Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:18:00 | WinXP | 111.88.10.234 (HOSTS-WORLDCALL.NET.PK): WORLDCALL TELECOM LTD, PK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:01:22:00 | WinXP | 199.117.151.75 (TRANQUILITY.NET): CORAL WIRELESS LLC, HONOLULU, HAWAII, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | e92ed9f79c NEW |
none[none] | none:none |
none|none | none | none |
T:02:05:00 | WinXP | 119.160.172.159 (-): BRUNET TELEKOM BRUNEI BERHAD (TELBRU), JERUDONG, BRUNEI AND MUARA, BN. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:11:00 | WinXP | 81.9.190.121 (CM-81-9-237-10.TELECABLE.ES): TELECABLE, OVIEDO, ASTURIAS, ES. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 3ae357d17b NEW |
none[0] | none:none |
PolyEnE| | lines=73 | trace |
T:03:53:00 | WinXP | 123.99.3.152 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:04:01:00 | WinXP | 119.154.65.198 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, LAHORE, PUNJAB, PK. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:04:18:00 | Win2K-f | 220.113.0.178 (BJGWBN.NET.CN): 7-3-101 SHA HE MIN YUAN CHANGPING DISTRICT BEIJING, BEIJING, BEIJING, CN. (DSL) |
94.244.80.209:65520 | CN:yigeshabi.8800.org :newvodavoda.com IT:mewgost.com CN:60.190.223.75:2012 |
139 | pcap | raw alerts ruleset |
irc http 30 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 42 29 of 43 29 of 41 |
44a384864c NEW 564048b35d NEW 87101f64b4 NEW |
none[none] none [none] none [none] |
none:none none:none none:none |
none|none none|none none|none |
none none none |
none none none |
04:27:00 | Win2K-f | 220.113.0.178 (BJGWBN.NET.CN): 7-3-101 SHA HE MIN YUAN CHANGPING DISTRICT BEIJING, BEIJING, BEIJING, CN. (DSL) |
83.133.119.197:65520 | CN:yigeshabi.8800.org CN:w.nucleardiscover.com CN:russia.9966.org CN:myck.nucleardiscover.com US:1stplaceroofing.com CN:ck3.nucleardiscover.com US:images01.tzimg.com US:notenumber.com CN:ck4.nucleardiscover.com :domdex.com :www.google-analytics.com :webmastercuba.com 98.126.50.74:80 |
139 | pcap | raw alerts ruleset |
irc http 74 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 41 29 of 43 25 of 43 20 of 42 |
03f191c225 NEW 36093c1d73 NEW 6d1c54e9c2 NEW 8662cd182e NEW |
none[none] none [none] none [none] none [none] |
none:none none:none none:none none:none |
none|none none|none none|none none|none |
none none none none |
none none none none |
04:39:00 | Win2K-f | 113.254.60.232 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | CN:w.nucleardiscover.com CN:russia.9966.org :download.macromedia.com US:fpdownload2.macromedia.com CN:s5.perfectexe.com CN:60.190.223.75:888 |
445 | pcap | raw alerts ruleset |
http irc 227 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 43 9 of 42 |
b34e640329 NEW e4240d7958 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
04:44:00 | Win2K-f | 82.250.60.226 (PROXAD.NET): PROXAD / FREE SAS, VERSAILLES, ILE-DE-FRANCE, FR. (DSL) |
n/a | US:thequalityautoinsurance.com US:directlombard.info US:as.casalemedia.com CA:www.searchnut.com US:activex.microsoft.com US:codecs.microsoft.com CA:www.ndparking.com US:searchportal.information.com :cdn.dsultra.com US:p.chango.com :a.collective-media.net US:ib.adnxs.com :segment-pixel.invitemedia.com :b.collective-media.net 50.16.78.28:80 96.16.200.74:80 |
139 | pcap | raw alerts ruleset |
http irc 35 lines |
Argh : 0.3 profile |
none | summary tarball |
1 of 42 1 of 43 |
015fa9521e NEW 974bd75b20 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
04:49:00 | Win2K-f | 178.187.76.112 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | :cashinvention.info US:www.devduo.com US:i.nuseek.com :c.statcounter.com :www.statcounter.com US:72.249.31.21:80 |
