Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:14:00 | WinXP | 95.81.208.84 (CHTTS.RU): ROUTE TO VOLGATELECOM CHEBOXARY, RU. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
37 of 43 | ca3e3b13f3 NEW |
none[none] | none:none |
none|none | none | none |
T:02:40:00 | WinXP | 114.73.95.185 (OPTUSNET.COM.AU): OPTUS INTERNET - RETAIL, WINDSOR, NEW SOUTH WALES, AU. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:03:08:00 | WinXP | 87.97.195.38 (PL.EKK.BG): EKK CATV PLOVDIV, PLOVDIV, PLOVDIV, BG. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:03:35:00 | WinXP | 119.15.231.127 (TCOL.COM.TW): E-MAX NETWORK CORP, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:04:48:00 | Win2K-f | 24.121.167.146 (NPGCO.COM): CABLEVISION OF BULLHEAD, BULLHEAD CITY, ARIZONA, US. (DSL) |
n/a | :gg.arrancar.org | 135 | pcap | raw alerts ruleset |
other 158 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | 51a03793ab NEW |
429f7618d3 [0] | ASM:Graph |
none|none | lines=546 | trace |
T:05:04:00 | WinXP | 61.121.54.104 (INFOWEB.NE.JP): INFOWEB(FUJITSU LTD.), TOKYO, TOKYO, JP. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:05:43:00 | WinXP | 46.117.123.213 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:06:55:00 | WinXP | 46.203.115.169 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 7e91ed5d1d NEW |
none[none] | none:none |
none|none | none | none |
T:08:30:00 | WinXP | 178.151.167.79 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:10:39:00 | WinXP | 217.202.242.193 (-): TELECOM ITALIA MOBILE, ROME, LAZIO, IT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 43 | d1091a9c6d NEW |
none[none] | none:none |
none|none | none | none |
11:48:00 | WinXP | 41.70.181.137 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:12:14:00 | Win2K-f | 184.76.195.43 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | 916752f248 NEW |
4e604fc8cb [0] | ASM:Graph |
none|none | lines=546 | trace | |
T:12:37:00 | WinXP | 24.121.209.27 (NPGCO.COM): CABLEVISION OF BULLHEAD, BULLHEAD CITY, ARIZONA, US. (DSL) |
n/a | :gg.arrancar.org | 135 | pcap | raw alerts ruleset |
other 158 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 42 | ae16e77702 NEW |
none[none] | none:none |
none|none | none | none |
T:12:48:00 | Win2K-f | 50.75.61.131 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 158 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 39 | 2e8bb50e90 NEW |
none[none] | none:none |
none|none | none | none | |
T:12:49:00 | WinXP | 4.184.255.55 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, FREDERICKSBURG, VIRGINIA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 81 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:15:14:00 | WinXP | 151.83.41.141 (SER-PR2-MAX.IUNET.IT): INFOSTRADA, ROME, LAZIO, IT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:15:46:00 | WinXP | 59.113.160.15 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
37 of 43 | f5528e7b8f NEW |
none[none] | none:none |
none|none | none | none | |
15:47:00 | WinXP | 46.134.247.52 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | c19c8a2776 NEW |
none[none] | none:none |
none|none | none | none |
T:16:17:00 | WinXP | 190.227.138.159 (NET.AR): TELECOM PERSONAL BS AS, AR. (DSL) |
n/a | :siliconfireware.ru :wpad US:new.egg.com |
445 | pcap | raw alerts ruleset |
http http 24 lines |
Yeah : 0.8 profile |
none | summary tarball |
36 of 42 | 8c04bc802a NEW |
none[none] | none:none |
none|none | none | none |
T:16:54:00 | WinXP | 181.4.151.166 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 43 | 026010c112 NEW |
none[none] | none:none |
none|none | none | none |
T:22:40:00 | WinXP | 207.144.15.229 (CSTEL.NET): COM-SOUTH, KATHLEEN, GEORGIA, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
37 of 42 | 949ea433e3 NEW |
none[none] | none:none |
none|none | none | none |