Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:46:00 | WinXP | 101.15.216.81 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 1096ba143e NEW |
none[none] | none:none |
none|none | none | none |
02:21:00 | Win2K-f | 223.19.206.195 (-): . |
n/a | US:www.maxmind.com :www.getmyip.org EU:getmyip.co.uk JP:www.sbtjapan.com EU:checkip.dyndns.org US:208.43.124.51:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:03:14:00 | WinXP | 116.202.96.17 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:03:19:00 | WinXP | 95.72.166.92 (-): OREHOVO-ZUEVO-2 FLATE RATE POOL, MOSCOW, MOSCOW CITY, RU. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 43 | 88ef3a1429 NEW |
none[none] | none:none |
none|none | none | none |
T:03:58:00 | WinXP | 123.193.134.60 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 9276456bf8 NEW |
none[none] | none:none |
none|none | none | none |
T:04:14:00 | WinXP | 68.189.248.17 (CHARTER.COM): CHARTER COMMUNICATIONS, PEPPERELL, MASSACHUSETTS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
04:26:00 | Win2K-f | 202.122.17.189 (E-KARNET.NET): KARUTURI TELECOM PVT LTD IS AN ISP WITH ITS OWN GATEWAY, BANGALORE, KARNATAKA, IN. (DSL) |
n/a | US:www.maxmind.com US:checkip.dyndns.org EU:getmyip.co.uk :www.getmyip.org US:208.43.124.51:80 EU:78.40.35.130:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:04:30:00 | WinXP | 122.118.82.49 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
38 of 42 | 2dcd9c9c49 NEW |
none[none] | none:none |
none|none | none | none |
T:04:35:00 | Win2K-f | 202.122.17.189 (E-KARNET.NET): KARUTURI TELECOM PVT LTD IS AN ISP WITH ITS OWN GATEWAY, BANGALORE, KARNATAKA, IN. (DSL) |
n/a | US:www.maxmind.com US:checkip.dyndns.org EU:getmyip.co.uk :www.getmyip.org US:208.43.124.51:80 US:216.146.39.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:04:38:00 | WinXP | 91.64.40.123 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, HAMBURG, HAMBURG, DE. (DSL) |
n/a | DE:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 1511a3f219 NEW |
none[none] | none:none |
none|none | none | none |
T:04:56:00 | WinXP | 59.117.182.148 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
36 of 43 | 42bff9d911 NEW |
none[none] | none:none |
none|none | none | none |
T:05:16:00 | WinXP | 77.64.207.136 (PRIMACOM.NET): PRIMACOM-HEADENDS, LEIPZIG, SACHSEN, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 43 | 53bd956572 NEW |
none[none] | none:none |
none|none | none | none | |
T:06:33:00 | WinXP | 186.196.186.195 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:06:49:00 | WinXP | 39.211.50.233 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 35 | 9716d7995a NEW |
c3a5354b6f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:07:16:00 | WinXP | 81.23.201.191 (SLADONEZH.RU): TRANSFER, RU. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 35 | e9fcd6f257 NEW |
2e05bc2272 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:08:59:00 | WinXP | 193.248.100.90 (ABO.WANADOO.FR): WANADOO FRANCE, PARIS, ILE-DE-FRANCE, FR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
25 of 32 | 8ad3105462 NEW |
none[4] | none:none |
none|none | none | trace | |
T:09:14:00 | WinXP | 178.167.190.205 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
43 of 43 | 24e8de6cb2 NEW |
none[none] | none:none |
none|none | none | none |
T:09:27:00 | WinXP | 92.47.153.199 (DIAL.ONLINE.KZ): JSC KAZAKHTELECOM KOSTANAY AFFILIATE, ALMATY, ALMATY CITY, KZ. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 43 | 0612a7de52 NEW |
none[none] | none:none |
none|none | none | none |
T:10:35:00 | WinXP | 24.214.119.167 (KNOLOGY.NET): KNOLOGY HOLDINGS INC, MADISON, ALABAMA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 36 0 of 32 |
126a1d4446 NEW 73f1082158 NEW |
31867051da [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=64 embedded dns lines=90 |
trace trace |
T:12:05:00 | WinXP | 134.249.19.179 (TERMBILLING.COM): VARIOUS REGISTRIES, UK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
37 of 43 | 831731ac0b NEW |
none[none] | none:none |
none|none | none | none |
T:13:49:00 | WinXP | 142.217.118.209 (TELEBECINTERNET.NET): TELEBEC, VAL-D'OR, QUEBEC, CA. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 0d1eb4df79 NEW |
none[none] | none:none |
none|none | none | none |
T:13:51:00 | WinXP | 31.63.225.181 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:14:15:00 | WinXP | 79.8.244.48 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA NET, BOLOGNA, EMILIA-ROMAGNA, IT. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:14:37:00 | WinXP | 178.150.103.244 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:15:26:00 | Win2K-f | 4.225.213.112 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DENVER, COLORADO, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:15:33:00 | WinXP | 50.11.17.146 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:16:27:00 | WinXP | 72.12.74.69 (OXFORDNETWORKS.NET): OXFORD NETWORKS, GREENWOOD, MAINE, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 314 lines |
Yeah : 1.3 profile |
none | summary tarball |
6 of 43 | cd452c38c5 NEW |
none[none] | none:none |
none|none | none | none | |
18:20:00 | Win2K-f | 69.111.252.194 (-): JOSEPH HAGGARTY, RENO, NEVADA, US. (100Mbps) |
n/a | US:www.maxmind.com EU:checkip.dyndns.org US:208.43.124.51:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:19:11:00 | WinXP | 112.204.210.250 (PLDT.NET): IPG, PH. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
19:35:00 | Win2K-f | 186.58.199.101 (COM.AR): TELEFONICA DE ARGENTINA, AR. (DSL) |
n/a | US:www.maxmind.com US:checkip.dyndns.org US:208.43.124.51:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
19:47:00 | Win2K-f | 189.1.173.11 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | US:www.maxmind.com US:checkip.dyndns.org BR:189.1.173.11:5333 US:208.43.124.51:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:20:19:00 | WinXP | 186.111.15.102 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 43 | 026010c112 NEW |
none[none] | none:none |
none|none | none | none |
20:20:00 | WinXP | 186.111.15.102 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 43 | 026010c112 NEW |
none[none] | none:none |
none|none | none | none |
22:06:00 | Win2K-f | 202.103.239.134 (163DATA.COM.CN): CHINANET GUANGXI PROVINCE NETWORK, BEIJING, BEIJING, CN. (100Mbps) |
n/a | US:www.maxmind.com EU:checkip.dyndns.org :www.getmyip.org EU:getmyip.co.uk JP:www.sbtjapan.com CN:202.103.239.134:7946 US:208.43.124.51:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 52 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |