Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:40:00 | Win2K-f | 202.56.192.195 (MANTRAONLINE.COM): USED FOR NETWORK INFRASTRUCTURE, CHENNAI, TAMIL NADU, IN. (DSL) |
n/a | US:www.maxmind.com US:checkip.dyndns.org US:208.43.124.51:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:00:45:00 | Win2K-f | 120.138.185.44 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
6a1dc43309 NEW 94e49d5627 NEW |
522dace6c1 [0] 777259292a[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:01:11:00 | Win2K-f | 70.60.10.76 (RR.COM): ROAD RUNNER HOLDCO LLC, HILLIARD, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:01:44:00 | WinXP | 66.90.145.108 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS AUSTIN HUB, AUSTIN, TEXAS, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:02:39:00 | WinXP | 173.22.144.247 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, SPRINGFIELD, MISSOURI, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:02:41:00 | Win2K-f | 24.155.7.215 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS WACO, WOODWAY, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:03:05:00 | WinXP | 91.64.44.207 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, KIEL, SCHLESWIG-HOLSTEIN, DE. (DSL) |
n/a | DE:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 1511a3f219 NEW |
none[none] | none:none |
none|none | none | none |
T:03:15:00 | WinXP | 113.10.110.202 (-): STARHUB HSDPA SG, SG. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
38 of 43 | 86ba17986b NEW |
none[none] | none:none |
none|none | none | none |
T:03:39:00 | WinXP | 217.203.161.231 (-): TELECOM ITALIA MOBILE, ROME, LAZIO, IT. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:05:57:00 | WinXP | 24.156.25.124 (NPGCO.COM): CABLEVISION OF BULLHEAD, US. (DSL) |
n/a | :gg.arrancar.org | 135 | pcap | raw alerts ruleset |
other 158 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | 51a03793ab NEW |
429f7618d3 [0] | ASM:Graph |
none|none | lines=546 | trace |
T:06:08:00 | WinXP | 186.97.123.140 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:07:28:00 | WinXP | 41.70.151.8 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
08:20:00 | WinXP | 101.15.195.236 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | ab16f1a1c0 NEW |
none[none] | none:none |
none|none | none | none |
T:09:07:00 | WinXP | 94.251.138.195 (-): CUSTOMER IN CZESTOCHOWA, CZESTOCHOWA, SLASKIE, PL. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 43 | e3713918df NEW |
none[none] | none:none |
none|none | none | none |
T:09:43:00 | WinXP | 77.20.52.253 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, GöTTINGEN, NIEDERSACHSEN, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | 03f912899b NEW |
none[0] | none:none |
none|none | lines=64 | trace | |
T:09:52:00 | Win2K-f | 219.71.114.122 (GIGA.NET.TW): HOSHIN MULTIMEDIA CENTER INC, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 80 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:30:00 | Win2K-f | 216.82.194.176 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS CORPUS CHRISTI HUB, CORPUS CHRISTI, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:12:12:00 | WinXP | 178.17.124.128 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 43 | c8d42bea74 NEW |
none[none] | none:none |
none|none | none | none |
T:12:57:00 | WinXP | 79.125.199.164 (FINANCE.GOV.MK): MAKEDONSKI TELEKOMUNIKACII A.D, SKOPJE, KARPOS, MK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 42 | 0d1eb4df79 NEW |
none[none] | none:none |
none|none | none | none |
T:13:00:00 | WinXP | 94.52.221.136 (-): NEW COM TELECOMUNICATII SA, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | 488d27fe97 NEW |
none[none] | none:none |
none|none | none | none |
T:14:29:00 | WinXP | 178.150.50.190 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:14:37:00 | WinXP | 41.143.9.210 (IAM.NET.MA): AFRINIC, MA. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 43 | 36b7b47613 NEW |
none[none] | none:none |
none|none | none | none |
T:15:14:00 | WinXP | 46.211.48.222 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:17:53:00 | WinXP | 4.143.226.64 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, BIG ROCK, ILLINOIS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 60 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:18:15:00 | Win2K-f | 72.45.19.145 (ATLANTICBB.NET): ATLANTIC BROADBAND, SMYRNA, DELAWARE, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:18:41:00 | Win2K-f | 24.49.148.169 (COOSAHS.NET): COOSA CABLE CO. INC, PELL CITY, ALABAMA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 43 38 of 41 |
31000127c2 NEW c6f4f8e31a NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:19:47:00 | WinXP | 211.75.159.211 (KENNY.COM.TW): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:52:00 | Win2K-f | 211.215.229.96 (HANANET.NET): HANARO TELECOM INC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
94.63.149.150:65520 | US:microsoft.com DE:proxim.ircgalaxy.pl :mnbmnbmnb.com EU:tretr23.com :nochnoch98.com 111.88.0.32:3128 117.211.58.188:3128 119.154.22.99:3128 184.154.138.35:3128 184.173.252.246:443 223.175.226.188:3128 223.175.23.220:3128 223.175.242.192:3128 27.2.246.103:3128 IR:82.115.19.124:3128 |
135 | pcap | raw alerts ruleset |
irc http 132 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 42 30 of 43 30 of 42 26 of 42 36 of 42 38 of 42 |
0ed155401e NEW 5f48731984 NEW 72898254bb NEW 7ee94178a2 NEW bf063bba17 NEW f269760f66 NEW |
none[none] none [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none none|none |
none none none none none none |
none none none none none none |
T:21:59:00 | Win2K-f | 1.161.144.174 (-): . |
83.133.119.197:65520 | EU:tretr23.com :nochnoch98.com DE:proxim.ircgalaxy.pl EU:backup-windows.ru :mnbmnbmnb.com 178.122.125.80:3128 178.126.7.57:3128 EU:188.129.174.18:6667 223.175.232.98:6667 223.175.241.154:6667 223.175.241.169:3128 31.44.142.20:6667 49.201.146.253:6667 EU:78.138.22.163:6667 EU:79.116.197.59:3128 92.47.131.173:3128 95.59.190.60:6667 |
445 | pcap | raw alerts ruleset |
http irc http 21 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 42 30 of 42 26 of 42 |
0ed155401e NEW 72898254bb NEW 7ee94178a2 NEW |
none[none] none [none] none [none] |
none:none none:none none:none |
none|none none|none none|none |
none none none |
none none none |
22:01:00 | Win2K-f | 210.245.85.175 (FPT-CUSTOMERS.FPT.VN): DAI IP CHO HOSTING GAME, VN. (DSL) |
n/a | US:www.maxmind.com EU:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
5 of 37 | 741c93f3c1 NEW |
none[3] | none:none |
UPX| | none | trace |
T:22:04:00 | WinXP | 92.36.5.229 (SKYLINK.RU): MOSCOW CELLULAR COMMUNICATIONS, RU. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
22:50:00 | Win2K-f | 180.222.218.148 (-): . |
n/a | US:www.maxmind.com US:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:22:55:00 | Win2K-f | 65.36.21.120 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS ODESSA HUB, SAN MARCOS, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:23:00:00 | Win2K-f | 180.222.218.148 (-): . |
n/a | US:www.maxmind.com :www.getmyip.org US:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:23:42:00 | WinXP | 27.54.4.154 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 43 | 86ba17986b NEW |
none[none] | none:none |
none|none | none | none |