Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:12:00 | WinXP | 125.76.229.27 (163DATA.COM.CN): CHINANET SHANXI(SN) PROVINCE NETWORK, BEIJING, BEIJING, CN. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:34:00 | WinXP | 61.56.160.30 (UBBN.NET): UNION BROADBAND NETWORK, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
44 of 44 | 8f619296d3 NEW |
none[none] | none:none |
none|none | none | none |
T:04:24:00 | WinXP | 93.102.39.43 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, LISBON, LISBOA, PT. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 44 | 39e767d023 NEW |
none[none] | none:none |
none|none | none | none | |
T:05:20:00 | WinXP | 114.181.214.11 (PLALA.OR.JP): NTT PLALA INC, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 09245a76fe NEW |
4767a61119 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:06:57:00 | WinXP | 182.5.190.69 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:09:04:00 | WinXP | 114.198.175.91 (-): GLOBALVIEW CATV CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | ef96217736 NEW |
none[none] | none:none |
none|none | none | none |
T:09:51:00 | WinXP | 217.202.7.150 (-): TELECOM ITALIA MOBILE, ROME, LAZIO, IT. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:10:59:00 | WinXP | 70.65.236.255 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, LETHBRIDGE, ALBERTA, CA. (DSL) |
n/a | :gg.arrancar.org | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 39 | ce28648035 NEW |
126d2f4655 [0] | ASM:Graph |
none|none | lines=546 | trace |
T:11:48:00 | WinXP | 119.154.95.192 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, ISLAMABAD, ISLAMABAD, PK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 0d1eb4df79 NEW |
none[none] | none:none |
none|none | none | none |
T:12:07:00 | WinXP | 61.45.55.209 (WAKWAK.NE.JP): XEPHION(NTT-ME CORPORATION), TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | c66d771507 NEW |
none[none] | none:none |
none|none | none | none | |
T:14:58:00 | WinXP | 91.64.116.202 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, HAMBURG, HAMBURG, DE. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:15:28:00 | WinXP | 24.35.142.79 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 39 of 42 |
5b4d05d086 NEW ee8f4bf7f1 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:15:59:00 | WinXP | 151.81.80.41 (51-151.NET24.IT): IUNET-BNET, IT. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | c9f7e394fb NEW |
none[none] | none:none |
none|none | none | none | |
T:15:59:00 | WinXP | 115.82.88.174 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 6e6fde936f NEW |
none[none] | none:none |
none|none | none | none |
T:17:29:00 | WinXP | 186.254.211.53 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:17:36:00 | WinXP | 89.155.209.187 (CPE.NETCABO.PT): TVCABO-PORTUGAL CABLE MODEM NETWORK, VIANA DO CASTELO, VIANA DO CASTELO, PT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:19:45:00 | WinXP | 182.63.165.5 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 8a2553433c NEW |
none[none] | none:none |
none|none | none | none |
T:20:29:00 | WinXP | 119.154.43.42 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, ISLAMABAD, ISLAMABAD, PK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | 488d27fe97 NEW |
none[none] | none:none |
none|none | none | none |
T:20:33:00 | WinXP | 189.67.133.236 (TIMBRASIL.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, RIO DE JANEIRO, RIO DE JANEIRO, BR. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
21:43:00 | Win2K-f | 193.137.7.195 (ESTV.IPV.PT): INSTITUTO POLITECNICO DE VISEU, PT. (DSL) |
n/a | US:www.maxmind.com :www.getmyip.org :getmyip.co.uk EU:checkip.dyndns.org DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:21:51:00 | WinXP | 106.76.64.128 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 44 | 1334bb0089 NEW |
none[none] | none:none |
none|none | none | none |
22:15:00 | Win2K-f | 122.180.147.211 (122.AIRTELBROADBAND.IN): BHARTI AIRTEL LTD. TELEMEDIA SERVICES, NEW DELHI, DELHI, IN. (DSL) |
n/a | US:www.maxmind.com US:checkip.dyndns.org :www.getmyip.org :getmyip.co.uk DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
4 of 37 | 8ce32ded17 NEW |
none[3] | none:none |
Armadillo| | none | trace |
T:22:28:00 | Win2K-f | 122.180.147.211 (122.AIRTELBROADBAND.IN): BHARTI AIRTEL LTD. TELEMEDIA SERVICES, NEW DELHI, DELHI, IN. (DSL) |
n/a | US:www.maxmind.com :www.getmyip.org US:checkip.dyndns.org DE:131.220.6.26:80 US:208.43.124.51:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
4 of 37 | 8ce32ded17 NEW |
none[3] | none:none |
Armadillo| | none | trace |
T:23:40:00 | WinXP | 174.39.233.22 (WINDSTREAM.NET): ALLTEL MIP CUSTOMERS - OMAHA, YORK, NEBRASKA, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
23:54:00 | Win2K-f | 125.64.18.46 (163DATA.COM.CN): CHINANET SICHUAN PROVINCE NETWORK, CHENGDU, SICHUAN, CN. (DSL) |
n/a | US:www.maxmind.com :getmyip.co.uk :www.getmyip.org EU:checkip.dyndns.org US:208.43.124.51:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |