Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:27:00 | WinXP | 119.154.34.172 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, ISLAMABAD, ISLAMABAD, PK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 169a5d5c84 NEW |
none[none] | none:none |
none|none | none | none |
T:03:12:00 | Win2K-f | 175.113.174.215 (-): . |
83.133.119.197:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:yigeshabi.8800.org CN:w.nucleardiscover.com CN:russia.9966.org CN:myck.nucleardiscover.com :chasecreditcardcashback.info CN:ck3.nucleardiscover.com US:spiceproduct.com CA:ndparking.com CN:ck4.nucleardiscover.com US:zoo.parkingspa.com US:yourbroadbandinternet.com CN:seo.hi72.com CA:216.8.179.25:80 |
135 | pcap | raw alerts ruleset |
irc http 148 lines |
Yeah : 1.8 profile |
none | summary tarball |
25 of 41 29 of 43 25 of 43 20 of 42 36 of 42 38 of 42 |
03f191c225 NEW 36093c1d73 NEW 6d1c54e9c2 NEW 8662cd182e NEW bf063bba17 NEW f269760f66 NEW |
none[none] none [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none none|none |
none none none none none none |
none none none none none none |
T:03:19:00 | Win2K-f | 203.118.62.233 (-): CARESTREAM-HEALTH-SINGAPORE-PTE-LTD-SID, SINGAPORE, SINGAPORE, SG. (100Mbps) |
n/a | :smallz.com US:i.nuseek.com US:advancecash101.com :www.google-analytics.com US:images.smartname.com US:p.chango.com US:pricefreightline.com US:quickloansforpeoplewithbadcredit.info US:as.casalemedia.com DE:www.sedoparking.com US:activex.microsoft.com US:codecs.microsoft.com US:140.174.25.1:80 SG:203.118.62.233:707 |
135 | pcap | raw alerts ruleset |
http irc 149 lines |
Argh : 0.3 profile |
none | summary tarball |
1 of 42 | 140978c6ed NEW |
none[none] | none:none |
none|none | none | none |
T:03:24:00 | WinXP | 222.230.153.147 (VECTANT.NE.JP): SEIKA CORPORATION, YOKOHAMA, KANAGAWA, JP. (100Mbps) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:03:38:00 | Win2K-f | 59.178.148.180 (BOL.NET.IN): MTNL CAT B ISP, DELHI, DELHI, IN. (DSL) |
n/a | CN:w.nucleardiscover.com US:freegiftsinc.com US:activex.microsoft.com US:codecs.microsoft.com CN:ck3.nucleardiscover.com CA:www.searchnut.com US:musicreviewer.net CA:www.ndparking.com US:i.casalemedia.com US:66.246.235.43:80 |
445 | pcap | raw alerts ruleset |
http 91 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:03:40:00 | WinXP | 174.42.132.1 (WINDSTREAM.NET): ALLTEL MIP CUSTOMERS - WARRENSVILLE HEIGHTS, CHARLOTTE, NORTH CAROLINA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:03:46:00 | WinXP | 211.5.25.78 (DION.NE.JP): DION (KDDI CORPORATION), YOKOHAMA, KANAGAWA, JP. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 130 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 1 of 43 |
53bfe15e91 NEW 57e3a42456 NEW |
1473091351 [0] none [none] |
ASM:Graph none:none |
tElock| none|none |
lines=75 embedded dns none |
trace none |
|
T:03:56:00 | Win2K-f | 92.36.159.161 (-): BH TELECOM BRAS DYNAMIC POOL, SARAJEVO, FEDERATION OF BOSNIA AND HERZEGOVINA, BA. (DSL) |
60.190.222.139:65520 | CN:proxim.ircgalaxy.pl CN:yigeshabi.8800.org CN:ck3.nucleardiscover.com CN:s5.perfectexe.com US:microsoft.com :televisionpricescomparison.com US:nlclassifiedes.com :coffeesfama.com CN:w.nucleardiscover.com CN:russia.9966.org US:as.casalemedia.com DE:www.sedoparking.com US:i.nuseek.com :pagead2.googlesyndication.com US:activex.microsoft.com :ajax.googleapis.com :whoisprivacyprotect.com US:codecs.microsoft.com :studentconsolidationloanslenders.com US:biz-realestate.info US:creditequitylinenow.com :soccerloan.com CN:ck4.nucleardiscover.com :moviestimesonline.com :europebig.com US:datadownloaddisk.com :equityfields.com CN:60.190.223.75:2012 |
445 | pcap | raw alerts ruleset |
http irc 60 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 41 25 of 43 20 of 42 1 of 42 |
03f191c225 NEW 6d1c54e9c2 NEW 8662cd182e NEW b2d97fede6 NEW |
none[none] none [none] none [none] none [none] |
none:none none:none none:none none:none |
none|none none|none none|none none|none |
none none none none |
none none none none |
04:37:00 | WinXP | 125.230.100.246 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
04:41:00 | WinXP | 174.42.132.1 (WINDSTREAM.NET): ALLTEL MIP CUSTOMERS - WARRENSVILLE HEIGHTS, CHARLOTTE, NORTH CAROLINA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:04:44:00 | WinXP | 31.147.189.39 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 88f3393e20 NEW |
none[none] | none:none |
none|none | none | none |
T:06:29:00 | WinXP | 95.58.13.22 (DIAL.ONLINE.KZ): JSC KAZAKHTELECOM SOUTH KAZAKHSTAN AFFILIATE, ALMATY, ALMATY CITY, KZ. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 2c94e3fd00 NEW |
none[none] | none:none |
none|none | none | none |
T:06:54:00 | WinXP | 92.223.61.49 (QSC.DE): GINKO, DE. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:08:28:00 | WinXP | 184.0.9.90 (EMBARQHSD.NET): EMBARQ CORPORATION, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace | |
T:08:50:00 | WinXP | 178.209.242.127 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
08:55:00 | WinXP | 118.165.18.155 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:10:41:00 | WinXP | 14.98.5.195 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:10:44:00 | WinXP | 186.255.185.58 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:11:36:00 | WinXP | 184.78.2.2 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:12:49:00 | WinXP | 31.16.41.11 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 88f3393e20 NEW |
none[none] | none:none |
none|none | none | none |
T:12:55:00 | WinXP | 177.30.80.254 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
36 of 42 | 4b6e822789 NEW |
none[none] | none:none |
none|none | none | none |
T:13:06:00 | WinXP | 174.42.172.186 (WINDSTREAM.NET): ALLTEL MIP CUSTOMERS - WARRENSVILLE HEIGHTS, SALISBURY, NORTH CAROLINA, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:13:08:00 | WinXP | 180.207.200.81 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
40 of 40 | d6997f4bc2 NEW |
none[none] | none:none |
none|none | none | none |
T:15:29:00 | WinXP | 177.31.16.136 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
33 of 35 | e9fcd6f257 NEW |
2e05bc2272 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:19:07:00 | WinXP | 201.173.184.164 (INTERCABLE.NET): TELEVISION INTERNACIONAL S.A. DE C.V, MONTERREY, NUEVO LEON, MX. (100Mbps) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 5c6df5141d NEW |
none[none] | none:none |
none|none | none | none |
T:19:33:00 | WinXP | 60.234.110.181 (ORCON.NET.NZ): ORCON INTERNET LTD SUPPORT, AUCKLAND, AUCKLAND, NZ. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:20:17:00 | WinXP | 14.99.107.33 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:44:00 | Win2K-f | 24.79.81.132 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 42 | b4324ba57a NEW |
none[none] | none:none |
none|none | none | none | |
T:22:39:00 | WinXP | 112.205.2.150 (PLDT.NET): IPG, PH. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | 6f43af423a NEW |
none[none] | none:none |
none|none | none | none |
T:23:02:00 | WinXP | 76.191.21.33 (SPEAKEASY.NET): SAN FRANCISCO, CALIFORNIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1013 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 41 | 682a384fe9 NEW |
none[3] | none:none |
none|none | none | trace | |
T:23:45:00 | Win2K-f | 184.74.16.128 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |