Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:10:00 | WinXP | 81.198.224.115 (-): ADDRESS POOL FOR LTC-HOME CUSTOMERS, RIGA, RIGA, LV. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 42 | efdb61e0c2 NEW |
none[none] | none:none |
none|none | none | none |
T:00:27:00 | WinXP | 59.103.194.48 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, ISLAMABAD, ISLAMABAD, PK. (DSL) |
213.155.0.224:80 | CN:in.kolso.pl DE:citi-bank.ru CN:60.190.222.139:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 43 | 6ec16e1c2a NEW |
none[none] | none:none |
none|none | none | none |
T:00:53:00 | WinXP | 61.215.166.3 (CABLENET.NE.JP): CABLENET SAITAMA CO. LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
761a66b891 NEW 98d05c039b NEW |
b469dac5dc [0] none [none] |
ASM:Graph none:none |
tElock| none|none |
lines=64 embedded dns none |
trace none |
T:01:04:00 | Win2K-f | 14.96.124.221 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 79 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:16:00 | WinXP | 180.207.221.10 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
03:40:00 | WinXP | 180.207.221.10 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:04:16:00 | Win2K-f | 211.75.159.211 (KENNY.COM.TW): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:04:20:00 | WinXP | 95.75.123.150 (-): TELECOM ITALIA MOBILE, IT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:05:49:00 | WinXP | 120.138.168.13 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 39 of 39 |
b8e6f4caf7 NEW fb92b91fe7 NEW |
f81eac6379 [0] fe88ab8768[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:06:38:00 | WinXP | 14.99.97.103 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:13:00 | WinXP | 213.66.164.142 (TELIA.COM): TELIA NETWORK SERVICES, DANDERYD, STOCKHOLMS LAN, SE. (DSL) |
n/a | :siliconfireware.ru GB:welcome3.smile.co.uk :wpad GB:195.92.84.198:80 |
445 | pcap | raw alerts ruleset |
http http http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 6c21e2c88b NEW |
none[none] | none:none |
none|none | none | none |
T:08:54:00 | WinXP | 41.56.62.225 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:09:10:00 | WinXP | 111.88.29.87 (HOSTS-WORLDCALL.NET.PK): WORLDCALL TELECOM LTD, PK. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 9276456bf8 NEW |
none[none] | none:none |
none|none | none | none |
T:09:17:00 | WinXP | 119.154.118.128 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, ISLAMABAD, ISLAMABAD, PK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | 9c583a7af3 NEW |
none[none] | none:none |
none|none | none | none |
T:09:41:00 | WinXP | 123.193.223.63 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:11:35:00 | WinXP | 119.154.47.28 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, RAWALPINDI, PUNJAB, PK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | 9c583a7af3 NEW |
none[none] | none:none |
none|none | none | none |
T:11:35:00 | WinXP | 31.18.156.199 (-): . |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | 5f186aa322 NEW |
none[none] | none:none |
none|none | none | none |
T:13:10:00 | WinXP | 208.94.182.79 (KARIBCABLE.COM): KARIB CABLE, KINGSTOWN, SAINT GEORGE, VC. (100Mbps) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 | 751685117f NEW |
none[none] | none:none |
none|none | none | none |
T:13:30:00 | WinXP | 49.15.202.38 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:13:39:00 | Win2K-f | 14.96.54.150 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 89 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
14:18:00 | WinXP | 82.81.16.207 (BEZEQINT.NET): ADSL-CUSTOMER-CONNECTION, TEL AVIV, TEL AVIV, IL. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
16:00:00 | WinXP | 111.88.8.34 (HOSTS-WORLDCALL.NET.PK): WORLDCALL TELECOM LTD, PK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
37 of 42 | 4fb6fba75f NEW |
none[none] | none:none |
none|none | none | none |
T:16:12:00 | WinXP | 177.30.13.160 (-): . |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:16:28:00 | WinXP | 87.49.60.36 (DSL.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, COPENHAGEN, KOBENHAVN, DK. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:17:42:00 | WinXP | 190.181.181.75 (-): . |
190.55.68.94:6667 | IR:cunts.no-ip.org | 135 | pcap | raw alerts ruleset |
irc 432 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 34 | a1db003660 NEW |
none[none] | none:none |
none|none | none | none |
T:18:06:00 | WinXP | 189.220.36.46 (CABLEONLINE.COM.MX): CABLEMAS TELECOMUNICACIONES SA DE CV, MX. (DSL) |
190.55.68.94:6667 | IR:cunts.no-ip.org | 135 | pcap | raw alerts ruleset |
irc 428 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 34 | a1db003660 NEW |
none[none] | none:none |
none|none | none | none |
T:18:06:00 | WinXP | 201.160.212.34 (CABLEONLINE.COM.MX): CABLEMAS TELECOMUNICACIONES (TIJUANA), TIJUANA, MEXICO, MX. (DSL) |
190.55.68.94:6667 | IR:cunts.no-ip.org | 135 | pcap | raw alerts ruleset |
irc 435 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 34 | a1db003660 NEW |
none[none] | none:none |
none|none | none | none |
T:18:08:00 | Win2K-f | 186.18.45.37 (186.IN-ADDR.ARPA): TELECENTRO S.A. - CLIENTES RESIDENCIALES, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
190.55.68.94:6667 | IR:cunts.no-ip.org | 135 | pcap | raw alerts ruleset |
irc 439 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 34 | a1db003660 NEW |
none[none] | none:none |
none|none | none | none |
T:18:08:00 | Win2K-f | 190.105.105.252 (-): . |
190.55.68.94:6667 | IR:cunts.no-ip.org | 135 | pcap | raw alerts ruleset |
irc 464 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 34 | a1db003660 NEW |
none[none] | none:none |
none|none | none | none |
T:18:08:00 | Win2K-f | 186.19.94.229 (-): . |
190.55.68.94:6667 | IR:cunts.no-ip.org | 135 | pcap | raw alerts ruleset |
irc 446 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 34 | a1db003660 NEW |
none[none] | none:none |
none|none | none | none |
T:18:08:00 | WinXP | 190.105.112.213 (-): . |
190.55.68.94:6667 | IR:cunts.no-ip.org | 135 | pcap | raw alerts ruleset |
irc 478 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 34 | a1db003660 NEW |
none[none] | none:none |
none|none | none | none |
T:18:12:00 | WinXP | 190.158.156.211 (DAVITA.COM): TV CABLE S.A, SANTAFé DE BOGOTá, DISTRITO ESPECIAL, CO. (DSL) |
190.55.68.94:6667 | IR:cunts.no-ip.org | 135 | pcap | raw alerts ruleset |
irc 452 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 34 | a1db003660 NEW |
none[none] | none:none |
none|none | none | none |
T:18:25:00 | Win2K-f | 186.227.69.109 (-): . |
190.55.68.94:6667 | IR:cunts.no-ip.org | 135 | pcap | raw alerts ruleset |
irc 707 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 34 | a1db003660 NEW |
none[none] | none:none |
none|none | none | none |
T:18:29:00 | WinXP | 190.209.44.193 (-): TELMEX CHILE S.A HFC, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
190.55.68.94:6667 | IR:cunts.no-ip.org | 135 | pcap | raw alerts ruleset |
irc 447 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 34 | a1db003660 NEW |
none[none] | none:none |
none|none | none | none |
T:18:30:00 | WinXP | 190.147.7.16 (CABLE.NET.CO): TELMEX COLOMBIA S.A, SANTAFé DE BOGOTá, DISTRITO ESPECIAL, CO. (DSL) |
190.55.68.94:6667 | IR:cunts.no-ip.org | 135 | pcap | raw alerts ruleset |
irc 446 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:18:30:00 | Win2K-f | 190.120.161.37 (VOIP.PAPNET.CL): PLUG AND PLAY NET S.A, CL. (DSL) |
190.55.68.94:6667 | IR:cunts.no-ip.org | 135 | pcap | raw alerts ruleset |
irc 535 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:32:00 | WinXP | 201.160.212.34 (CABLEONLINE.COM.MX): CABLEMAS TELECOMUNICACIONES (TIJUANA), TIJUANA, MEXICO, MX. (DSL) |
190.55.68.94:6667 | IR:cunts.no-ip.org | 135 | pcap | raw alerts ruleset |
irc 429 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 34 | a1db003660 NEW |
none[none] | none:none |
none|none | none | none |
T:19:08:00 | WinXP | 184.0.10.59 (EMBARQHSD.NET): EMBARQ CORPORATION, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:19:16:00 | WinXP | 220.228.68.25 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:26:00 | WinXP | 216.211.242.61 (NORWOODLIGHT.COM): NORWOOD LIGHT BROADBAND, NORWOOD, MASSACHUSETTS, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:22:46:00 | WinXP | 49.15.209.231 (-): . |
n/a | DE:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 04d4170d3b NEW |
none[none] | none:none |
none|none | none | none |
T:22:50:00 | WinXP | 61.218.205.52 (HINET.NET): TAIWAN PROVINCE TAP-WATER CO. LTD, KAOHSIUNG, T'AI-WAN, TW. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |