Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:02:03:00 | WinXP | 91.205.252.83 (-): JSC ROSTOV-ON-DON CELLULAR TELEPHONE, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:04:13:00 | WinXP | 108.72.213.32 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:04:51:00 | WinXP | 188.176.69.221 (DSL.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, DK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
05:57:00 | WinXP | 87.97.236.169 (PL.EKK.BG): EKK CATV PLOVDIV, PLOVDIV, PLOVDIV, BG. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
1 of 43 40 of 41 39 of 41 29 of 29 38 of 43 22 of 43 1 of 43 none 35 of 43 15 of 42 7 of 37 29 of 29 35 of 43 39 of 40 41 of 42 37 of 43 38 of 44 31 of 32 26 of 28 37 of 42 38 of 42 1 of 43 38 of 41 38 of 44 43 of 43 1 of 43 32 of 32 40 of 43 34 of 34 39 of 41 3 of 37 9 of 42 36 of 43 41 of 41 26 of 43 16 of 44 41 of 43 |
0a5f0b13d6 NEW 1096ba143e NEW 169a5d5c84 NEW 1a2c0e6130 NEW 1e46eb92be NEW 258c957144 NEW 2dbc977045 NEW 2f6cab0a72 NEW 3129f5662b NEW 3420de55b8 NEW 3862324588 NEW 3ae357d17b NEW 595430f951 NEW 5e8ccc4190 NEW 63d3d93432 NEW 69f32b85f1 NEW 71395792c5 NEW 741e3b03b3 NEW 7d99b0e910 NEW 88edab3d8b NEW 8a2553433c NEW 8dcd3108b5 NEW 9276456bf8 NEW 994930c79a NEW ab147c2b58 NEW ac238609b7 NEW b502f83a7c NEW c8d42bea74 NEW d20f157117 NEW d8040f84d4 NEW d9cb288f31 NEW e4240d7958 NEW e9117180db NEW e9667ba9e6 NEW e9a62d4b65 NEW f593071f74 NEW fb486908b0 NEW |
none[none] none [none] none [none] none [0] none [none] none [none] none [none] none [none] none [none] none [none] none [3] none [0] none [none] 8d5f86583f[0] none [none] none [none] none [none] none [0] none [0] none [none] none [none] none [none] none [none] none [none] none [none] none [none] 28f5be93b0[0] none [none] 738f555183[0] d683995e84[0] 45603a001c[0] none [none] none [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none ASM:Graph none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none ASM:Graph none:none ASM:Graph ASM:Graph ASM:Graph none:none none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none none|none none|none none|none none|none none|none UPX| PolyEnE| none|none PolyEnE| none|none none|none none|none none|none PolyEnE| none|none none|none none|none none|none none|none none|none none|none PolyEnE| none|none PolyEnE| PolyEnE| UPX| none|none none|none none|none none|none none|none none|none |
none none none lines=60 none none none none none none none lines=73 none lines=68 none none none lines=61 lines=68 none none none none none none none lines=73 none lines=68 lines=73 lines=174 embedded dns none none none none none none |
none none none trace none none none none none none trace trace none trace none none none trace trace none none none none none none none trace none trace trace trace none none none none none none |
T:06:21:00 | WinXP | 27.54.1.79 (-): . |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:07:17:00 | WinXP | 67.55.129.234 (NETINS.NET): CENTRAL SCOTT TELEPHONE, BLAIR, NEBRASKA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:08:26:00 | WinXP | 119.154.40.241 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, ISLAMABAD, ISLAMABAD, PK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:08:28:00 | WinXP | 190.227.143.203 (NET.AR): TELECOM PERSONAL BS AS, AR. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:12:12:00 | WinXP | 119.154.115.153 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, ISLAMABAD, ISLAMABAD, PK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:12:33:00 | WinXP | 109.175.248.133 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:12:39:00 | WinXP | 220.213.55.234 (WAKWAK.NE.JP): XEPHION-CIDR-BLK, YOKOHAMA, KANAGAWA, JP. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:57:00 | WinXP | 212.225.203.104 (PTVTELECOM.COM): ES-PROCONO-AS, CóRDOBA, ANDALUCIA, ES. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
13:58:00 | Win2K-f | 190.11.105.220 (-): COOP. POPULAR DE ELEC. OBRAS Y SERVICIOS PUB. DE SANTA ROSA LTDA, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | US:www.maxmind.com US:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
1 of 43 40 of 41 39 of 41 29 of 29 38 of 43 22 of 43 1 of 43 none 35 of 43 15 of 42 7 of 37 29 of 29 35 of 43 39 of 40 41 of 42 37 of 43 38 of 44 31 of 32 26 of 28 37 of 42 38 of 42 1 of 43 38 of 41 38 of 44 43 of 43 1 of 43 32 of 32 40 of 43 34 of 34 3 of 37 9 of 42 36 of 43 41 of 41 26 of 43 16 of 44 41 of 43 |
0a5f0b13d6 NEW 1096ba143e NEW 169a5d5c84 NEW 1a2c0e6130 NEW 1e46eb92be NEW 258c957144 NEW 2dbc977045 NEW 2f6cab0a72 NEW 3129f5662b NEW 3420de55b8 NEW 3862324588 NEW 3ae357d17b NEW 595430f951 NEW 5e8ccc4190 NEW 63d3d93432 NEW 69f32b85f1 NEW 71395792c5 NEW 741e3b03b3 NEW 7d99b0e910 NEW 88edab3d8b NEW 8a2553433c NEW 8dcd3108b5 NEW 9276456bf8 NEW 994930c79a NEW ab147c2b58 NEW ac238609b7 NEW b502f83a7c NEW c8d42bea74 NEW d20f157117 NEW d9cb288f31 NEW e4240d7958 NEW e9117180db NEW e9667ba9e6 NEW e9a62d4b65 NEW f593071f74 NEW fb486908b0 NEW |
none[none] none [none] none [none] none [0] none [none] none [none] none [none] none [none] none [none] none [none] none [3] none [0] none [none] 8d5f86583f[0] none [none] none [none] none [none] none [0] none [0] none [none] none [none] none [none] none [none] none [none] none [none] none [none] 28f5be93b0[0] none [none] 738f555183[0] 45603a001c[0] none [none] none [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none ASM:Graph none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none ASM:Graph none:none ASM:Graph ASM:Graph none:none none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none none|none none|none none|none none|none none|none UPX| PolyEnE| none|none PolyEnE| none|none none|none none|none none|none PolyEnE| none|none none|none none|none none|none none|none none|none none|none PolyEnE| none|none PolyEnE| UPX| none|none none|none none|none none|none none|none none|none |
none none none lines=60 none none none none none none none lines=73 none lines=68 none none none lines=61 lines=68 none none none none none none none lines=73 none lines=68 lines=174 embedded dns none none none none none none |
none none none trace none none none none none none trace trace none trace none none none trace trace none none none none none none none trace none trace trace none none none none none none |
T:14:03:00 | WinXP | 186.122.151.180 (-): . |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:15:06:00 | WinXP | 2.195.44.211 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:18:46:00 | WinXP | 46.202.89.13 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:19:34:00 | WinXP | 186.253.137.154 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:19:39:00 | Win2K-f | 120.138.175.125 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:20:48:00 | WinXP | 122.30.203.89 (OCN.NE.JP): OPEN COMPUTER NETWORK, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:21:48:00 | WinXP | 59.103.198.103 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, ISLAMABAD, ISLAMABAD, PK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |