Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:35:00 | WinXP | 94.52.221.136 (-): NEW COM TELECOMUNICATII SA, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | 488d27fe97 NEW |
none[none] | none:none |
none|none | none | none |
T:01:36:00 | WinXP | 119.15.231.127 (TCOL.COM.TW): E-MAX NETWORK CORP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:03:44:00 | WinXP | 61.216.228.101 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:06:21:00 | Win2K-f | 211.215.229.96 (HANANET.NET): HANARO TELECOM INC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
83.133.119.197:65520 | DE:proxim.ircgalaxy.pl US:microsoft.com :vetvetcom.com EU:tretr23.com :ytreytre.com 117.241.136.43:3128 119.154.131.130:3128 178.90.207.2:3128 178.90.37.103:3128 184.173.252.246:443 CN:222.88.205.195:443 223.175.242.170:3128 223.223.137.230:3128 46.185.128.33:3128 IN:61.0.123.130:3128 RO:89.40.49.111:3128 93.74.85.200:3128 |
135 | pcap | raw alerts ruleset |
irc http http 130 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 42 30 of 43 34 of 43 25 of 43 36 of 42 38 of 42 |
0ed155401e NEW 5f48731984 NEW 6dfaa9ebca NEW b64990c0ef NEW bf063bba17 NEW f269760f66 NEW |
none[none] none [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none none|none |
none none none none none none |
none none none none none none |
T:06:30:00 | Win2K-f | 95.25.77.199 (CORBINA.RU): INVESTELEKTROSVIAZ LTD, MOSCOW, MOSCOW CITY, RU. (DSL) |
95.143.193.118:65520 | EU:tretr23.com :ytreytre.com DE:proxim.ircgalaxy.pl :vetvetcom.com 178.126.68.139:6667 182.5.231.128:6667 184.173.252.243:443 184.173.252.246:443 EU:188.126.150.212:6667 CN:222.88.205.195:443 223.175.226.91:6667 223.175.231.93:3128 223.175.233.197:3128 223.175.242.231:6667 41.107.0.115:3128 CN:59.51.52.178:6667 FR:82.239.165.28:6667 EU:91.202.135.226:3128 |
445 | pcap | raw alerts ruleset |
irc http http 21 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 42 39 of 42 30 of 43 34 of 43 25 of 43 |
0ed155401e NEW 554de1e248 NEW 5f48731984 NEW 6dfaa9ebca NEW b64990c0ef NEW |
none[none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none |
none none none none none |
none none none none none |
T:07:54:00 | WinXP | 98.132.175.128 (WINDSTREAM.NET): ALLTEL LNS CUSTOMERS - LITTLE ROCK, BLOOMING PRAIRIE, MINNESOTA, US. (DIAL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 3bb58142f4 NEW |
none[none] | none:none |
none|none | none | none |
T:08:12:00 | WinXP | 211.133.210.241 (THN.NE.JP): TOKAI CORPORATION, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 40 of 41 |
71e6f60517 NEW ab4e3226c4 NEW |
1ef1781501 [0] c2d0313e73[0] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=91 none |
trace trace |
T:09:14:00 | WinXP | 223.16.78.10 (-): . |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | 66a7e9abab NEW |
none[none] | none:none |
none|none | none | none |
T:12:18:00 | WinXP | 90.149.90.70 (TELE2.NO): TELE2-ADSL-DYNAMIC, OSLO, OSLO, NO. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:12:27:00 | WinXP | 216.252.37.93 (-): AVENUE BROADBAND COMMUNICATIONS INC, TYLER, TEXAS, US. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 | bcb3ec60f2 NEW |
none[none] | none:none |
none|none | none | none |
T:12:56:00 | WinXP | 95.72.81.250 (-): KOLOMNA FLATE RATE POOL, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | 88ef3a1429 NEW |
none[none] | none:none |
none|none | none | none |
13:00:00 | WinXP | 216.252.37.93 (-): AVENUE BROADBAND COMMUNICATIONS INC, TYLER, TEXAS, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | bcb3ec60f2 NEW |
none[none] | none:none |
none|none | none | none |
T:14:18:00 | WinXP | 79.125.196.37 (FINANCE.GOV.MK): MAKEDONSKI TELEKOMUNIKACII A.D, SKOPJE, KARPOS, MK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 0d1eb4df79 NEW |
none[none] | none:none |
none|none | none | none |
16:31:00 | WinXP | 75.102.188.25 (ITCTEL.COM): INTERSTATE TELECOMMUNICATIONS COOPERATIVE INC, CLEAR LAKE, SOUTH DAKOTA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 3ae357d17b NEW |
none[0] | none:none |
PolyEnE| | lines=73 | trace |
T:17:08:00 | WinXP | 209.54.64.163 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:17:14:00 | WinXP | 95.92.254.13 (-): TVCABO PORTUGAL S.A, PT. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:18:10:00 | WinXP | 61.150.5.66 (163DATA.COM.CN): XI'AN DATA BRANCH XIAN CITY SHAANXI PROVINCE, XIAN, SHAANXI, CN. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 41 of 43 |
5799ab6538 NEW ddbe111920 NEW |
2713679411 [0] none [none] |
ASM:Graph none:none |
tElock| none|none |
lines=64 embedded dns none |
trace none |
T:18:36:00 | WinXP | 223.142.7.8 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:19:57:00 | Win2K-f | 96.11.193.159 (RR.COM): ROAD RUNNER HOLDCO LLC, WEST CHESTER, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 40 |
9bdd2c95b1 NEW cd456ac095 NEW |
d1bbd693ba [0] d75caee680[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:21:50:00 | WinXP | 41.70.181.137 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |