | none:none |
none|none | none | none |
T:07:33:00 | Win2K-f | 216.188.238.56 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS WACO HUB, WACO, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:08:50:00 | WinXP | 211.133.210.178 (THN.NE.JP): TOKAI CORPORATION, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 40 of 41 |
71e6f60517 NEW ab4e3226c4 NEW |
1ef1781501 [0] c2d0313e73[0] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=91 none |
trace trace |
T:09:22:00 | Win2K-f | 118.219.28.189 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
60.190.222.139:65520 | US:microsoft.com DE:proxima.ircgalaxy.pl CN:lb.perfectexe.com EU:www.derquda.com CN:dick.perfectexe.com CN:hn.yigeyuming.com :a.95622.com :1.95622.com :historiceffort.com US:i.nuseek.com :search.dmtracker.com CN:2b.perfectexe.com CN:122.224.6.164:82 CN:222.170.127.203:88 EU:91.193.194.114:80 |
135 | pcap | raw alerts ruleset |
irc http 190 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 42 34 of 36 29 of 32 29 of 43 24 of 42 |
8809b6417c NEW 99b248336f NEW 9d677c3f70 NEW b34e640329 NEW c413ca56c4 NEW |
none[none] c64bd1a776[0] 77e75ff10f[0] none [none] none [none] |
none:none ASM:Graph ASM:Graph none:none none:none |
none|none Armadillo| tElock| none|none none|none |
none lines=91 lines=120 embedded dns none none |
none trace trace none none |
T:10:02:00 | WinXP | 113.210.30.136 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, MY. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:10:08:00 | Win2K-f | 95.135.214.113 (UKRTEL.NET): UKRTELECOM, KIEV, KYYIV, UA. (DSL) |
n/a | US:educationofusa.com :www.elearners.com :educationdynamics.122.2o7.net :freecomputergames.com 208.87.33.150:80 CN:222.170.127.203:88 |
445 | pcap | raw alerts ruleset |
http 197 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:10:22:00 | WinXP | 121.120.79.132 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:10:39:00 | WinXP | 79.163.248.105 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, KATOWICE, SLASKIE, PL. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:11:29:00 | Win2K-f | 64.179.173.118 (IW.NET): PRAIRIEWAVE CABLE MODEM DHCP, YANKTON, SOUTH DAKOTA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 40 |
67f1a33096 NEW 724cf0dc37 NEW |
148e04eaab [0] 901dd267d4[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:11:33:00 | WinXP | 190.58.16.215 (TSTT.NET.TT): TELECOMMUNICATION SERVICES OF TRINIDAD AND TOBAGO, ARIMA, ARIMA, TT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
11:50:00 | WinXP | 121.121.105.164 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:12:22:00 | Win2K-f | 75.38.87.130 (-): HAVANA HOUSE, BAKERSFIELD, CALIFORNIA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:35:00 | WinXP | 115.164.220.96 (-): DIGI TELECOMMUNICATIONS SDN BHD, SHAH ALAM, SELANGOR, MY. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:14:05:00 | WinXP | 200.100.140.93 (TELESP.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, SãO PAULO, SAO PAULO, BR. (DIAL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:14:20:00 | Win2K-f | 70.126.162.133 (RR.COM): ROAD RUNNER HOLDCO LLC, WINTER HAVEN, FLORIDA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | a4497aa84e NEW |
d1b46a6ff9 [0] | ASM:Graph |
none|none | lines=546 | trace | |
T:14:31:00 | Win2K-f | 123.111.111.32, 222.170.127.203 (INVALID IPV4 ADDRESS): INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS. (INVALID IPV4 ADDRESS) |
60.190.222.139:65520 | US:microsoft.com DE:proxim.ircgalaxy.pl CN:lb.perfectexe.com CN:dick.perfectexe.com CN:hn.yigeyuming.com :a.95622.com CN:2b.perfectexe.com CN:2b.yigeyuming.com :realtorread.com US:i.nuseek.com :search.dmtracker.com |
135 | pcap | raw alerts ruleset |
irc http 190 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 43 28 of 42 38 of 40 38 of 40 29 of 43 24 of 42 |
3ef3c2ad56 NEW 8809b6417c NEW 89f410e7cc NEW 909270c172 NEW b34e640329 NEW c413ca56c4 NEW |
none[none] none [none] 2593cbda62[0] 55c25968a5[0] none [none] none [none] |
none:none none:none ASM:Graph ASM:Graph none:none none:none |
none|none none|none Armadillo| tElock| none|none none|none |
none none lines=91 lines=125 embedded dns none none |
none none trace trace none none |
T:14:54:00 | Win2K-f | 208.94.183.97 (KARIBCABLE.COM): KARIB CABLE, KINGSTOWN, SAINT GEORGE, VC. (100Mbps) |
n/a | :1.95622.com US:productquotient.com US:dsnextgen.com :cdn.dsultra.com US:domdex.com US:p.chango.com CA:idcs.interclick.com US:ib.adnxs.com :a.collective-media.net :segment-pixel.invitemedia.com :ad.doubleclick.net :b.collective-media.net CA:74.122.140.122:80 74.125.224.59:80 75.101.205.96:80 96.16.200.74:80 |
445 | pcap | raw alerts ruleset |
http irc 72 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:15:03:00 | Win2K-f | 198.230.120.33 (SASKTELMOBILITY.COM): SERVICE PROVIDER CORPORATION, BEDMINSTER, NEW JERSEY, US. (DSL) |
n/a | US:hempcookies.com US:as.casalemedia.com :images.ddc.com US:domdex.com US:p.chango.com US:ib.adnxs.com :a.collective-media.net :ad.doubleclick.net :b.collective-media.net :segment-pixel.invitemedia.com CA:idcs.interclick.com :ads.undertone.com :ads.olivebrandresponse.com :r.turn.com US:leadback.advertising.com US:tacoda.at.atwola.com US:activex.microsoft.com US:codecs.microsoft.com US:cdn.optmd.com DE:proxim.ircgalaxy.pl |
445 | pcap | raw alerts ruleset |
http 41 lines |
Argh : 0.3 profile |
none | summary tarball |
1 of 42 | ccaedbac00 NEW |
none[none] | none:none |
none|none | none | none |
T:16:24:00 | Win2K-f | 24.33.80.202 (RR.COM): ROAD RUNNER HOLDCO LLC, MILFORD, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:17:35:00 | Win2K-f | 64.183.255.133 (RR.COM): ROAD RUNNER HOLDCO LLC, HOUSTON, TEXAS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1008 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 43 | 4e2690d61d NEW |
none[none] | none:none |
none|none | none | none | |
T:18:17:00 | WinXP | 93.102.162.15 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, PT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
18:33:00 | WinXP | 64.33.132.86 (AIRSTREAMCOMM.NET): TRI COUNTY TELEPHONE, WISCONSIN, US. (DIAL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 0cfab99612 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:18:37:00 | Win2K-f | 75.37.173.251 (SBCGLOBAL.NET): JASON LEE, PLANO, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:55:00 | WinXP | 190.120.129.114 (EMTEL.NET.CO): COLOMBIA MVIL, TOCAIMA, CUNDINAMARCA, CO. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 80b5952d6c NEW |
none[none] | none:none |
none|none | none | none |
T:19:25:00 | Win2K-f | 66.189.4.40 (CHARTER.COM): CHARTER COMMUNICATIONS, LUDLOW, MASSACHUSETTS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:44:00 | WinXP | 60.250.246.160 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 38 35 of 38 |
38ed850a0e NEW b9297745a1 NEW |
46990f37cd [0] 4294884d84[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:21:12:00 | Win2K-f | 97.96.10.90 (RR.COM): ROAD RUNNER HOLDCO LLC, VALRICO, FLORIDA, US. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 1e4f8f9259 NEW |
e73db583fd [0] | ASM:Graph |
none|none | lines=546 | trace | |
T:21:28:00 | WinXP | 123.215.103.45 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
83.133.119.197:65520 | DE:proxima.ircgalaxy.pl US:microsoft.com CN:lb.perfectexe.com CN:dick.perfectexe.com CN:hn.yigeyuming.com :a.95622.com CN:2b.perfectexe.com :www.lddwj.com :wpad :www.zkaoo.com 1.1.1.1:80 CN:222.170.127.203:88 DE:83.133.119.197:65520 |
135 | pcap | raw alerts ruleset |
irc http 138 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 42 34 of 36 29 of 32 29 of 43 24 of 42 |
8809b6417c NEW 99b248336f NEW 9d677c3f70 NEW b34e640329 NEW c413ca56c4 NEW |
none[none] c64bd1a776[0] 77e75ff10f[0] none [none] none [none] |
none:none ASM:Graph ASM:Graph none:none none:none |
none|none Armadillo| tElock| none|none none|none |
none lines=91 lines=120 embedded dns none none |
none trace trace none none |
T:23:45:00 | WinXP | 124.45.62.45 (WAKWAK.NE.JP): NTT-ME CORPORATION, TOKYO, TOKYO, JP. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace |