Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:51:00 | WinXP | 188.176.69.177 (DSL.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, DK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:00:56:00 | WinXP | 119.154.71.35 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, LAHORE, PUNJAB, PK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 2eae16912d NEW |
none[none] | none:none |
none|none | none | none |
T:01:05:00 | WinXP | 4.224.141.103 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, INDIANAPOLIS, INDIANA, US. (DIAL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:01:34:00 | WinXP | 123.241.97.106 (LSC.NET.TW): TBCOM-NET, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 41 of 43 |
2bc8f15054 NEW 9956124c58 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
01:47:00 | WinXP | 4.224.141.103 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, INDIANAPOLIS, INDIANA, US. (DIAL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:02:12:00 | WinXP | 95.102.222.28 (T-COM.SK): BLOCK OF DYNAMIC IPS FOR BROADBAND CUSTOMERS, BRATISLAVA, BRATISLAVA, SK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:02:33:00 | WinXP | 176.59.246.43 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:02:47:00 | WinXP | 218.117.136.74 (BBTEC.NET): JAPAN NATION-WIDE NETWORK OF SOFTBANK BB CORP, KITAKYUSHU, FUKUOKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:40:00 | WinXP | 81.23.201.191 (SLADONEZH.RU): TRANSFER, RU. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
33 of 35 | e9fcd6f257 NEW |
2e05bc2272 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:06:00:00 | WinXP | 81.13.105.62 (RMT.RU): CLIENT, MOSCOW, MOSCOW CITY, RU. (100Mbps) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | 8c3c90cc1c NEW |
none[none] | none:none |
none|none | none | none |
T:06:48:00 | WinXP | 86.56.116.146 (BLUE-CABLE.DE): TELECOLUMBUS KUNDENSERVICE GMBH, DE. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:07:41:00 | WinXP | 114.24.112.36 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 735d25139c NEW |
none[none] | none:none |
none|none | none | none |
T:08:55:00 | WinXP | 223.29.205.135 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 33 lines |
Yeah : 1.3 profile |
none | summary tarball |
2 of 35 | 3199efa07d NEW |
none[none] | none:none |
none|none | none | none | |
T:09:16:00 | WinXP | 118.15.249.169 (OCN.NE.JP): OPEN COMPUTER NETWORK, TOKYO, TOKYO, JP. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 9276456bf8 NEW |
none[none] | none:none |
none|none | none | none |
T:10:01:00 | WinXP | 218.167.32.147 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 0d1eb4df79 NEW |
none[none] | none:none |
none|none | none | none |
T:11:07:00 | WinXP | 92.252.128.40 (MV.RU): ULYANOVSK BRANCH OF OJSC VOLGATELECOM, RU. (DIAL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
37 of 43 | 831731ac0b NEW |
none[none] | none:none |
none|none | none | none |
T:11:40:00 | WinXP | 190.103.65.70 (-): COTEL LTDA, LA PAZ, LA PAZ, BO. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | f45285574e NEW |
d984958bf9 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:14:15:00 | WinXP | 83.97.175.79 (CM-93-156-61-10.TELECABLE.ES): TELECABLE, GIJON, ASTURIAS, ES. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 42 | 79abfc94b7 NEW |
none[none] | none:none |
none|none | none | none |
T:14:21:00 | WinXP | 93.87.25.149 (GNET.CO.YU): YU-TELEKOM, RS. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 42 | dcb0e4b683 NEW |
none[none] | none:none |
none|none | none | none |
T:14:21:00 | WinXP | 76.8.230.197 (-): TAT HUNTEL, MCCOMB, MISSISSIPPI, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | 751685117f NEW |
none[none] | none:none |
none|none | none | none |
T:15:00:00 | Win2K-f | 111.88.52.169 (HOSTS-WORLDCALL.NET.PK): WORLDCALL TELECOM LTD, PK. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 95 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 2 of 32 |
607b60ad51 NEW e5c7bce70e NEW |
none[4] e5c7bce70e[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:15:52:00 | WinXP | 89.214.4.250 (-): GPRS COSTUMERS, FARO, FARO, PT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 42 | 6e8231528a NEW |
none[none] | none:none |
none|none | none | none |
T:16:11:00 | WinXP | 178.17.124.141 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 42 | 48ebc3d253 NEW |
none[none] | none:none |
none|none | none | none |
18:25:00 | Win2K-f | 94.184.96.112 (-): NPD OF IKCO CO, TEHRAN, ESFAHAN, IR. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk JP:www.sbtjapan.com US:checkip.dyndns.org DE:131.220.6.26:80 94.184.96.112:8092 |
445 | pcap | raw alerts ruleset |
http 56 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:22:13:00 | WinXP | 41.93.131.198 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:22:53:00 | WinXP | 203.77.52.177 (GCN.NET.TW): GLOBAL COMMUNICATION NETWORK CORP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 75a358c05d NEW |
none[none] | none:none |
none|none | none | none |
T:23:12:00 | Win2K-f | 120.138.169.209 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 39 of 39 |
b8e6f4caf7 NEW fb92b91fe7 NEW |
f81eac6379 [0] fe88ab8768[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
23:14:00 | WinXP | 223.140.99.12 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |