Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:25:00 | WinXP | 27.98.0.19 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 100 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 40 of 41 |
6a6aaa5b73 NEW 8bde6dd126 NEW |
63889c9976 [0] 885c68f500[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=42 lines=64 embedded dns |
trace trace |
T:01:22:00 | WinXP | 175.124.143.165 (-): . |
83.133.119.197:65520 | DE:proxim.ircgalaxy.pl US:microsoft.com CN:shabi.coolnuff.com EU:nonetnet.com CN:w.nucleardiscover.com CN:ru.coolnuff.com IT:mewgost.com CN:myck.nucleardiscover.com CN:ck3.nucleardiscover.com CN:ck4.nucleardiscover.com CN:seo.hi72.com CN:122.224.18.53:80 DE:83.133.119.197:65520 |
135 | pcap | raw alerts ruleset |
irc http 205 lines |
Yeah : 1.8 profile |
none | summary tarball |
21 of 42 19 of 42 15 of 42 24 of 42 4 of 41 30 of 33 29 of 43 38 of 42 |
03190bc721 NEW 1515bc6da9 NEW 3420de55b8 NEW 46472b11c3 NEW 4be1c730de NEW 533d15b5ce NEW 564048b35d NEW 7652503978 NEW |
none[none] none [none] none [none] none [none] none [none] c67adf46e2[0] none [none] none [none] |
none:none none:none none:none none:none none:none ASM:Graph none:none none:none |
none|none none|none none|none none|none none|none tElock| none|none none|none |
none none none none none lines=126 embedded dns none none |
none none none none none trace none none |
T:02:48:00 | WinXP | 119.154.109.5 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, ISLAMABAD, ISLAMABAD, PK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | cebfbf3c54 NEW |
none[none] | none:none |
none|none | none | none |
T:03:02:00 | WinXP | 175.177.106.124 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:03:28:00 | WinXP | 14.96.170.52 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:04:09:00 | WinXP | 210.166.21.202 (CTT.NE.JP): CABLE TELEVISION TOYAMA INCORPORETED, TOYAMA, TOYAMA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:05:00:00 | WinXP | 14.96.18.214 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:05:11:00 | Win2K-f | 14.96.2.37 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 120 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | 73f1082158 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:05:48:00 | WinXP | 46.203.86.180 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
43 of 43 | 15576ae143 NEW |
none[none] | none:none |
none|none | none | none |
T:05:59:00 | WinXP | 121.245.106.226 (VSNL.NET.IN): DELHI-VSB- LEASED LINE TATA TELESERVICES LTD, DELHI, DELHI, IN. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:06:05:00 | WinXP | 92.47.80.74 (-): JSC KAZAKHTELECOM TALDYKORGAN METRO ETHERNET NETWORK, KZ. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
06:25:00 | Win2K-f | 46.45.128.14 (-): . |
n/a | US:www.maxmind.com :www.getmyip.org EU:getmyip.co.uk :checkip.dyndns.org DE:131.220.6.26:80 US:208.43.124.51:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:06:29:00 | WinXP | 14.99.125.16 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:06:41:00 | WinXP | 187.80.157.0 (CAMPUSEAI.ORG): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 | 3d3a793f61 NEW |
none[none] | none:none |
none|none | none | none |
06:43:00 | WinXP | 114.37.131.21 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:06:59:00 | WinXP | 115.165.82.139 (CATV02.ITSCOM.JP): ITS COMMUNICATIONS INC, KAWASAKI, KANAGAWA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:07:05:00 | WinXP | 77.20.143.179 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, AUGSBURG, BAYERN, DE. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:07:09:00 | Win2K-f | 222.232.195.157 (HANANET.NET): HANARO TELECOM INC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
60.190.222.139:65520 | US:microsoft.com DE:proxim.ircgalaxy.pl CN:shabi.coolnuff.com CN:w.nucleardiscover.com CN:ru.coolnuff.com CN:myck.nucleardiscover.com US:arizonadivorcechildcustody.info US:searchportal.information.com :cdn.dsultra.com US:p.chango.com :domdex.com CN:ck3.nucleardiscover.com :oaktelevisioncabinet.com :batterytelevisiondigital.com |
135 | pcap | raw alerts ruleset |
irc http 205 lines |
Yeah : 1.8 profile |
none | summary tarball |
15 of 42 24 of 42 4 of 41 30 of 33 1 of 42 36 of 41 1 of 41 |
3420de55b8 NEW 46472b11c3 NEW 4be1c730de NEW 533d15b5ce NEW 6bd5d9ca17 NEW a8d5f22a14 NEW e614e86dcb NEW |
none[none] none [none] none [none] c67adf46e2[0] none [none] none [none] none [none] |
none:none none:none none:none ASM:Graph none:none none:none none:none |
none|none none|none none|none tElock| none|none none|none none|none |
none none none lines=126 embedded dns none none none |
none none none trace none none none |
T:07:50:00 | WinXP | 186.110.109.246 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:08:03:00 | Win2K-f | 118.107.218.109 (-): OPTICAL COMMUNICATION ENGINEERING SDN BHD, MY. (DSL) |
n/a | US:askacehardware.com US:audioteleconferencingservices.info US:parklogic.com US:as.casalemedia.com :www.searchmagna.com US:activex.microsoft.com US:codecs.microsoft.com :segment-pixel.invitemedia.com :a.collective-media.net US:ib.adnxs.com :b.collective-media.net 173.223.12.74:80 50.16.78.28:80 US:64.210.61.115:80 |
135 | pcap | raw alerts ruleset |
http irc 32 lines |
Argh : 0.3 profile |
none | summary tarball |
1 of 42 | b2bf299ee4 NEW |
none[none] | none:none |
none|none | none | none |
T:08:18:00 | Win2K-f | 89.153.182.88 (CPE.NETCABO.PT): TVCABO-PORTUGAL CABLE MODEM NETWORK, PT. (DSL) |
n/a | **:coldheatsoldertool.info US:greatdegreeonline.com US:activex.microsoft.com US:codecs.microsoft.com US:9907s.cdnfileserver.com :tagiller.com US:i.nuseek.com :pagead2.googlesyndication.com :whoisprivacyprotect.com US:www.whoisprivacyprotect.com :smallz.com :www.google-analytics.com :freecreditreport-47.com DE:proxim.ircgalaxy.pl DE:83.133.119.197:65520 |
445 | pcap | raw alerts ruleset |
http irc 66 lines |
Argh : 0.3 profile |
none | summary tarball |
1 of 42 | 81f03900d8 NEW |
none[none] | none:none |
none|none | none | none |
T:08:25:00 | WinXP | 61.216.232.68 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 43 | 2e1de2483f NEW |
none[none] | none:none |
none|none | none | none |
T:08:32:00 | WinXP | 217.245.71.21 (T-DIALIN.NET): DEUTSCHE TELEKOM AG, BERLIN, BERLIN, DE. (DIAL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 4a02e36717 NEW |
0be1a8e7db [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:14:05:00 | WinXP | 49.15.123.208 (-): . |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | 88f3393e20 NEW |
none[none] | none:none |
none|none | none | none |
T:14:06:00 | WinXP | 89.204.205.73 (O2.IE): O2 IRELAND MOBILE PHONE OPERATOR, DUBLIN, DUBLIN, IE. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
43 of 43 | 9d0e1cdb4a NEW |
none[none] | none:none |
none|none | none | none |
T:14:13:00 | WinXP | 186.109.70.245 (-): . |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | f2f3d8239c NEW |
none[none] | none:none |
none|none | none | none |
T:15:08:00 | WinXP | 151.82.142.77 (51-151.NET24.IT): IUNET-BNET, IT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
15:13:00 | WinXP | 187.160.60.16 (NIC-R2-R1-MTY.NIC.MX): NETWORK INFORMATION CENTER MEXICO, MX. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 42 | 33ffb2cb88 NEW |
none[none] | none:none |
none|none | none | none |
T:16:11:00 | WinXP | 27.98.22.151 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 41 |
6b315f5dbc NEW 7938865f8c NEW |
7604b94520 [0] a9b9e4904b[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
T:16:27:00 | Win2K-f | 50.84.152.35 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 40 |
474acf88e5 NEW 68f0c14692 NEW |
1f53944b24 [0] ccc1b24d53[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
T:18:10:00 | WinXP | 178.167.215.223 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:18:14:00 | WinXP | 174.42.140.178 (WINDSTREAM.NET): ALLTEL MIP CUSTOMERS - WARRENSVILLE HEIGHTS, CHARLOTTE, NORTH CAROLINA, US. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:18:51:00 | WinXP | 186.255.69.208 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 95d1a78f0d NEW |
none[none] | none:none |
none|none | none | none |
T:19:13:00 | WinXP | 187.46.0.67 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, SãO PAULO, SAO PAULO, BR. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 5c6df5141d NEW |
none[none] | none:none |
none|none | none | none |
T:20:06:00 | WinXP | 61.215.137.22 (CABLENET.NE.JP): CABLENET SAITAMA CO. LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 43 41 of 42 |
4f4bbf29ec NEW 743e8678f4 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:20:41:00 | WinXP | 118.83.10.5 (HTOJ.J-CNET.JP): JCN-HTMNET, HACHIOJI, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 100 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 2 of 32 |
607b60ad51 NEW e5c7bce70e NEW |
none[4] e5c7bce70e[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:21:12:00 | Win2K-f | 70.65.56.152 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, RED DEER, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1008 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 41 | 682a384fe9 NEW |
none[3] | none:none |
none|none | none | trace | |
T:22:11:00 | WinXP | 186.254.144.140 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:23:11:00 | Win2K-f | 72.45.61.112 (ATLANTICBB.NET): ATLANTIC BROADBAND, MIDDLETOWN, DELAWARE, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:23:46:00 | WinXP | 211.124.227.242 (ZAQ.NE.JP): K CABLE TELEVISION CORPORATION INC, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 18 of 35 |
07fabc79ef NEW 218ce30f5c NEW |
none[0] none [3] |
none:none none:none |
Armadillo| none|none |
lines=90 none |
trace trace |