Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:34:00 | WinXP | 101.102.33.67 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 42 | 9ede0bcf90 NEW |
none[none] | none:none |
none|none | none | none | |
T:00:35:00 | WinXP | 188.176.71.27 (DSL.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, DK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:01:42:00 | WinXP | 218.165.16.9 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | c19c8a2776 NEW |
none[none] | none:none |
none|none | none | none |
T:02:22:00 | WinXP | 112.202.211.18 (PLDT.NET): IPG, PH. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:04:32:00 | Win2K-f | 1.251.61.249 (-): . |
83.133.119.197:65520 | :proxima.ircgalaxy.pl US:microsoft.com CN:sb.letmedo.net RU:netnet51.com EU:tretr23.com CN:w.nucleardiscover.com RO:backup-windows.ru :ytreytre.com :a.95622.com :1.95622.com CN:ru.letmedo.net EU:188.247.135.32:80 DE:83.133.119.197:65520 |
135 | pcap | raw alerts ruleset |
irc http 127 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 42 31 of 33 35 of 42 6 of 42 31 of 33 37 of 43 23 of 42 16 of 44 |
0ed155401e NEW 168aab35a3 NEW 2ea76f965d NEW 5f675b2dee NEW 667f0c59f3 NEW 69f32b85f1 NEW b341b96a17 NEW f593071f74 NEW |
none[none] 60b730b97e[0] none [none] none [none] 8fe2be2095[0] none [none] none [none] none [none] |
none:none ASM:Graph none:none none:none ASM:Graph none:none none:none none:none |
none|none tElock| none|none none|none Armadillo| none|none none|none none|none |
none lines=120 embedded dns none none lines=91 none none none |
none trace none none trace none none none |
T:05:12:00 | Win2K-f | 87.10.210.83 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A. TIN EASY LITE, ROME, LAZIO, IT. (DSL) |
n/a | US:winonlineprizes.com :ooooo.net US:as.casalemedia.com US:activex.microsoft.com US:codecs.microsoft.com US:i.nuseek.com US:64.145.88.89:80 US:64.38.232.180:80 UA:77.121.200.20:6667 |
445 | pcap | raw alerts ruleset |
http 58 lines |
Argh : 0.3 profile |
none | summary tarball |
1 of 42 | cafe6fc824 NEW |
none[none] | none:none |
none|none | none | none |
T:06:23:00 | WinXP | 96.10.87.79 (RR.COM): ROAD RUNNER HOLDCO LLC, WINSTON SALEM, NORTH CAROLINA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 40 |
9bdd2c95b1 NEW cd456ac095 NEW |
d1bbd693ba [0] d75caee680[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:07:41:00 | WinXP | 89.155.208.250 (CPE.NETCABO.PT): TVCABO-PORTUGAL CABLE MODEM NETWORK, VIANA DO CASTELO, VIANA DO CASTELO, PT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
07:52:00 | WinXP | 89.155.208.250 (CPE.NETCABO.PT): TVCABO-PORTUGAL CABLE MODEM NETWORK, VIANA DO CASTELO, VIANA DO CASTELO, PT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:08:36:00 | WinXP | 207.144.15.229 (CSTEL.NET): COM-SOUTH, KATHLEEN, GEORGIA, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
37 of 42 | 949ea433e3 NEW |
none[none] | none:none |
none|none | none | none |
09:09:00 | WinXP | 119.154.78.172 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, LAHORE, PUNJAB, PK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | 488d27fe97 NEW |
none[none] | none:none |
none|none | none | none |
T:10:58:00 | WinXP | 119.154.181.202 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, ISLAMABAD, ISLAMABAD, PK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:11:37:00 | WinXP | 180.218.169.56 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | c19c8a2776 NEW |
none[none] | none:none |
none|none | none | none |
T:11:41:00 | WinXP | 68.189.248.17 (CHARTER.COM): CHARTER COMMUNICATIONS, PEPPERELL, MASSACHUSETTS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:15:41:00 | WinXP | 173.215.43.120 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:15:45:00 | WinXP | 46.134.200.88 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
35 of 36 | f3440caba1 NEW |
none[none] | none:none |
none|none | none | none |
T:15:52:00 | WinXP | 200.175.199.18 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 42 | 59bcd87e9b NEW |
none[none] | none:none |
none|none | none | none |
15:58:00 | Win2K-f | 94.102.11.221 (NI.NET.TR): NETINTERNET BILGISAYAR VE TELEKOMUNIKASYAN SAN. VE TIC. LTD. STI, TR. (DSL) |
n/a | US:www.maxmind.com EU:checkip.dyndns.org US:208.43.124.51:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:16:23:00 | WinXP | 24.35.159.9 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 42 | 0d1eb4df79 NEW |
none[none] | none:none |
none|none | none | none |
T:16:27:00 | WinXP | 89.214.108.62 (-): GPRS COSTUMERS, ALMADA, SETUBAL, PT. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | d11b1f56f9 NEW |
none[none] | none:none |
none|none | none | none |
T:16:57:00 | WinXP | 72.10.90.114 (PINELAND.NET): PINELAND TELEPHONE, SOUTH LAKE TAHOE, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 44 38 of 43 |
67c849c687 NEW fcd5ed4078 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:17:51:00 | WinXP | 207.191.253.228 (SPEAKEASY.NET): CEDAR RAPIDS, IOWA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 1096ba143e NEW |
none[none] | none:none |
none|none | none | none |
19:09:00 | Win2K-f | 117.25.178.171 (163DATA.COM.CN): CHINANET FUJIAN PROVINCE NETWORK, FUZHOU, FUJIAN, CN. (DSL) |
n/a | US:www.maxmind.com US:checkip.dyndns.org :www.getmyip.org :getmyip.co.uk DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:20:40:00 | WinXP | 93.102.129.244 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, PT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 48e4b28402 NEW |
none[none] | none:none |
none|none | none | none |
T:20:49:00 | WinXP | 1.200.36.95 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:20:59:00 | Win2K-f | 70.60.191.151 (RR.COM): ROAD RUNNER HOLDCO LLC, MEMPHIS, TENNESSEE, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:01:00 | WinXP | 46.203.144.111 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 584b104a9f NEW |
none[none] | none:none |
none|none | none | none | |
T:22:55:00 | Win2K-f | 115.240.37.172 (PHOTONINFOTECH.COM): RELIANCE COMMUNICATIONS LTD, BANGALORE, KARNATAKA, IN. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 158 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | 73f1082158 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:23:12:00 | WinXP | 89.165.193.82 (HERTZA.RO): SC AXEL SRL, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:23:47:00 | WinXP | 111.88.34.132 (HOSTS-WORLDCALL.NET.PK): WORLDCALL TELECOM LTD, PK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
36 of 42 | 76bb13e145 NEW |
none[none] | none:none |
none|none | none | none |