445 | pcap | raw alerts ruleset |
irc http 315 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
04:57:00 | Win2K-f | 178.46.122.144 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
60.190.222.139:65520 | CN:ck3.nucleardiscover.com DE:proxim.ircgalaxy.pl CN:yigeshabi.8800.org :newvodavoda.com CN:s5.perfectexe.com :vacationsyour.com CN:myck.nucleardiscover.com US:homeinsurancesoft.com :anti-agingmedications.com CN:w.nucleardiscover.com IT:mewgost.com CN:russia.9966.org US:as.casalemedia.com US:i.nuseek.com :pagead2.googlesyndication.com CA:www.ndparking.com US:activex.microsoft.com CN:ck4.nucleardiscover.com :yivutu.com :salesstocks.com :2days.net US:moneydeposit.info |
445 | pcap | raw alerts ruleset |
irc http 152 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 43 25 of 43 1 of 43 |
564048b35d NEW 6d1c54e9c2 NEW fddbad32e7 NEW |
none[none] none [none] none [none] |
none:none none:none none:none |
none|none none|none none|none |
none none none |
none none none |
T:05:20:00 | Win2K-f | 75.23.126.35 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, PEORIA, ILLINOIS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 36 29 of 33 |
0474b4b09f NEW 1c3210698a NEW |
affa94efc0 [0] 38bbefb8cc[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
T:05:32:00 | Win2K-f | 112.205.190.45 (PLDT.NET): IPG, PH. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 975 lines |
Yeah : 1.3 profile |
none | summary tarball |
16 of 43 | fd3f11d128 NEW |
none[none] | none:none |
none|none | none | none | |
05:33:00 | Win2K-f | 61.7.151.98 (-): 10 FL. 72. CAT TELECOM TOWER BANGRAK BANGKOK THAILAND, BANGKOK, KRUNG THEP, TH. (DSL) |
n/a | US:www.maxmind.com :www.getmyip.org US:checkip.dyndns.org EU:getmyip.co.uk US:www.vouchercodes.net DE:131.220.6.26:80 EU:91.198.22.71:80 |
445 | pcap | raw alerts ruleset |
http 1006 lines |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 7587773eea NEW |
none[3] | none:none |
StarForce| | none | trace |
T:05:42:00 | Win2K-f | 61.7.151.98 (-): 10 FL. 72. CAT TELECOM TOWER BANGRAK BANGKOK THAILAND, BANGKOK, KRUNG THEP, TH. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk US:www.vouchercodes.net |
445 | pcap | raw alerts ruleset |
http 1016 lines |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 7587773eea NEW |
none[3] | none:none |
StarForce| | none | trace |
T:06:28:00 | Win2K-f | 121.245.47.233 (VSNL.NET.IN): HYDERABAD-VSB- LEASED LINE TATA TELESERVICES LTD, NEW DELHI, DELHI, IN. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 100 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:14:00 | Win2K-f | 59.125.159.170 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, KAOHSIUNG, T'AI-WAN, TW. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:08:22:00 | WinXP | 111.80.186.176 (HINET.NET): MOBILE BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:08:25:00 | WinXP | 122.126.147.182 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:08:43:00 | WinXP | 186.210.120.225 (-): . |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 5a07de7dc6 NEW |
none[none] | none:none |
none|none | none | none |
T:09:04:00 | WinXP | 109.162.33.162 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | d11b1f56f9 NEW |
none[none] | none:none |
none|none | none | none | |
10:29:00 | WinXP | 188.73.203.120 (CAMPUSEAI.ORG): EUROPEAN REGIONAL REGISTRY, UK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 169a5d5c84 NEW |
none[none] | none:none |
none|none | none | none |
T:13:55:00 | WinXP | 112.200.39.15 (PLDT.NET): IPG, LAS PINAS CITY, MANILA, PH. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1002 lines |
Yeah : 1.3 profile |
none | summary tarball |
20 of 42 | 9809a6f3eb NEW |
none[none] | none:none |
none|none | none | none | |
15:50:00 | Win2K-f | 125.64.18.31 (163DATA.COM.CN): CHINANET SICHUAN PROVINCE NETWORK, CHENGDU, SICHUAN, CN. (DSL) |
n/a | US:www.maxmind.com EU:checkip.dyndns.org :www.getmyip.org EU:getmyip.co.uk CN:125.64.18.31:7155 DE:131.220.6.26:80 EU:78.40.35.134:80 EU:91.198.22.71:80 |
445 | pcap | raw alerts ruleset |
http 8 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:15:59:00 | Win2K-f | 125.64.18.31 (163DATA.COM.CN): CHINANET SICHUAN PROVINCE NETWORK, CHENGDU, SICHUAN, CN. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 19 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
16:41:00 | WinXP | 186.255.10.210 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:16:58:00 | Win2K-f | 203.196.77.154 (SPACELAN.NE.JP): KANAZAWA CABLE TELEVISION NET CO. LTD, KANAZAWA, ISHIKAWA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 40 of 41 |
2fc89991b2 NEW 7bdf45b79a NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
17:13:00 | WinXP | 46.72.49.190 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 1096ba143e NEW |
none[none] | none:none |
none|none | none | none |
T:17:27:00 | WinXP | 189.67.71.15 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, RIO DE JANEIRO, RIO DE JANEIRO, BR. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 42 | 33ffb2cb88 NEW |
none[none] | none:none |
none|none | none | none |
T:18:32:00 | WinXP | 111.81.179.9 (HINET.NET): MOBILE BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:18:36:00 | WinXP | 186.51.190.200 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | 5c6df5141d NEW |
none[none] | none:none |
none|none | none | none |
18:38:00 | WinXP | 94.253.155.59 (XNET.HR): BNET HRVATSKA, HR. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 6e6fde936f NEW |
none[none] | none:none |
none|none | none | none |
T:18:43:00 | WinXP | 24.138.215.14 (-): LIBERTY CABLEVISION - LUQUILLO, PR. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 35 | e9fcd6f257 NEW |
2e05bc2272 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:19:53:00 | WinXP | 59.124.124.152 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 40 of 41 |
6a6aaa5b73 NEW 8bde6dd126 NEW |
63889c9976 [0] 885c68f500[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=42 lines=64 embedded dns |
trace trace |
T:20:09:00 | WinXP | 115.80.167.215 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:20:35:00 | WinXP | 72.251.104.73 (1DIAL.COM): AD-BASE SYSTEMS INC. (DBA GLOBALPOPS), PITTSBURGH, PENNSYLVANIA, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 91e993a998 NEW |
none[none] | none:none |
none|none | none | none |
20:54:00 | WinXP | 115.80.167.215 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:21:18:00 | Win2K-f | 218.20.70.2 (163DATA.COM.CN): CHINANET GUANGDONG PROVINCE NETWORK, GUANGZHOU, GUANGDONG, CN. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:21:32:00 | WinXP | 75.37.173.251 (SBCGLOBAL.NET): JASON LEE, PLANO, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:11:00 | Win2K-f | 211.5.25.59 (DION.NE.JP): DION (KDDI CORPORATION), YOKOHAMA, KANAGAWA, JP. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 107 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 1 of 43 |
53bfe15e91 NEW 57e3a42456 NEW |
1473091351 [0] none [none] |
ASM:Graph none:none |
tElock| none|none |
lines=75 embedded dns none |
trace none |
|
T:22:49:00 | Win2K-f | 98.154.61.44 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:23:58:00 | WinXP | 174.42.196.68 (WINDSTREAM.NET): ALLTEL MIP CUSTOMERS - WARRENSVILLE HEIGHTS, COLUMBIA, SOUTH CAROLINA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |