Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:42:00 | WinXP | 188.176.70.54 (DSL.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, DK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:00:54:00 | WinXP | 212.233.182.3 (-): OPTISPRINT, BG. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 115 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 43 41 of 43 |
06bb6ed423 NEW 917c47aa26 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:02:34:00 | WinXP | 178.90.73.33 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace | |
T:04:01:00 | WinXP | 118.233.133.71 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:04:27:00 | Win2K-f | 14.98.224.132 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:04:51:00 | WinXP | 115.165.194.128 (-): PHOENIX CATV CO. LTD, TW. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
05:52:00 | WinXP | 119.154.184.104 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, ISLAMABAD, ISLAMABAD, PK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:06:10:00 | WinXP | 27.97.221.239 (-): . |
n/a | DE:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 04d4170d3b NEW |
none[none] | none:none |
none|none | none | none |
T:06:49:00 | WinXP | 59.113.96.205 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:07:02:00 | WinXP | 173.211.174.77 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 157 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
68b5e580f0 NEW b475ce7c0b NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:07:15:00 | WinXP | 124.241.157.210 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 39 of 39 |
b8e6f4caf7 NEW fb92b91fe7 NEW |
f81eac6379 [0] fe88ab8768[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:07:28:00 | Win2K-f | 208.88.70.103 (-): BBW 4 ACES TOWER CUSTOMER SUBNET, SHREVEPORT, LOUISIANA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:29:00 | WinXP | 115.165.80.32 (CATV02.ITSCOM.JP): ITS COMMUNICATIONS INC, KAWASAKI, KANAGAWA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:07:31:00 | Win2K-f | 202.156.205.207 (MAXONLINE.COM.SG): STARHUB CABLE VISION LTD, SINGAPORE, SINGAPORE, SG. (DSL) |
n/a | DE:ilo.brenz.pl CN:shabi.coolnuff.com CN:w.nucleardiscover.com CN:ru.coolnuff.com CN:myck.nucleardiscover.com US:coldsolderingguns.info US:searchportal.information.com CN:ck3.nucleardiscover.com :cdn.dsultra.com :domdex.com :lapepitadeoro.com US:p.chango.com 208.93.137.180:80 |
135 | pcap | raw alerts ruleset |
http 480 lines |
Yeah : 1.3 profile |
none | summary tarball |
20 of 38 15 of 42 4 of 41 36 of 42 |
070728ba00 NEW 3420de55b8 NEW 4be1c730de NEW 80041772de NEW |
none[none] none [none] none [none] none [none] |
none:none none:none none:none none:none |
none|none none|none none|none none|none |
none none none none |
none none none none |
T:07:38:00 | WinXP | 77.20.202.123 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, HAMBURG, HAMBURG, DE. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:07:45:00 | Win2K-f | 98.89.56.75 (BELLSOUTH.NET): BELLSOUTH.NET INC, ATLANTA, GEORGIA, US. (DSL) |
n/a | CN:w.nucleardiscover.com :flightmultimedia.com US:i.nuseek.com :federalconsolidationloansinfo.com :www.google-analytics.com :pagead2.googlesyndication.com :whoisprivacyprotect.com US:www.whoisprivacyprotect.com US:calemonlawtoday.com US:lawyergenome.net US:as.casalemedia.com CA:www.searchnut.com :actiongameflash.com DE:ilo.brenz.pl :shfmra.com CN:ck3.nucleardiscover.com US:onlinecourseaccounting.com :uweqez.com CA:princewilliamdaughter.com :jfdfau.com US:mobilecomputingtechnology.com US:bioengineeringcenter.com :vcmpef.com US:biometricdevices.org :blkztu.com US:biasmoney.com US:quoteclevelandbankers.info :uqjuuf.com US:makemoneyin4days.com :eequsl.com CN:myck.nucleardiscover.com :uicgqi.com :yiarnl.com |
445 | pcap | raw alerts ruleset |
http 65 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 43 1 of 43 |
b34e640329 NEW bcf5b9f7f1 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:08:25:00 | WinXP | 94.243.92.104 (NS2.ORANGE.MD): ORANGE MOLDOVA NETWORK, CHISINAU, CHISINAU, MD. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 95d1a78f0d NEW |
none[none] | none:none |
none|none | none | none |
08:46:00 | WinXP | 187.80.1.139 (CAMPUSEAI.ORG): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:09:16:00 | WinXP | 189.119.153.163 (TIMBRASIL.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
09:22:00 | WinXP | 189.119.153.163 (TIMBRASIL.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:10:32:00 | WinXP | 190.58.16.63 (TSTT.NET.TT): TELECOMMUNICATION SERVICES OF TRINIDAD AND TOBAGO, ARIMA, ARIMA, TT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:10:36:00 | Win2K-f | 24.155.156.219 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS WACO, WOODWAY, TEXAS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:11:06:00 | WinXP | 82.81.235.231 (BEZEQINT.NET): ADSL-CUSTOMER-CONNECTION, AKKO, HAZAFON, IL. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:12:03:00 | WinXP | 49.15.31.233 (-): . |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 9276456bf8 NEW |
none[none] | none:none |
none|none | none | none |
T:13:09:00 | WinXP | 115.130.2.96 (-): 3G MOBILE SERVICE PROVIDER, ELTHAM, VICTORIA, AU. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:25:00 | WinXP | 87.18.45.176 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A. TIN EASY LITE, BERGAMO, LOMBARDIA, IT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:16:52:00 | WinXP | 186.198.177.87 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 1096ba143e NEW |
none[none] | none:none |
none|none | none | none |
17:48:00 | Win2K-f | 201.88.109.142 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk US:www.vouchercodes.net US:208.43.124.51:80 |
445 | pcap | raw alerts ruleset |
http 1003 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | d60e538e72 NEW |
none[3] | none:none |
UPX| | none | trace |
17:48:00 | Win2K-f | 190.254.8.234 (TELEFONICA.NET.CO): COLOMBIA TELECOMUNICACIONES S.A. ESP, ARMENIA, QUINDIO, CO. (DSL) |
n/a | US:www.maxmind.com EU:checkip.dyndns.org US:208.43.124.51:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | d60e538e72 NEW |
none[3] | none:none |
UPX| | none | trace |
T:17:54:00 | Win2K-f | 24.234.237.249 (COX.NET): COX COMMUNICATIONS INC, LAS VEGAS, NEVADA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:17:56:00 | Win2K-f | 201.88.109.142 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | US:www.maxmind.com :www.getmyip.org EU:getmyip.co.uk US:www.vouchercodes.net DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 1007 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | d60e538e72 NEW |
none[3] | none:none |
UPX| | none | trace |
T:17:58:00 | WinXP | 14.96.170.8 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 86 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:26:00 | Win2K-f | 24.155.16.138 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS ODESSA HUB, ODESSA, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:18:28:00 | WinXP | 175.112.16.4 (-): . |
60.190.222.139:65520 | DE:proxim.ircgalaxy.pl US:microsoft.com CN:shabi.coolnuff.com CN:w.nucleardiscover.com EU:nonetnet.com CN:ru.coolnuff.com IT:mewgost.com CN:myck.nucleardiscover.com :freecreditscore-27.com US:searchportal.information.com CN:ck3.nucleardiscover.com :pagead2.googlesyndication.com :googleads.g.doubleclick.net :cdn.dsultra.com 208.93.137.180:80 |
135 | pcap | raw alerts ruleset |
irc http 139 lines |
Yeah : 1.8 profile |
none | summary tarball |
20 of 38 15 of 42 27 of 43 4 of 41 29 of 43 36 of 42 38 of 42 |
070728ba00 NEW 3420de55b8 NEW 3cabb079e2 NEW 4be1c730de NEW 564048b35d NEW bf063bba17 NEW f269760f66 NEW |
none[none] none [none] none [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none none|none none|none |
none none none none none none none |
none none none none none none none |
T:18:52:00 | WinXP | 219.105.96.22 (ADACHI.NE.JP): CABLE TELEVISION ADACHI CORP, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
19:12:00 | WinXP | 173.29.239.119 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, CHANHASSEN, MINNESOTA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 1fcc146d70 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:19:43:00 | Win2K-f | 96.8.188.78 (GVTC.COM): GUADALUPE VALLEY TELEPHONE COOPERATIVE INC, NEW BRAUNFELS, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 40 |
9bdd2c95b1 NEW cd456ac095 NEW |
d1bbd693ba [0] d75caee680[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:19:44:00 | WinXP | 117.104.16.102 (T-COM.NE.JP): TOKAI CORPORATION, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 40 of 41 |
6a6aaa5b73 NEW 8bde6dd126 NEW |
63889c9976 [0] 885c68f500[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=42 lines=64 embedded dns |
trace trace |
19:45:00 | WinXP | 50.72.77.170 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 123 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 38 of 41 |
34cbe7a593 NEW 3e83a2d4d7 NEW |
d38cb78003 [0] b97fd63d29[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:20:06:00 | WinXP | 175.177.105.211 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:20:19:00 | WinXP | 189.118.1.51 (TIMBRASIL.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, SãO PAULO, SAO PAULO, BR. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 1096ba143e NEW |
none[none] | none:none |
none|none | none | none |
T:20:33:00 | WinXP | 118.111.233.94 (MESH.AD.JP): NEC BIGLOBE LTD, OSAKA, OSAKA, JP. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | 6b04d043c3 NEW |
none[none] | none:none |
none|none | none | none |
T:20:47:00 | Win2K-f | 202.57.14.180 (-): PRIMA-JKT-PANIN, JAKARTA, JAKARTA RAYA, ID. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 41 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 | 53bfe15e91 NEW |
1473091351 [0] | ASM:Graph |
tElock| | lines=75 embedded dns |
trace |
T:21:40:00 | WinXP | 75.95.236.71 (CLEARWIRE-DNS.NET): CLEARWIRE US LLC, HONOLULU, HAWAII, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
21:58:00 | WinXP | 177.30.142.62 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 0cfab99612 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:22:09:00 | Win2K-f | 14.96.137.255 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 21 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:23:56:00 | WinXP | 92.227.35.128 (ALICEDSL.DE): HANSENET-ADSL, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |