Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:21:00 | WinXP | 114.145.133.84 (OCN.NE.JP): OPEN COMPUTER NETWORK, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:00:22:00 | Win2K-f | 81.62.192.172 (BLUEWIN.CH): BLUEWIN IS AN LIR AND ISP IN SWITZERLAND, ZURICH, ZURICH, CH. (DSL) |
n/a | :ppppp.org CN:w.nucleardiscover.com CN:s5.perfectexe.com US:i.nuseek.com :www.google-analytics.com :ytreytre.com :ispmen.com 117.200.48.220:3128 178.54.10.24:3128 186.90.219.155:3128 223.175.225.118:3128 223.175.240.105:3128 TN:41.224.248.188:3128 IN:59.99.208.145:3128 |
135 | pcap | raw alerts ruleset |
http irc 56 lines |
Yeah : 0.8 profile |
none | summary tarball |
20 of 42 26 of 42 29 of 42 9 of 42 |
008e960e9b NEW 143e472915 NEW a61fddb554 NEW e4240d7958 NEW |
none[none] none [none] none [none] none [none] |
none:none none:none none:none none:none |
none|none none|none none|none none|none |
none none none none |
none none none none |
T:00:50:00 | WinXP | 46.162.218.72 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 136 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 44 40 of 44 |
07d1bdda49 NEW ba603fad6d NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:01:42:00 | WinXP | 61.215.168.201 (CABLENET.NE.JP): CABLENET SAITAMA CO. LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
10eebdc28e NEW 761a66b891 NEW |
e2ca2da35d [0] b469dac5dc[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:02:25:00 | WinXP | 223.176.142.143 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:07:09:00 | WinXP | 46.134.209.82 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
35 of 36 | f3440caba1 NEW |
none[none] | none:none |
none|none | none | none |
T:08:25:00 | WinXP | 115.82.61.176 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 44 | b6cb1b2f30 NEW |
none[none] | none:none |
none|none | none | none |
T:09:20:00 | WinXP | 123.99.17.153 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:09:20:00 | WinXP | 164.132.31.20 (-): IUNET S.P.A, MILANO, LOMBARDIA, IT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
37 of 42 | 99c26b4e9a NEW |
none[none] | none:none |
none|none | none | none |
T:10:23:00 | Win2K-f | 50.71.75.214 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 144 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 43 | 7f5da98345 NEW |
none[none] | none:none |
none|none | none | none | |
T:10:50:00 | WinXP | 91.65.145.60 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, MUNICH, BAYERN, DE. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:11:52:00 | WinXP | 46.203.183.204 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
43 of 43 | 15576ae143 NEW |
none[none] | none:none |
none|none | none | none |
T:12:10:00 | WinXP | 31.40.104.111 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | 488d27fe97 NEW |
none[none] | none:none |
none|none | none | none |
T:12:27:00 | Win2K-f | 110.9.189.159 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
83.133.119.197:65520 | DE:proxima.ircgalaxy.pl US:microsoft.com CN:sb.letmedo.net :netnet50.com 178.17.164.202:80 CN:60.190.223.60:2012 95.143.193.118:65520 |
135 | pcap | raw alerts ruleset |
irc 118 lines |
Yeah : 1.8 profile |
none | summary tarball |
31 of 33 39 of 41 |
168aab35a3 NEW aa6d257461 NEW |
60b730b97e [0] 6aca567868[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=120 embedded dns lines=91 |
trace trace |
T:12:52:00 | Win2K-f | 31.41.9.33 (-): . |
n/a | DE:proxima.ircgalaxy.pl DE:83.133.119.197:65520 95.143.193.118:65520 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:13:33:00 | WinXP | 93.102.61.22 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, PORTO, PORTO, PT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 0d1eb4df79 NEW |
none[none] | none:none |
none|none | none | none |
T:15:30:00 | WinXP | 2.197.130.172 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:16:12:00 | WinXP | 91.65.145.60 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, MUNICH, BAYERN, DE. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
17:15:00 | Win2K-f | 210.107.69.68 (BORA.NET): BORANET-NET, KR. (DSL) |
n/a | US:www.maxmind.com :getmyip.co.uk :www.getmyip.org EU:checkip.dyndns.org US:208.43.124.51:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:17:44:00 | WinXP | 208.94.177.146 (KARIBCABLE.COM): KARIB CABLE, KINGSTOWN, SAINT GEORGE, VC. (100Mbps) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | 751685117f NEW |
none[none] | none:none |
none|none | none | none |
18:16:00 | WinXP | 208.94.177.146 (KARIBCABLE.COM): KARIB CABLE, KINGSTOWN, SAINT GEORGE, VC. (100Mbps) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 | 751685117f NEW |
none[none] | none:none |
none|none | none | none |
18:30:00 | Win2K-f | 175.112.215.7 (-): . |
83.133.119.197:65520 | :proxim.ircgalaxy.pl US:microsoft.com :newsoftnewsworld.com EU:adquorum.com CN:sb.letmedo.net EU:bdchance.com :netnet50.com CN:60.190.223.60:2012 RO:85.121.39.222:80 |
135 | pcap | raw alerts ruleset |
irc http 132 lines |
Yeah : 1.8 profile |
none | summary tarball |
33 of 42 30 of 43 39 of 42 |
69f59a0454 NEW c5055355dc NEW f4c93e7909 NEW |
none[none] none [none] none [none] |
none:none none:none none:none |
none|none none|none none|none |
none none none |
none none none |
20:25:00 | Win2K-f | 182.18.134.162 (-): . |
n/a | US:www.maxmind.com :www.getmyip.org :getmyip.co.uk US:checkip.dyndns.org DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:20:35:00 | Win2K-f | 182.18.134.162 (-): . |
n/a | US:www.maxmind.com US:checkip.dyndns.org DE:131.220.6.26:80 US:208.43.124.51:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
20:37:00 | WinXP | 76.11.216.214 (NEWWAVECOMM.NET): NEW WAVE COMMUNICATIONS, TAYLORVILLE, ILLINOIS, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace | |
T:22:44:00 | WinXP | 77.20.196.29 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BERLIN, BERLIN, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace |