Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:30:00 | Win2K-f | 1.60.139.54 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 92 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
00:53:00 | Win2K-f | 116.108.20.19 (USER10-17.ENET.VN): ELECTRIC TELECOMMUNICATION COMPANY, VN. (DSL) |
n/a | US:www.maxmind.com :getmyip.co.uk :www.getmyip.org US:checkip.dyndns.org US:208.43.124.51:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
06:02:00 | Win2K-f | 223.19.193.205 (-): . |
n/a | US:www.maxmind.com EU:checkip.dyndns.org :getmyip.co.uk :www.getmyip.org DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:06:09:00 | Win2K-f | 222.234.192.16 (HANANET.NET): HANARO TELECOM INC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
94.63.149.150:65520 | :proxim.ircgalaxy.pl US:microsoft.com CN:sb.letmedo.net EU:netnetnet1.com CN:w.nucleardiscover.com RU:sedsed1.com CN:hn.yigeyuming.com :a.95622.com 109.162.90.151:3128 113.94.189.50:3128 117.204.163.236:3128 125.165.188.94:3128 182.7.178.112:3128 |
135 | pcap | raw alerts ruleset |
irc http 136 lines |
Yeah : 1.8 profile |
none | summary tarball |
35 of 43 30 of 33 28 of 33 35 of 43 37 of 43 35 of 43 16 of 44 |
3129f5662b NEW 533d15b5ce NEW 58c343a8d8 NEW 595430f951 NEW 69f32b85f1 NEW d7fd6d78a4 NEW f593071f74 NEW |
none[none] c67adf46e2[0] none [0] none [none] none [none] none [none] none [none] |
none:none ASM:Graph none:none none:none none:none none:none none:none |
none|none tElock| Armadillo| none|none none|none none|none none|none |
none lines=126 embedded dns lines=91 none none none none |
none trace trace none none none none |
T:06:10:00 | Win2K-f | 223.19.193.205 (-): . |
n/a | US:www.maxmind.com US:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
06:30:00 | WinXP | 117.19.84.122 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:06:31:00 | WinXP | 176.59.139.41 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 1096ba143e NEW |
none[none] | none:none |
none|none | none | none |
T:06:36:00 | WinXP | 210.236.22.165 (MEGAEGG.NE.JP): ENERGIA COMMUNICATIONS INC, TAHARA, AICHI, JP. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
43 of 43 | debeecd50c NEW |
none[none] | none:none |
none|none | none | none |
T:06:53:00 | Win2K-f | 114.42.120.171 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:hawaiiancityhotels.com :s5.mainpage.cc US:as.casalemedia.com US:autoslines.com :images.ddc.com US:activex.microsoft.com US:codecs.microsoft.com 117.198.130.53:6667 120.68.33.144:6667 174.35.39.16:80 DE:195.190.13.78:8103 |
445 | pcap | raw alerts ruleset |
http irc 28 lines |
Argh : 0.3 profile |
none | summary tarball |
1 of 43 | 9ceb96f28f NEW |
none[none] | none:none |
none|none | none | none |
T:07:19:00 | WinXP | 46.214.113.96 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:07:51:00 | WinXP | 176.59.128.202 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:09:12:00 | WinXP | 207.191.252.151 (SPEAKEASY.NET): CEDAR RAPIDS, IOWA, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | 751685117f NEW |
none[none] | none:none |
none|none | none | none |
T:15:18:00 | WinXP | 151.31.133.216 (30-151.LIBERO.IT): FREE INTERNET DIAL-UP SERVICES, CHIETI, ABRUZZI, IT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 3ae357d17b NEW |
none[0] | none:none |
PolyEnE| | lines=73 | trace |
T:16:08:00 | WinXP | 70.65.71.206 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, RED DEER, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1020 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 41 | 682a384fe9 NEW |
none[3] | none:none |
none|none | none | trace | |
17:11:00 | Win2K-f | 218.63.69.77 (163DATA.COM.CN): CHINANET YUNNAN PROVINCE NETWORK, BEIJING, BEIJING, CN. (DIAL) |
n/a | US:www.maxmind.com US:checkip.dyndns.org US:208.43.124.51:80 CN:218.63.69.77:7849 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:18:04:00 | WinXP | 118.83.42.243 (HTOJ.J-CNET.JP): JCN-HTMNET, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 123 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 43 36 of 39 |
6fc2b9fade NEW c72d3d40b6 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:19:31:00 | WinXP | 117.108.20.155 (KCN.NE.JP): KCN-NET INTERNET SERVICE PROVIDER, TOKYO, TOKYO, JP. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 36 | 1595515522 NEW |
none[none] | none:none |
none|none | none | none |
T:19:43:00 | WinXP | 176.59.137.130 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 43 | 13e6a02512 NEW |
none[none] | none:none |
none|none | none | none |
T:19:43:00 | Win2K-f | 49.133.40.80 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 44 41 of 44 |
99f212a9df NEW 9fa81e360b NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:19:44:00 | WinXP | 24.50.225.133 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 35 | e9fcd6f257 NEW |
2e05bc2272 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
20:03:00 | Win2K-f | 94.102.11.190 (NI.NET.TR): NETINTERNET BILGISAYAR VE TELEKOMUNIKASYAN SAN. VE TIC. LTD. STI, TR. (DSL) |
n/a | US:www.maxmind.com EU:checkip.dyndns.org :getmyip.co.uk :www.getmyip.org US:208.43.124.51:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:20:12:00 | Win2K-f | 94.102.11.190 (NI.NET.TR): NETINTERNET BILGISAYAR VE TELEKOMUNIKASYAN SAN. VE TIC. LTD. STI, TR. (DSL) |
n/a | US:www.maxmind.com :www.getmyip.org :getmyip.co.uk US:checkip.dyndns.org DE:131.220.6.26:80 US:216.146.39.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:20:29:00 | WinXP | 190.248.157.143 (EPM.NET.CO): EPM TELECOMUNICACIONES S.A. E.S.P, CO. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | 5c6df5141d NEW |
none[none] | none:none |
none|none | none | none |
T:21:22:00 | WinXP | 61.150.5.66 (163DATA.COM.CN): XI'AN DATA BRANCH XIAN CITY SHAANXI PROVINCE, XIAN, SHAANXI, CN. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 41 of 43 |
5799ab6538 NEW ddbe111920 NEW |
2713679411 [0] none [none] |
ASM:Graph none:none |
tElock| none|none |
lines=64 embedded dns none |
trace none |
T:22:14:00 | Win2K-f | 180.74.110.222 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 116 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
6a1dc43309 NEW 94e49d5627 NEW |
522dace6c1 [0] 777259292a[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:23:37:00 | WinXP | 77.254.87.92 (INETIA.PL): INTERNETIA, SZCZECIN, ZACHODNIOPOMORSKIE, PL. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 169a5d5c84 NEW |
none[none] | none:none |
none|none | none | none |