Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:36:00 | WinXP | 115.80.157.47 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 420b1a76c4 NEW |
none[none] | none:none |
none|none | none | none |
T:00:51:00 | Win2K-f | 1.230.89.60 (-): . |
60.190.222.139:65520 | US:microsoft.com CN:proxim.ircgalaxy.pl CN:shabi.coolnuff.com CN:w.nucleardiscover.com CN:ru.coolnuff.com CN:myck.nucleardiscover.com **:laserhairremovaltrainingnewyork.info CN:ck3.nucleardiscover.com :rasamayee.com US:i.nuseek.com :pagead2.googlesyndication.com CN:ck4.nucleardiscover.com CN:60.190.223.132:88 |
135 | pcap | raw alerts ruleset |
irc http 150 lines |
Yeah : 1.8 profile |
none | summary tarball |
19 of 42 15 of 42 4 of 41 36 of 42 22 of 43 38 of 42 |
1515bc6da9 NEW 3420de55b8 NEW 4be1c730de NEW bf063bba17 NEW e01c2589dc NEW f269760f66 NEW |
none[none] none [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none none|none |
none none none none none none |
none none none none none none |
T:00:59:00 | Win2K-f | 125.230.54.91 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | CA:hotelsuer.com US:p.chango.com CN:s5.perfectexe.com US:193082.r.msn.com US:bluesky-movie.com 117.32.189.254:7224 **:169.254.88.102:707 CN:61.147.123.53:1056 |
135 | pcap | raw alerts ruleset |
http irc 40 lines |
Yeah : 0.8 profile |
none | summary tarball |
9 of 42 | e4240d7958 NEW |
none[none] | none:none |
none|none | none | none |
T:01:12:00 | WinXP | 203.196.71.205 (KAGACABLE.NE.JP): KAGA CABLE TELEVISION CO.LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 40 of 41 |
2fc89991b2 NEW 7bdf45b79a NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:01:22:00 | Win2K-f | 87.2.128.249 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A. TIN EASY LITE, MILANO, LOMBARDIA, IT. (DSL) |
n/a | CN:myck.nucleardiscover.com US:thedegreeprograms.com US:federalconsolidationloanapplication.info US:as.casalemedia.com US:activex.microsoft.com US:codecs.microsoft.com US:bandomercantil.com US:63.80.242.19:80 CA:74.117.116.125:80 |
445 | pcap | raw alerts ruleset |
http 30 lines |
Argh : 0.3 profile |
none | summary tarball |
1 of 43 | c878167e01 NEW |
none[none] | none:none |
none|none | none | none |
T:01:43:00 | WinXP | 31.18.154.131 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 5f186aa322 NEW |
none[none] | none:none |
none|none | none | none |
T:02:22:00 | WinXP | 67.208.246.18 (BLK1.NET): ARIALINK, LANSING, MICHIGAN, US. (DSL) |
n/a | :gg.arrancar.org | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 | f91839432e NEW |
none[none] | none:none |
none|none | none | none |
T:02:44:00 | WinXP | 123.193.240.250 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 9276456bf8 NEW |
none[none] | none:none |
none|none | none | none |
02:51:00 | WinXP | 151.54.122.223 (51-151.NET24.IT): IUNET-BNET, VENICE, VENETO, IT. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 | 94e76c7ef4 NEW |
none[none] | none:none |
none|none | none | none |
T:02:54:00 | WinXP | 79.133.150.53 (-): ADSL USERS, RU. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:04:05:00 | Win2K-f | 70.77.72.254 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, PRINCE GEORGE, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1008 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 41 | 682a384fe9 NEW |
none[3] | none:none |
none|none | none | trace | |
T:04:21:00 | Win2K-f | 14.96.212.111 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:05:06:00 | WinXP | 123.193.138.5 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 9276456bf8 NEW |
none[none] | none:none |
none|none | none | none |
06:44:00 | WinXP | 123.193.138.5 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 9276456bf8 NEW |
none[none] | none:none |
none|none | none | none |
07:33:00 | WinXP | 112.202.23.227 (PLDT.NET): IPG, CEBU, CEBU CITY, PH. (DIAL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:08:16:00 | Win2K-f | 211.124.224.82 (ZAQ.NE.JP): K CABLE TELEVISION CORPORATION INC, OSAKA, OSAKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
none:none ASM:Graph |
Armadillo| tElock| |
lines=90 lines=75 embedded dns |
trace trace |
08:37:00 | WinXP | 93.102.73.237 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, AVEIRO, AVEIRO, PT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:08:58:00 | WinXP | 93.102.182.59 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, PT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
43 of 43 | ff17997b9f NEW |
none[none] | none:none |
none|none | none | none |
T:09:21:00 | WinXP | 61.215.166.3 (CABLENET.NE.JP): CABLENET SAITAMA CO. LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
761a66b891 NEW 98d05c039b NEW |
b469dac5dc [0] none [none] |
ASM:Graph none:none |
tElock| none|none |
lines=64 embedded dns none |
trace none |
T:09:47:00 | WinXP | 82.81.180.216 (BEZEQINT.NET): ADSL-CUSTOMER-CONNECTION, JERUSALEM, YERUSHALAYIM, IL. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:10:14:00 | WinXP | 189.118.113.77 (TIMBRASIL.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, RIO DE JANEIRO, RIO DE JANEIRO, BR. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 5c6df5141d NEW |
none[none] | none:none |
none|none | none | none |
T:10:45:00 | WinXP | 118.233.116.97 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 43 | aa84aca646 NEW |
none[none] | none:none |
none|none | none | none |
10:54:00 | WinXP | 118.233.116.97 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 43 | aa84aca646 NEW |
none[none] | none:none |
none|none | none | none |
T:13:35:00 | WinXP | 95.88.0.85 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BERLIN, BERLIN, DE. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 43 | 3ef772fcd5 NEW |
none[none] | none:none |
none|none | none | none |
T:13:55:00 | WinXP | 24.234.237.249 (COX.NET): COX COMMUNICATIONS INC, LAS VEGAS, NEVADA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:17:00 | Win2K-f | 122.146.240.120 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:14:35:00 | WinXP | 87.20.42.92 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A. TIN EASY LITE, MODENA, EMILIA-ROMAGNA, IT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:14:45:00 | Win2K-f | 14.96.91.56 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:15:22:00 | WinXP | 216.47.38.95 (SPEAKEASY.NET): WORCESTER, MASSACHUSETTS, US. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 1096ba143e NEW |
none[none] | none:none |
none|none | none | none |
15:42:00 | WinXP | 216.47.38.95 (SPEAKEASY.NET): WORCESTER, MASSACHUSETTS, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 1096ba143e NEW |
none[none] | none:none |
none|none | none | none |
T:16:19:00 | Win2K-f | 65.19.251.75 (VNET-INC.COM): TRIANGLE TELEPHONE, ENNIS, MONTANA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 115 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:16:20:00 | WinXP | 62.120.25.208 (-): ETTIHADETISALAT, RIYADH, AR RIYAD, SA. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:16:24:00 | WinXP | 187.82.134.236 (CAMPUSEAI.ORG): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.8 profile |
none | summary tarball |
41 of 41 | 5c6df5141d NEW |
none[none] | none:none |
none|none | none | none |
T:19:07:00 | WinXP | 124.45.57.128 (WAKWAK.NE.JP): NTT-ME CORPORATION, TOKYO, TOKYO, JP. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
19:51:00 | Win2K-f | 46.45.184.76 (-): . |
n/a | US:www.maxmind.com EU:getmyip.co.uk US:www.vouchercodes.net US:208.43.124.51:80 |
445 | pcap | raw alerts ruleset |
http 1003 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:20:11:00 | WinXP | 115.82.30.137 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:20:56:00 | WinXP | 70.60.14.52 (RR.COM): ROAD RUNNER HOLDCO LLC, CIRCLEVILLE, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 41 |
0563ea7af7 NEW 7e1532574f NEW |
bc2e11a802 [0] e6930769d0[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=65 embedded dns lines=91 |
trace trace |
T:22:05:00 | WinXP | 223.16.250.113 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
22:07:00 | WinXP | 119.154.183.46 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, ISLAMABAD, ISLAMABAD, PK. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 1096ba143e NEW |
none[none] | none:none |
none|none | none | none |
T:22:25:00 | WinXP | 81.198.178.11 (-): ADDRESS POOL FOR LTC-HOME CUSTOMERS, RIGA, RIGA, LV. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
42 of 42 | efdb61e0c2 NEW |
none[none] | none:none |
none|none | none | none |
T:22:36:00 | Win2K-f | 61.58.150.235 (TINP.NET.TW): TAIWAN INFRASTRUCTURE NETWORK TECHNOLOGIES, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:23:30:00 | Win2K-f | 24.155.156.219 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS WACO, WOODWAY, TEXAS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |