Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:58:00 | Win2K-f | 1.224.253.194 (-): . |
n/a | DE:irc.zief.pl US:microsoft.com CN:60.190.222.131:81 |
135 | pcap | raw alerts ruleset |
irc http 268 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 40 of 41 35 of 40 |
34cd9e2f76 NEW 376a6b6ecd NEW d6d06ae104 NEW |
none[none] none [none] none [none] |
none:none none:none none:none |
none|none none|none none|none |
none none none |
none none none |
T:01:16:00 | WinXP | 94.240.204.149 (DSL.ONLINE.GE): GOL GELINK NET, GE. (DSL) |
n/a | DE:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
37 of 41 | fe34e6a71a NEW |
none[none] | none:none |
none|none | none | none |
T:01:17:00 | Win2K-f | 27.98.0.27 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 40 of 41 |
6a6aaa5b73 NEW 8bde6dd126 NEW |
63889c9976 [0] 885c68f500[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=42 lines=64 embedded dns |
trace trace |
01:54:00 | Win2K-f | 218.63.69.77 (163DATA.COM.CN): CHINANET YUNNAN PROVINCE NETWORK, BEIJING, BEIJING, CN. (DIAL) |
n/a | US:www.maxmind.com EU:checkip.dyndns.org EU:getmyip.co.uk US:www.vouchercodes.net :www.getmyip.org US:208.43.124.51:80 US:217.160.239.39:80 EU:91.198.22.71:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:02:30:00 | WinXP | 122.149.92.63 (DODO.COM.AU): LAYER 2 BROADBAND CUSTOMER NETWORK, AU. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 11 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:02:34:00 | WinXP | 31.16.40.215 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 88f3393e20 NEW |
none[none] | none:none |
none|none | none | none |
T:03:26:00 | WinXP | 112.201.80.78 (PLDT.NET): IPG, LAS PINAS CITY, MANILA, PH. (DSL) |
n/a | :gg.arrancar.org | 135 | pcap | raw alerts ruleset |
other 454 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 42 | b53773d680 NEW |
none[none] | none:none |
none|none | none | none |
T:04:30:00 | WinXP | 89.178.14.138 (CORBINA.RU): BROADBAND CUSTOMERS IN MOSCOW, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:05:41:00 | WinXP | 49.14.111.33 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 5c6df5141d NEW |
none[none] | none:none |
none|none | none | none |
T:05:53:00 | WinXP | 109.99.204.227 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
06:12:00 | WinXP | 109.99.204.227 (JWS.COM): EU-ZZ, UK. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:06:19:00 | WinXP | 27.98.18.62 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 11 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:06:29:00 | WinXP | 123.193.117.52 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 42 | 3977189133 NEW |
none[none] | none:none |
none|none | none | none |
T:06:40:00 | WinXP | 24.105.216.184 (MHCABLE.COM): MID-HUDSON CABLEVISION INC. (CATSKILL), COEYMANS HOLLOW, NEW YORK, US. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:08:30:00 | WinXP | 202.177.105.53 (MB-ICTV.JP): IRUMA CABLE TV, TOKYO, TOKYO, JP. (DSL) |
n/a | :gg.arrancar.org | 135 | pcap | raw alerts ruleset |
other 172 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | a650c67e14 NEW |
none[none] | none:none |
none|none | none | none |
T:08:46:00 | WinXP | 70.112.223.203 (RR.COM): ROAD RUNNER HOLDCO LLC, AUSTIN, TEXAS, US. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 61 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | 73f1082158 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:09:50:00 | WinXP | 87.97.211.218 (PL.EKK.BG): EKK CATV PLOVDIV, PLOVDIV, PLOVDIV, BG. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:10:41:00 | Win2K-f | 4.227.197.220 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DENVER, COLORADO, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 122 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:10:41:00 | WinXP | 180.207.198.1 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | d11b1f56f9 NEW |
none[none] | none:none |
none|none | none | none |
T:11:39:00 | Win2K-f | 219.124.28.21 (CABLENET.NE.JP): CABLENET SAITAMA CO. LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 41 |
5bbb57c115 NEW 75ac189d9e NEW |
03e5cb3c4a [0] 705dbaa801[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:11:52:00 | WinXP | 14.97.155.228 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 79 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:19:00 | WinXP | 46.134.198.130 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | c19c8a2776 NEW |
none[none] | none:none |
none|none | none | none |
T:12:31:00 | WinXP | 174.116.12.141 (ROGERS.COM): ROGERS CABLE COMMUNICATIONS INC, ST. JOHN'S, NEWFOUNDLAND AND LABRADOR, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:47:00 | WinXP | 178.150.33.135 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | aad01847fa NEW |
none[none] | none:none |
none|none | none | none |
T:13:08:00 | WinXP | 173.25.166.241 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, CHANHASSEN, MINNESOTA, US. (DSL) |
n/a | RU:siliconfireware.ru RU:auction.nic.ru :www.google-analytics.com RU:domain-parking.ru :wpad RU:ebookfinaltrash.ru RU:89.108.64.156:80 |
445 | pcap | raw alerts ruleset |
http http http http 42 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee NEW |
none[0] | none:none |
ASPack| | lines=298 embedded dns |
trace |
T:13:53:00 | WinXP | 178.167.140.44 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | dc467897c8 NEW |
none[none] | none:none |
none|none | none | none |
13:56:00 | WinXP | 178.24.72.139 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:14:21:00 | Win2K-f | 70.65.245.237 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, LETHBRIDGE, ALBERTA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:46:00 | WinXP | 109.55.217.164 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:14:58:00 | WinXP | 173.214.231.53 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
68b5e580f0 NEW b475ce7c0b NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:15:50:00 | WinXP | 24.155.134.25 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS ODESSA HUB, ODESSA, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:16:19:00 | Win2K-f | 208.85.217.47 (VOICEONE.CA): 3757277 CANADA INC. (OA 295.CA), CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 94 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:28:00 | Win2K-f | 71.100.27.146 (VERIZON.NET): VERIZON INTERNET SERVICES INC, TAMPA, FLORIDA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
none 40 of 43 |
a0b90e31ec NEW e776fb5f1a NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
16:49:00 | WinXP | 123.193.131.79 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 9276456bf8 NEW |
none[none] | none:none |
none|none | none | none |
T:16:55:00 | WinXP | 92.251.163.243 (-): H3G IRELAND SUBSCRIBERS, IE. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | dc467897c8 NEW |
none[none] | none:none |
none|none | none | none |
T:17:34:00 | Win2K-f | 50.11.54.182 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:18:50:00 | WinXP | 24.155.236.136 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS ODESSA HUB, MIDLAND, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:19:18:00 | Win2K-f | 27.98.0.51 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 40 of 41 |
6a6aaa5b73 NEW 8bde6dd126 NEW |
63889c9976 [0] 885c68f500[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=42 lines=64 embedded dns |
trace trace |
T:20:01:00 | Win2K-f | 61.16.165.227 (DIRECT.NET.IN): TATA COMMUNICATIONS INTERNET SERVICES LTD, BANGALORE, KARNATAKA, IN. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
703674dc37 NEW c55e86f7e9 NEW |
none[none] c790c10ad1[0] |
none:none ASM:Graph |
none|none tElock| |
none lines=64 embedded dns |
none trace |
T:20:20:00 | Win2K-f | 210.198.9.109 (TSUNEISHI.CO.JP): RCA CORPORATION, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
none:none ASM:Graph |
Armadillo| tElock| |
lines=90 lines=75 embedded dns |
trace trace |
20:33:00 | WinXP | 112.205.2.150 (PLDT.NET): IPG, PH. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | 6f43af423a NEW |
none[none] | none:none |
none|none | none | none |
T:20:53:00 | WinXP | 120.138.175.125 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
6a1dc43309 NEW 94e49d5627 NEW |
522dace6c1 [0] 777259292a[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:21:54:00 | WinXP | 117.254.237.78 (STERLINGSTUDENTS.NET): NIB (NATIONAL INTERNET BACKBONE), NEW DELHI, DELHI, IN. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |