Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:26:00 | WinXP | 175.177.105.61 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:00:28:00 | WinXP | 217.17.100.60 (-): CS-SAT-TRAKT, CS. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:01:19:00 | WinXP | 202.137.208.252 (ORTELCOM.COM): ORTELCOMMUNICATIONS-IN, BHUBANESHWAR, ORISSA, IN. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:01:27:00 | Win2K-f | 24.155.34.130 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS ODESSA HUB, MIDLAND, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:02:33:00 | WinXP | 109.86.130.77 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 9276456bf8 NEW |
none[none] | none:none |
none|none | none | none |
02:49:00 | Win2K-f | 94.92.167.125 (BUSINESS.TELECOMITALIA.IT): INTERBUSINESS, ROME, LAZIO, IT. (DSL) |
n/a | US:www.maxmind.com :getmyip.co.uk US:checkip.dyndns.org :www.getmyip.org DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
4 of 37 | 8ce32ded17 NEW |
none[3] | none:none |
Armadillo| | none | trace |
02:59:00 | WinXP | 109.86.130.77 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 9276456bf8 NEW |
none[none] | none:none |
none|none | none | none |
T:04:22:00 | WinXP | 46.203.46.133 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
43 of 43 | 15576ae143 NEW |
none[none] | none:none |
none|none | none | none |
T:04:27:00 | WinXP | 210.236.8.120 (MEGAEGG.NE.JP): ENERGIA COMMUNICATIONS INC, HIROSHIMA, HIROSHIMA, JP. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
43 of 43 | debeecd50c NEW |
none[none] | none:none |
none|none | none | none |
T:04:48:00 | WinXP | 94.139.25.144 (-): BOSCHTELEKOM, BERLIN, BERLIN, DE. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 2dcd9c9c49 NEW |
none[none] | none:none |
none|none | none | none |
04:52:00 | WinXP | 46.203.46.133 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
43 of 43 | 15576ae143 NEW |
none[none] | none:none |
none|none | none | none |
T:06:15:00 | WinXP | 109.86.179.27 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 67db574df4 NEW |
none[none] | none:none |
none|none | none | none |
T:06:23:00 | WinXP | 207.191.249.13 (SPEAKEASY.NET): CEDAR RAPIDS, IOWA, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | 751685117f NEW |
none[none] | none:none |
none|none | none | none |
T:06:28:00 | WinXP | 212.129.85.92 (-): METEOR-GPRS, DUBLIN, DUBLIN, IE. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:11:27:00 | WinXP | 134.249.38.17 (TERMBILLING.COM): VARIOUS REGISTRIES, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 42 | 0cee797e1f NEW |
none[none] | none:none |
none|none | none | none |
T:11:35:00 | WinXP | 93.87.24.70 (GNET.CO.YU): YU-TELEKOM, RS. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 42 | dcb0e4b683 NEW |
none[none] | none:none |
none|none | none | none |
11:54:00 | WinXP | 134.249.38.17 (TERMBILLING.COM): VARIOUS REGISTRIES, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 42 | 0cee797e1f NEW |
none[none] | none:none |
none|none | none | none |
T:12:04:00 | WinXP | 59.103.198.117 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, ISLAMABAD, ISLAMABAD, PK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 43 | 96b1cefe23 NEW |
none[none] | none:none |
none|none | none | none |
T:12:05:00 | WinXP | 101.96.61.122 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:24:00 | WinXP | 46.203.26.94 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
43 of 43 | 15576ae143 NEW |
none[none] | none:none |
none|none | none | none |
T:13:07:00 | Win2K-f | 70.60.122.147 (RR.COM): ROAD RUNNER HOLDCO LLC, CHARLOTTE, NORTH CAROLINA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
13:48:00 | WinXP | 93.87.24.70 (GNET.CO.YU): YU-TELEKOM, RS. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 42 | dcb0e4b683 NEW |
none[none] | none:none |
none|none | none | none |
14:43:00 | Win2K-f | 202.60.81.80 (NETLOGISTICS.COM.AU): NET LOGISTICS, SYDNEY, NEW SOUTH WALES, AU. (DSL) |
n/a | US:www.maxmind.com :www.getmyip.org :getmyip.co.uk EU:checkip.dyndns.org US:208.43.124.51:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:14:46:00 | Win2K-f | 24.155.4.161 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS ODESSA HUB, MESQUITE, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:16:06:00 | WinXP | 92.251.190.218 (-): H3G IRELAND SUBSCRIBERS, IE. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
27 of 33 | 5db86f4ced NEW |
none[none] | none:none |
none|none | none | none |
T:17:15:00 | WinXP | 223.139.204.129 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 1096ba143e NEW |
none[none] | none:none |
none|none | none | none |
17:24:00 | Win2K-f | 202.168.254.27 (BDMAIL.NET): BBN-BD, DHAKA, DHAKA, BD. (DSL) |
n/a | US:www.maxmind.com :getmyip.co.uk :www.getmyip.org US:checkip.dyndns.org DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
17:27:00 | WinXP | 223.139.204.129 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 1096ba143e NEW |
none[none] | none:none |
none|none | none | none |
T:17:33:00 | Win2K-f | 202.168.254.27 (BDMAIL.NET): BBN-BD, DHAKA, DHAKA, BD. (DSL) |
n/a | US:www.maxmind.com :www.getmyip.org :getmyip.co.uk US:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:17:54:00 | WinXP | 67.215.215.62 (BARDSTOWNCABLE.NET): CITY OF BARDSTOWN KENTUCKY, BARDSTOWN, KENTUCKY, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:17:55:00 | WinXP | 109.83.6.10 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:18:05:00 | WinXP | 186.180.188.205 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:18:34:00 | WinXP | 65.101.150.193 (JRSCRAFTS.COM): MONDOGENERATOR, SEATTLE, WASHINGTON, US. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:19:07:00 | Win2K-f | 76.205.72.68 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, CLEVELAND, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 74 lines |
Yeah : 1.3 profile |
none | summary tarball |
1 of 33 33 of 33 |
4ca3056804 NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
none:none ASM:Graph |
Armadillo| tElock| |
lines=90 lines=75 embedded dns |
trace trace |
T:19:07:00 | WinXP | 175.177.105.57 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:19:58:00 | Win2K-f | 190.51.173.121 (COM.AR): TELEFONICA DE ARGENTINA, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
5 of 42 | 8a138ee69d NEW |
none[none] | none:none |
none|none | none | none | |
T:20:56:00 | WinXP | 99.93.138.147 (PACBELL.NET): AT&T INTERNET SERVICES, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:31:00 | WinXP | 173.215.43.97 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace |