Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:05:00 | WinXP | 61.253.189.237 (KRLINE.NET): KRNIC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
46.252.130.7:65520 | DE:proxima.ircgalaxy.pl US:microsoft.com CN:shabi.coolnuff.com CN:60.190.223.75:2012 |
135 | pcap | raw alerts ruleset |
irc 156 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 41 31 of 33 |
ab9c4b5f21 NEW d789c8d157 NEW |
5fe48b2dcc [0] 5f6572479f[0] |
ASM:Graph ASM:Graph |
Armadillo| PolyEnE| |
lines=42 lines=113 embedded dns |
trace trace |
T:00:52:00 | WinXP | 65.113.116.222 (TRANQUILITY.NET): CORAL WIRELESS LLC, HONOLULU, HAWAII, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | e92ed9f79c NEW |
none[none] | none:none |
none|none | none | none |
T:01:09:00 | WinXP | 177.28.84.211 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:01:16:00 | WinXP | 79.121.52.75 (KABELNET.HU): VIDANET CABLETELEVISION PROVIDER LTD, HU. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:01:45:00 | WinXP | 112.110.199.5 (-): GPRS VAS SERVICES, IN. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | b269b15ffd NEW |
none[none] | none:none |
none|none | none | none |
02:30:00 | Win2K-f | 223.19.194.167 (-): . |
n/a | US:www.maxmind.com :www.getmyip.org :checkip.dyndns.org US:208.43.124.51:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:03:05:00 | WinXP | 188.176.70.196 (DSL.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, DK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:03:39:00 | WinXP | 119.103.87.200 (163DATA.COM.CN): CHINANET HUBEI PROVINCE NETWORK, WUHAN, HUBEI, CN. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | 751685117f NEW |
none[none] | none:none |
none|none | none | none |
T:04:28:00 | WinXP | 109.53.161.128 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 5c6df5141d NEW |
none[none] | none:none |
none|none | none | none |
T:05:20:00 | WinXP | 155.239.147.205 (TELKOMADSL.CO.ZA): AFRINIC, CAPE TOWN, WESTERN CAPE, ZA. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
37 of 41 | 63ac15306f NEW |
none[none] | none:none |
none|none | none | none |
T:05:29:00 | WinXP | 14.97.204.50 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:05:36:00 | Win2K-f | 121.245.73.192 (VSNL.NET.IN): DELHI-VSB- LEASED LINE TATA TELESERVICES LTD, DELHI, DELHI, IN. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:05:50:00 | WinXP | 117.20.182.112 (-): STARHUB HSPA, SINGAPORE, SINGAPORE, SG. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 9276456bf8 NEW |
none[none] | none:none |
none|none | none | none |
T:06:05:00 | Win2K-f | 72.48.214.196 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS ODESSA HUB, MIDLAND, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:06:07:00 | WinXP | 178.37.42.202 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | aad01847fa NEW |
none[none] | none:none |
none|none | none | none |
T:09:06:00 | WinXP | 119.241.2.221 (MESH.AD.JP): NEC BIGLOBE LTD, YOKOHAMA, KANAGAWA, JP. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:09:44:00 | WinXP | 113.10.90.200 (-): STARHUB HSDPA SG, SG. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:10:20:00 | WinXP | 123.99.8.84 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 2f6cab0a72 NEW |
none[none] | none:none |
none|none | none | none |
T:10:30:00 | WinXP | 118.233.113.31 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 43 | e69f7d2dea NEW |
none[none] | none:none |
none|none | none | none |
T:11:21:00 | WinXP | 151.81.30.0 (51-151.NET24.IT): IUNET-BNET, IT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:11:58:00 | WinXP | 173.17.199.77 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, SAVAGE, MINNESOTA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:12:28:00 | WinXP | 182.63.179.96 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:13:02:00 | Win2K-f | 4.177.216.138 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, SAN DIEGO, CALIFORNIA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 237 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 40 of 42 |
9131865126 NEW ac50d76cbd NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
|
T:13:16:00 | Win2K-f | 208.88.70.103 (-): BBW 4 ACES TOWER CUSTOMER SUBNET, SHREVEPORT, LOUISIANA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:13:42:00 | WinXP | 46.203.62.202 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:13:55:00 | WinXP | 109.125.26.89 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 01c4a6b3eb NEW |
dd524b0259 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:14:50:00 | Win2K-f | 98.141.160.48 (CAVTEL.NET): CAVALIER TELEPHONE, PHILADELPHIA, PENNSYLVANIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:15:35:00 | Win2K-f | 118.83.18.72 (HTOJ.J-CNET.JP): JCN-HTMNET, HACHIOJI, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 123 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 37 of 40 |
acabc6b6d1 NEW c70fcf30a3 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:15:40:00 | WinXP | 178.167.197.182 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:16:40:00 | WinXP | 106.70.71.195 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:16:49:00 | WinXP | 80.104.114.234 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A, MILANO, LOMBARDIA, IT. (DIAL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 8a2553433c NEW |
none[none] | none:none |
none|none | none | none |
T:16:58:00 | WinXP | 64.33.252.13 (MIDSTATESD.NET): MIDSTATE COMMUNICATIONS, CHAMBERLAIN, SOUTH DAKOTA, US. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 0cfab99612 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
17:39:00 | WinXP | 80.104.114.234 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A, MILANO, LOMBARDIA, IT. (DIAL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 8a2553433c NEW |
none[none] | none:none |
none|none | none | none |
T:18:14:00 | WinXP | 93.102.216.174 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, PT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:18:43:00 | Win2K-f | 120.138.168.13 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 39 of 39 |
b8e6f4caf7 NEW fb92b91fe7 NEW |
f81eac6379 [0] fe88ab8768[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
18:44:00 | WinXP | 186.110.221.183 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 4e005f8e82 NEW |
none[none] | none:none |
none|none | none | none |
T:18:50:00 | WinXP | 50.72.215.161 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 38 of 43 |
965cac2fb0 NEW a26d336ff2 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:19:02:00 | WinXP | 202.107.247.8 (CNINFO.NET): CHINANET-ZJ QUZHOU NODE NETWORK, QUZHOU, ZHEJIANG, CN. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
20:19:00 | WinXP | 64.33.252.13 (MIDSTATESD.NET): MIDSTATE COMMUNICATIONS, CHAMBERLAIN, SOUTH DAKOTA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 0cfab99612 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:20:28:00 | WinXP | 60.234.100.117 (ORCON.NET.NZ): ORCON INTERNET LTD SUPPORT, AUCKLAND, AUCKLAND, NZ. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:21:37:00 | Win2K-f | 66.60.106.38 (FIRSTDIGITAL.COM): FIRSTDIGITAL COMMUNICATIONS LLC, ROSEVILLE, CALIFORNIA, US. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:21:44:00 | Win2K-f | 50.14.194.187 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:21:53:00 | WinXP | 117.19.115.241 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:22:55:00 | WinXP | 4.176.120.38 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, ALBUQUERQUE, NEW MEXICO, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 87 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:23:16:00 | Win2K-f | 175.124.143.165 (-): . |
83.133.119.197:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:shabi.coolnuff.com :newvodavoda.com IT:mewgost.com CN:w.nucleardiscover.com CN:ru.coolnuff.com IT:wertlist.com IT:195.14.112.197:80 CN:60.190.223.75:2012 CN:60.190.223.75:888 |
135 | pcap | raw alerts ruleset |
irc http 206 lines |
Yeah : 1.8 profile |
none | summary tarball |
10 of 43 31 of 42 30 of 33 29 of 43 38 of 42 29 of 41 |
357f35fbb9 NEW 44a384864c NEW 533d15b5ce NEW 564048b35d NEW 7652503978 NEW 87101f64b4 NEW |
none[none] none [none] c67adf46e2[0] none [none] none [none] none [none] |
none:none none:none ASM:Graph none:none none:none none:none |
none|none none|none tElock| none|none none|none none|none |
none none lines=126 embedded dns none none none |
none none trace none none none |
T:23:27:00 | Win2K-f | 113.210.101.195 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, MY. (DSL) |
60.190.222.139:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:shabi.coolnuff.com CN:w.nucleardiscover.com IT:mewgost.com IT:wertlist.com IT:195.14.112.197:80 CN:60.190.223.75:2011 CN:60.190.223.75:2012 CN:60.190.223.75:888 |
445 | pcap | raw alerts ruleset |
irc http 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:23:53:00 | Win2K-f | 14.99.19.66 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
18 of 35 0 of 32 |
218ce30f5c NEW 73f1082158 NEW |
none[3] none [0] |
none:none none:none |
none|none Armadillo| |
none lines=90 |
trace trace |