Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:32:00 | WinXP | 119.77.155.206 (UBBN.NET): UNION BROADBAND NETWORK, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 0d1eb4df79 NEW |
none[none] | none:none |
none|none | none | none |
T:01:08:00 | WinXP | 101.12.49.129 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | 88ef3a1429 NEW |
none[none] | none:none |
none|none | none | none |
01:34:00 | Win2K-f | 223.19.193.24 (-): . |
n/a | US:www.maxmind.com EU:checkip.dyndns.org :www.getmyip.org :getmyip.co.uk DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:02:59:00 | WinXP | 96.10.87.193 (RR.COM): ROAD RUNNER HOLDCO LLC, WINSTON SALEM, NORTH CAROLINA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 40 |
9bdd2c95b1 NEW cd456ac095 NEW |
d1bbd693ba [0] d75caee680[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:03:47:00 | WinXP | 151.83.242.227 (SER-PR2-MAX.IUNET.IT): INFOSTRADA, IT. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | d11b1f56f9 NEW |
none[none] | none:none |
none|none | none | none |
T:03:48:00 | Win2K-f | 216.8.223.188 (ETCZONE.COM): ENHANCED TELECOMMUNICATIONS CORP, SUNMAN, INDIANA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:03:50:00 | Win2K-f | 68.146.203.190 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:03:58:00 | WinXP | 88.30.13.110 (RIMA-TDE.NET): TELEFONICA MOVILES ESPANA (NCC#2007041930), MADRID, MADRID, ES. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:04:14:00 | WinXP | 2.176.148.183 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 8a2553433c NEW |
none[none] | none:none |
none|none | none | none |
T:04:21:00 | WinXP | 193.248.96.173 (ABO.WANADOO.FR): WANADOO FRANCE, PARIS, ILE-DE-FRANCE, FR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:05:40:00 | Win2K-f | 113.3.69.140 (-): CHINA UNICOM HEILONGJIANG PROVINCE NETWORK, HARBIN, HEILONGJIANG, CN. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
17 of 43 0 of 33 |
007869237f NEW a08f3b74a4 NEW |
none[none] none [0] |
none:none none:none |
none|none Armadillo| |
none lines=90 |
none trace |
|
06:21:00 | WinXP | 87.97.255.32 (PL.EKK.BG): EKK CATV PLOVDIV, PLOVDIV, PLOVDIV, BG. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:06:36:00 | WinXP | 180.207.234.51 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 44 | b6cb1b2f30 NEW |
none[none] | none:none |
none|none | none | none |
T:06:42:00 | WinXP | 151.22.179.66 (-): OFFERTA MEDIUM, IT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:11:02:00 | WinXP | 76.11.216.214 (NEWWAVECOMM.NET): NEW WAVE COMMUNICATIONS, TAYLORVILLE, ILLINOIS, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:11:20:00 | WinXP | 178.158.139.26 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:11:33:00 | Win2K-f | 1.250.114.249 (-): . |
83.133.119.197:65520 | DE:proxima.ircgalaxy.pl US:microsoft.com CN:sb.letmedo.net RU:pizdanutih.net RU:sedsed1.com 109.196.191.226:3128 112.168.240.193:3128 119.154.155.79:3128 178.125.69.136:3128 180.94.94.115:3128 CN:60.190.223.60:2012 GH:80.87.88.66:3128 KZ:87.247.43.93:3128 92.46.146.93:3128 93.180.222.199:3128 95.57.50.76:3128 95.58.216.37:3128 |
135 | pcap | raw alerts ruleset |
irc http 115 lines |
Yeah : 1.8 profile |
none | summary tarball |
31 of 33 35 of 43 31 of 33 26 of 43 |
168aab35a3 NEW 3129f5662b NEW 667f0c59f3 NEW e9a62d4b65 NEW |
60b730b97e [0] none [none] 8fe2be2095[0] none [none] |
ASM:Graph none:none ASM:Graph none:none |
tElock| none|none Armadillo| none|none |
lines=120 embedded dns none lines=91 none |
trace none trace none |
T:11:42:00 | Win2K-f | 201.162.13.144 (CABLEXTREMO.COM.MX): CABLEVISION DE SALTILLO SA DE CV, MX. (DSL) |
83.133.119.197:65520 | RU:sedsed1.com DE:proxima.ircgalaxy.pl :newsoftnewsworld.com RU:pizdanutih.net CN:sb.letmedo.net RU:adquorum.com CN:w.nucleardiscover.com 178.122.144.254:6667 RU:193.27.246.230:80 46.49.37.139:6667 93.115.72.5:6667 93.116.154.250:6667 95.56.37.251:6667 95.59.106.254:6667 |
445 | pcap | raw alerts ruleset |
http http irc 23 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 43 35 of 43 32 of 42 29 of 44 30 of 43 38 of 43 26 of 43 38 of 43 |
2e7acdf2a9 NEW 3129f5662b NEW 969da03341 NEW b44d3ea50e NEW c5055355dc NEW dc902481ee NEW e9a62d4b65 NEW f6d42994f6 NEW |
none[none] none [none] none [none] none [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none none|none none|none none|none |
none none none none none none none none |
none none none none none none none none |
T:13:22:00 | WinXP | 46.203.210.82 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
43 of 43 | 15576ae143 NEW |
none[none] | none:none |
none|none | none | none |
T:13:25:00 | WinXP | 67.206.187.7 (ELTOPIA.NET): ELTOPIA.COM LLC, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
13:29:00 | WinXP | 217.203.99.66 (-): TELECOM ITALIA MOBILE, IT. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 42 | f92798c71c NEW |
none[none] | none:none |
none|none | none | none |
T:14:17:00 | WinXP | 93.102.62.134 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, PORTO, PORTO, PT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 0d1eb4df79 NEW |
none[none] | none:none |
none|none | none | none |
T:18:59:00 | WinXP | 72.48.81.89 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS WACO HUB, WOODWAY, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:19:58:00 | WinXP | 181.0.192.241 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
20:18:00 | WinXP | 115.82.200.1 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:20:39:00 | Win2K-f | 24.234.237.101 (COX.NET): COX COMMUNICATIONS INC, LAS VEGAS, NEVADA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:08:00 | WinXP | 42.74.41.141 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |