Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
01:52:00 | Win2K-f | 116.86.136.119 (MAXONLINE.COM.SG): STARHUB CABLE VISION LTD, SINGAPORE, SINGAPORE, SG. (DSL) |
n/a | US:www.maxmind.com :getmyip.co.uk :www.getmyip.org EU:checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:03:04:00 | WinXP | 99.93.137.227 (PACBELL.NET): AT&T INTERNET SERVICES, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:35:00 | Win2K-f | 14.98.240.34 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:06:11:00 | WinXP | 180.176.91.135 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 44 | 1334bb0089 NEW |
none[none] | none:none |
none|none | none | none |
T:06:40:00 | WinXP | 39.213.77.44 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 8a2553433c NEW |
none[none] | none:none |
none|none | none | none |
T:06:45:00 | Win2K-f | 208.88.70.103 (-): BBW 4 ACES TOWER CUSTOMER SUBNET, SHREVEPORT, LOUISIANA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:34:00 | WinXP | 176.59.140.203 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 2f6cab0a72 NEW |
none[none] | none:none |
none|none | none | none |
T:07:46:00 | WinXP | 92.36.106.86 (SKYLINK.RU): MOSCOW CELLULAR COMMUNICATIONS, RU. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 8a2553433c NEW |
none[none] | none:none |
none|none | none | none |
08:33:00 | Win2K-f | 211.21.155.58 (HINET.NET): TAIPEI DA HWU DYI FAN NEI COMMUNITY, TAIPEI, T'AI-PEI, TW. (100Mbps) |
n/a | US:www.maxmind.com :getmyip.co.uk EU:checkip.dyndns.org :www.getmyip.org DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
4 of 37 | 8ce32ded17 NEW |
none[3] | none:none |
Armadillo| | none | trace |
T:08:56:00 | WinXP | 178.17.124.155 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 43 | c8d42bea74 NEW |
none[none] | none:none |
none|none | none | none |
T:11:25:00 | WinXP | 182.11.16.21 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 44 | c2e846e9d0 NEW |
none[none] | none:none |
none|none | none | none | |
T:12:22:00 | WinXP | 81.191.91.219 (BLUECOM.NO): VENTELO, OSLO, OSLO, NO. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:12:30:00 | WinXP | 151.83.133.7 (SER-PR2-MAX.IUNET.IT): INFOSTRADA, IT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 8a2553433c NEW |
none[none] | none:none |
none|none | none | none |
T:12:57:00 | WinXP | 151.31.124.16 (31-151.LIBERO.IT): FREE INTERNET DIAL-UP SERVICES, ROME, LAZIO, IT. (DIAL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 44 | 01fc62d237 NEW |
none[none] | none:none |
none|none | none | none |
T:13:36:00 | Win2K-f | 115.130.7.252 (-): 3G MOBILE SERVICE PROVIDER, SYDNEY, NEW SOUTH WALES, AU. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:54:00 | WinXP | 49.134.165.58 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 44 41 of 44 |
99f212a9df NEW 9fa81e360b NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:14:19:00 | WinXP | 95.75.44.180 (-): TELECOM ITALIA MOBILE, IT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 8a2553433c NEW |
none[none] | none:none |
none|none | none | none |
T:14:24:00 | WinXP | 187.46.201.242 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, SãO PAULO, SAO PAULO, BR. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:14:50:00 | WinXP | 119.63.21.215 (CTT.NE.JP): CABLE TELEVISION TOYAMA INCORPORETED, TOYAMA, TOYAMA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:15:23:00 | WinXP | 24.103.10.122 (RR.COM): ROAD RUNNER HOLDCO LLC, NEW YORK, NEW YORK, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:18:04:00 | Win2K-f | 76.190.216.105 (RR.COM): ROAD RUNNER HOLDCO LLC, BEACHWOOD, OHIO, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:09:00 | WinXP | 151.31.91.215 (31-151.LIBERO.IT): FREE INTERNET DIAL-UP SERVICES, VICENZA, VENETO, IT. (DIAL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:21:05:00 | Win2K-f | 175.120.23.168 (-): . |
83.133.119.197:65520 | DE:proxim.ircgalaxy.pl US:microsoft.com CN:sb.degreesbuy.com CN:w.nucleardiscover.com CN:hn.yigeyuming.com :a.95622.com CN:ru.degreesbuy.com :1.95622.com :electricwaterkettle.com :www.electricwaterkettle.com CN:myck.nucleardiscover.com CN:60.190.223.75:888 |
135 | pcap | raw alerts ruleset |
irc http 141 lines |
Yeah : 1.8 profile |
none | summary tarball |
15 of 42 4 of 41 30 of 33 28 of 33 37 of 43 23 of 43 22 of 44 20 of 44 |
3420de55b8 NEW 4be1c730de NEW 533d15b5ce NEW 58c343a8d8 NEW 69f32b85f1 NEW 88ef975791 NEW a904e321f6 NEW d9318bac86 NEW |
none[none] none [none] c67adf46e2[0] none [0] none [none] none [none] none [none] none [none] |
none:none none:none ASM:Graph none:none none:none none:none none:none none:none |
none|none none|none tElock| Armadillo| none|none none|none none|none none|none |
none none lines=126 embedded dns lines=91 none none none none |
none none trace trace none none none none |
T:21:12:00 | Win2K-f | 109.82.1.48 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | US:images01.tzimg.com :domdex.com :www.google-analytics.com US:ib.adnxs.com US:view.atdmt.com :ad.yieldmanager.com CA:pixel.mathtag.com US:ringsmen.org US:dvdjob.com US:as.casalemedia.com :images.ddc.com 66.114.50.85:80 |
445 | pcap | raw alerts ruleset |
http irc 59 lines |
Yeah : 0.8 profile |
none | summary tarball |
1 of 44 9 of 42 |
bb261333cb NEW e4240d7958 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:21:35:00 | Win2K-f | 118.233.188.10 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | :a.95622.com :showerlocator.com CN:w.nucleardiscover.com US:canmotorcycle.com CA:p.internettraffic.com US:as.casalemedia.com :images.ddc.com :domdex.com 67.214.158.5:80 |
445 | pcap | raw alerts ruleset |
http 107 lines |
Argh : 0.3 profile |
none | summary tarball |
1 of 42 | 0de10080bb NEW |
none[none] | none:none |
none|none | none | none |
21:42:00 | WinXP | 68.183.153.203 (DSLEXTREME.COM): DSL EXTREME, LOS ANGELES, CALIFORNIA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 6c56402f1b NEW |
none[none] | none:none |
none|none | none | none |
22:23:00 | WinXP | 109.82.1.48 (JWS.COM): EU-ZZ, UK. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:22:24:00 | WinXP | 151.81.6.162 (51-151.NET24.IT): IUNET-BNET, MILANO, LOMBARDIA, IT. (DIAL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
39 of 44 | 367bf8e150 NEW |
none[none] | none:none |
none|none | none | none |
T:22:39:00 | WinXP | 60.40.78.188 (OCN.NE.JP): OPEN COMPUTER NETWORK, HIROSHIMA, HIROSHIMA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:22:53:00 | Win2K-f | 218.45.207.9 (MS01.ITSCOM.JP): ITSCOM_MANSIONLAN, YOKOHAMA, KANAGAWA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
761a66b891 NEW 98d05c039b NEW |
b469dac5dc [0] none [none] |
ASM:Graph none:none |
tElock| none|none |
lines=64 embedded dns none |
trace none |