Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:33:00 | WinXP | 211.75.234.92 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1009 lines |
Yeah : 1.3 profile |
none | summary tarball |
17 of 41 | e1693609f9 NEW |
none[3] | none:none |
none|none | none | trace | |
T:00:51:00 | WinXP | 83.242.198.196 (PERIODICALS.RU): COMSTAR TELECOMMUNICATIONS LTD, RU. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
01:07:00 | WinXP | 82.81.18.142 (BEZEQINT.NET): ADSL-CUSTOMER-CONNECTION, TEL AVIV, TEL AVIV, IL. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:02:30:00 | WinXP | 112.110.4.106 (-): GPRS VAS SERVICES, DELHI, DELHI, IN. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | d6df3972a0 NEW |
none[0] | none:none |
PolyEnE| | lines=65 | trace |
T:02:36:00 | WinXP | 117.19.231.199 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
02:58:00 | WinXP | 180.177.70.126 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 42 | 194a3a1b0f NEW |
none[none] | none:none |
none|none | none | none |
T:03:54:00 | WinXP | 14.98.124.207 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:04:04:00 | WinXP | 180.207.202.136 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
04:30:00 | Win2K-f | 201.33.23.182 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk US:www.vouchercodes.net DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 1006 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:05:08:00 | WinXP | 46.203.56.65 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
43 of 43 | 15576ae143 NEW |
none[none] | none:none |
none|none | none | none |
T:05:14:00 | Win2K-f | 202.170.187.152 (CCNET-AI.NE.JP): COMMUNITY NETWORK CENTER INC, TOYOKAWA, AICHI, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
none:none ASM:Graph |
Armadillo| tElock| |
lines=90 lines=75 embedded dns |
trace trace |
T:06:32:00 | WinXP | 59.117.64.108 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 42 | eae907d977 NEW |
none[none] | none:none |
none|none | none | none |
T:06:36:00 | WinXP | 92.251.140.178 (-): H3G IRELAND SUBSCRIBERS, IE. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:06:58:00 | WinXP | 46.202.189.108 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 169a5d5c84 NEW |
none[none] | none:none |
none|none | none | none | |
T:07:21:00 | WinXP | 41.97.183.99 (196-46-248-WIMAX.SLC.DZ): AFRINIC, DZ. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | 5c6df5141d NEW |
none[none] | none:none |
none|none | none | none |
T:07:44:00 | WinXP | 77.22.47.71 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BERLIN, BERLIN, DE. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 6ce2f9af19 NEW |
none[none] | none:none |
none|none | none | none |
T:08:08:00 | WinXP | 120.138.141.152 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
6a1dc43309 NEW 94e49d5627 NEW |
522dace6c1 [0] 777259292a[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:09:10:00 | Win2K-f | 222.237.152.64 (HANANET.NET): HANARO TELECOM INC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
83.133.119.197:65520 | US:microsoft.com DE:proxima.ircgalaxy.pl CN:shabi.coolnuff.com IT:wertlist.com CN:w.nucleardiscover.com CN:ru.coolnuff.com CN:myck.nucleardiscover.com :buyusedpantiesonline.com CN:ck3.nucleardiscover.com :flaskett.com IT:mewgost.com CN:ck4.nucleardiscover.com US:football-infoputer.info :theatermoviereviews.com US:biometrictimeclockdevice.com CN:hn.yigeyuming.com :robotshoppe.com US:chasecreditcardapply.info :seo.hi72.com :federalconsolidationloaninfo.com US:seperationadvisory.com CN:60.190.223.75:2012 DE:83.133.119.197:65520 |
135 | pcap | raw alerts ruleset |
irc http 176 lines |
Yeah : 1.8 profile |
none | summary tarball |
19 of 42 15 of 42 24 of 42 4 of 41 29 of 43 39 of 41 29 of 43 31 of 33 |
1515bc6da9 NEW 3420de55b8 NEW 46472b11c3 NEW 4be1c730de NEW 564048b35d NEW ab9c4b5f21 NEW b34e640329 NEW d789c8d157 NEW |
none[none] none [none] none [none] none [none] none [none] 5fe48b2dcc[0] none [none] 5f6572479f[0] |
none:none none:none none:none none:none none:none ASM:Graph none:none ASM:Graph |
none|none none|none none|none none|none none|none Armadillo| none|none PolyEnE| |
none none none none none lines=42 none lines=113 embedded dns |
none none none none none trace none trace |
T:09:12:00 | Win2K-f | 1.224.253.194 (-): . |
n/a | DE:irc.zief.pl US:microsoft.com :ii.ebatmoyhuy.com CN:shabi.coolnuff.com CN:w.nucleardiscover.com CN:ru.coolnuff.com CN:myck.nucleardiscover.com :televisionpricescomparison.com CN:ck3.nucleardiscover.com US:christmasscore.com US:zoo.parkingspa.com CN:ck4.nucleardiscover.com US:i.nuseek.com CN:60.190.223.132:88 |
135 | pcap | raw alerts ruleset |
irc http 357 lines |
Yeah : 1.3 profile |
none | summary tarball |
24 of 42 19 of 42 15 of 42 37 of 41 40 of 41 24 of 42 4 of 41 |
053e020371 NEW 1515bc6da9 NEW 3420de55b8 NEW 34cd9e2f76 NEW 376a6b6ecd NEW 46472b11c3 NEW 4be1c730de NEW |
none[none] none [none] none [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none none|none none|none |
none none none none none none none |
none none none none none none none |
T:09:22:00 | Win2K-f | 70.24.235.254 (BELL.CA): SYMPATICO HSE, MONTREAL, QUEBEC, CA. (DSL) |
n/a | US:discountpriceusa.com US:genometestingservice.com US:as.casalemedia.com CA:www.searchnut.com US:activex.microsoft.com US:codecs.microsoft.com DE:www.sedoparking.com :a.95622.com CN:w.nucleardiscover.com US:illinoistollay.com CA:www.ndparking.com CN:s5.perfectexe.com :seo.hi72.com :gameathletes.com :sponsoredbanking.com CN:s5.mainpage.cc US:vipmoneypoker.com US:gambling-medicine.info |
135 | pcap | raw alerts ruleset |
http 27 lines |
Yeah : 0.8 profile |
none | summary tarball |
35 of 42 1 of 42 24 of 41 1 of 42 9 of 42 |
1af296e06c NEW 72c59be051 NEW 806ec886a5 NEW c41d181c7a NEW e4240d7958 NEW |
none[none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none |
none none none none none |
none none none none none |
T:09:29:00 | Win2K-f | 112.110.123.10 (-): ICL-NET, DELHI, DELHI, IN. (DIAL) |
n/a | :progegew.com US:caballw.com US:i.nuseek.com :pagead2.googlesyndication.com CN:w.nucleardiscover.com US:as.casalemedia.com CN:ru.coolnuff.com CN:s5.perfectexe.com CA:www.searchnut.com US:activex.microsoft.com US:codecs.microsoft.com :seo.hi72.com US:p.chango.com :whoisprivacyprotect.com :rebelstring.com US:sport-india.info US:hot-cruise.info |
445 | pcap | raw alerts ruleset |
http irc 58 lines |
Yeah : 0.8 profile |
none | summary tarball |
15 of 42 9 of 42 31 of 42 1 of 42 9 of 42 |
3420de55b8 NEW 851790f318 NEW aa85153745 NEW d183ace3be NEW e4240d7958 NEW |
none[none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none |
none none none none none |
none none none none none |
T:09:29:00 | WinXP | 211.58.225.159 (HANANET.NET): HANARO TELECOM INC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
83.133.119.197:65520 | DE:proxima.ircgalaxy.pl US:microsoft.com CN:shabi.coolnuff.com CN:w.nucleardiscover.com CN:ru.coolnuff.com CN:myck.nucleardiscover.com **:coldheatsolderingironreview.info CN:ck3.nucleardiscover.com US:collegedegreeworld.com US:as.casalemedia.com CA:www.searchnut.com US:activex.microsoft.com US:codecs.microsoft.com US:p.chango.com CN:ck4.nucleardiscover.com US:billconsolidationloannocollateral.info :movietrailersnowplaying.com :threadsreame.com :2010-freescoreusa.com :chinamytown.com :findamovietheaternearyou.com US:ksa.name US:studentloanrefinancetitle.com :seo.hi72.com US:insurance-food.net :lifeinsuranceonlineapply.com US:financecamping.net :btdcorporation.com :creditreportseeker.com US:howdoifindalawyer.com |
135 | pcap | raw alerts ruleset |
irc http 188 lines |
Yeah : 1.8 profile |
none | summary tarball |
33 of 35 19 of 42 15 of 42 24 of 42 4 of 41 40 of 42 1 of 42 |
09d6505627 NEW 1515bc6da9 NEW 3420de55b8 NEW 46472b11c3 NEW 4be1c730de NEW 55249eab15 NEW 8e75862ec8 NEW |
5c860f7b2f [0] none [none] none [none] none [none] none [none] none [none] none [none] |
ASM:Graph none:none none:none none:none none:none none:none none:none |
tElock| none|none none|none none|none none|none none|none none|none |
lines=112 embedded dns none none none none none none |
trace none none none none none none |
T:09:38:00 | Win2K-f | 186.110.123.208 (-): . |
n/a | US:superbroadbandsite.com **:federalconsolidatedloan.info US:closingcostmortgagerefinancing.info US:loansbankcredit.com US:searchportal.information.com US:financecinema.net US:as.casalemedia.com CA:www.searchnut.com US:activex.microsoft.com US:codecs.microsoft.com :www.searchmagna.com US:9907s.cdnfileserver.com IT:wertlist.com US:p.chango.com CN:ru.coolnuff.com :homerefinancingonlinenow.com DE:proxima.ircgalaxy.pl :moviesynopses.com US:zoo.parkingspa.com :theatermoviestimes.com :astronomyoutreach.com |
445 | pcap | raw alerts ruleset |
http 28 lines |
Argh : 0.3 profile |
none | summary tarball |
0 of 42 1 of 42 |
ae72f10549 NEW ce54b51815 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:09:40:00 | Win2K-f | 123.193.117.52 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:knbc7.com :1.95622.com :individualusers.com CN:w.nucleardiscover.com US:activex.microsoft.com US:codecs.microsoft.com :tipofftourney.com US:p.chango.com US:searchportal.information.com :cdn.dsultra.com :domdex.com US:automatic-tracking.com :abrigarte.com US:medicine-sell.info DE:irc.zief.pl CN:s5.perfectexe.com DE:proxim.ircgalaxy.pl CN:s5.mainpage.cc CN:myck.nucleardiscover.com US:broker-film.info US:loandrugstore.net US:wiiea.com US:modelsebuy.info US:togetloans.com US:lottolesbian.info :irelandpsychics.com US:petslungcancer.net CN:ck4.nucleardiscover.com :housenmembers.com :truckshair.info |
445 | pcap | raw alerts ruleset |
http 31 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:09:45:00 | WinXP | 184.0.9.90 (EMBARQHSD.NET): EMBARQ CORPORATION, US. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:12:44:00 | WinXP | 94.253.176.167 (XNET.HR): BNET HRVATSKA, HR. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | 6e6fde936f NEW |
none[none] | none:none |
none|none | none | none |
T:14:19:00 | Win2K-f | 24.233.74.234 (SUBURBANCOMPANIES.COM): BRAINTREE ELECTRIC LIGHT DEPARTMENT, BRAINTREE, MASSACHUSETTS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 187 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | 0afff56a4c NEW |
none[none] | none:none |
none|none | none | none | |
T:14:35:00 | WinXP | 173.182.111.71 (TELUS.NET): TELUS COMMUNICATIONS INC, BURNABY, BRITISH COLUMBIA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:14:55:00 | WinXP | 95.83.197.2 (-): O2 IRELAND MOBILE BROADBAND OPEN.INTERNET APN, DUBLIN, DUBLIN, IE. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
43 of 43 | 9d0e1cdb4a NEW |
none[none] | none:none |
none|none | none | none |
T:17:31:00 | Win2K-f | 121.245.137.237 (-): MUMBAI-LVSB- LEASED LINE TATA TELESERVICES LTD, LUCKNOW, UTTAR PRADESH, IN. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:21:00 | WinXP | 61.218.205.52 (HINET.NET): TAIWAN PROVINCE TAP-WATER CO. LTD, KAOHSIUNG, T'AI-WAN, TW. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 43 41 of 42 |
4f4bbf29ec NEW 743e8678f4 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:19:56:00 | WinXP | 190.132.111.96 (ANTELDATA.NET.UY): ANCEL, UY. (DIAL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 5c6df5141d NEW |
none[none] | none:none |
none|none | none | none |
T:20:07:00 | WinXP | 24.155.109.152 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS AUSTIN HUB, AUSTIN, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:21:15:00 | WinXP | 24.155.252.89 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS ODESSA HUB, WACO, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:21:43:00 | Win2K-f | 61.16.165.227 (DIRECT.NET.IN): TATA COMMUNICATIONS INTERNET SERVICES LTD, BANGALORE, KARNATAKA, IN. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
703674dc37 NEW c55e86f7e9 NEW |
none[none] c790c10ad1[0] |
none:none ASM:Graph |
none|none tElock| |
none lines=64 embedded dns |
none trace |
T:22:25:00 | WinXP | 4.224.141.26 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, INDIANAPOLIS, INDIANA, US. (DIAL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a0139d7ad8 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
23:11:00 | Win2K-f | 61.7.151.98 (-): 10 FL. 72. CAT TELECOM TOWER BANGRAK BANGKOK THAILAND, BANGKOK, KRUNG THEP, TH. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk US:www.vouchercodes.net :www.getmyip.org EU:checkip.dyndns.org DE:131.220.6.26:80 US:217.160.239.39:80 EU:91.198.22.71:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 7587773eea NEW |
none[3] | none:none |
StarForce| | none | trace |
T:23:20:00 | Win2K-f | 61.7.151.98 (-): 10 FL. 72. CAT TELECOM TOWER BANGRAK BANGKOK THAILAND, BANGKOK, KRUNG THEP, TH. (DSL) |
n/a | US:www.maxmind.com :www.getmyip.org EU:getmyip.co.uk US:www.vouchercodes.net :checkip.dyndns.org DE:131.220.6.26:80 US:217.160.239.39:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 7587773eea NEW |
none[3] | none:none |
StarForce| | none | trace |
T:23:42:00 | WinXP | 151.83.89.146 (SER-PR2-MAX.IUNET.IT): INFOSTRADA, IT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | d11b1f56f9 NEW |
none[none] | none:none |
none|none | none | none |