Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:21:00 | WinXP | 101.12.124.29 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | 488d27fe97 NEW |
none[none] | none:none |
none|none | none | none |
T:00:31:00 | WinXP | 49.133.43.90 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 44 41 of 44 |
99f212a9df NEW 9fa81e360b NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:01:50:00 | WinXP | 78.147.59.190 (AS13285.NET): OPAL TELECOM DSL, LONDON, ENGLAND, UK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
02:28:00 | WinXP | 113.10.92.177 (-): STARHUB HSDPA SG, SG. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | 66a7e9abab NEW |
none[none] | none:none |
none|none | none | none |
T:04:28:00 | WinXP | 109.86.151.87 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | aad01847fa NEW |
none[none] | none:none |
none|none | none | none |
T:06:16:00 | WinXP | 223.217.107.7 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:10:25:00 | WinXP | 31.40.104.111 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | 488d27fe97 NEW |
none[none] | none:none |
none|none | none | none |
T:10:52:00 | WinXP | 186.110.247.91 (-): . |
n/a | :siliconfireware.ru :wpad RU:www.bbin.ru RU:www.binbank.ru |
445 | pcap | raw alerts ruleset |
http http 21 lines |
Yeah : 0.8 profile |
none | summary tarball |
36 of 42 | 8c04bc802a NEW |
none[none] | none:none |
none|none | none | none |
T:12:30:00 | WinXP | 4.236.15.199 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, NEW YORK, NEW YORK, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 86 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:52:00 | Win2K-f | 208.82.46.239 (ENERGIZE.NET): PULASKI ELECTRIC SYSTEM, PULASKI, TENNESSEE, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
17:23:00 | Win2K-f | 61.7.151.98 (-): 10 FL. 72. CAT TELECOM TOWER BANGRAK BANGKOK THAILAND, BANGKOK, KRUNG THEP, TH. (DSL) |
n/a | US:www.maxmind.com :www.getmyip.org US:checkip.dyndns.org EU:getmyip.co.uk US:208.43.124.51:80 EU:78.40.35.130:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 7587773eea NEW |
none[3] | none:none |
StarForce| | none | trace |
T:20:27:00 | WinXP | 186.23.77.127 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 43 | 8e7ffd9fdc NEW |
none[none] | none:none |
none|none | none | none |
T:21:11:00 | Win2K-f | 216.188.219.202 (SMIG.NET): SOUTHERN MINNESOTA INTERNET GROUP, AUSTIN, MINNESOTA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 114 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:21:43:00 | Win2K-f | 68.189.248.16 (CHARTER.COM): CHARTER COMMUNICATIONS, PEPPERELL, MASSACHUSETTS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:23:25:00 | Win2K-f | 110.12.70.196 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
95.143.193.118:65520 | :proxim.ircgalaxy.pl US:microsoft.com :newsoftnewsworld.com EU:adquorum.com :vetvetcom.com EU:tretr23.com :ytreytre.com 184.173.252.243:443 184.173.252.246:443 CN:222.88.205.195:443 94.63.240.235:80 |
135 | pcap | raw alerts ruleset |
irc http 125 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 42 30 of 43 33 of 42 29 of 44 30 of 43 39 of 42 |
0ed155401e NEW 5f48731984 NEW 69f59a0454 NEW b44d3ea50e NEW c5055355dc NEW f4c93e7909 NEW |
none[none] none [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none none|none |
none none none none none none |
none none none none none none |
T:23:59:00 | Win2K-f | 77.29.128.56 (-): ADSL IP SUBNET, TETOVO, TETOVO, MK. (DSL) |
n/a | US:hotdisability.net US:excellentbankruptcy.com :proxim.ircgalaxy.pl US:microsoft.com CA:vrobots.com CN:myck.nucleardiscover.com CN:w.nucleardiscover.com EU:tretr23.com US:pamlicocommunitycollege.net US:bankruptcybarcelona.net 223.175.225.118:6667 CN:59.55.138.132:6667 95.57.100.125:6667 |
445 | pcap | raw alerts ruleset |
http 23 lines |
Argh : 0.3 profile |
none | summary tarball |
1 of 43 | d4fafe14a7 NEW |
none[none] | none:none |
none|none | none | none |