Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:22:00 | WinXP | 90.149.168.104 (TELE2.NO): TELE2-ADSL-DYNAMIC, OSLO, OSLO, NO. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:01:02:00 | WinXP | 95.86.214.2 (-): MOBILE NETWORK TECHNICAL OPERATION CENTER, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 269ce49eb2 NEW |
none[none] | none:none |
none|none | none | none |
T:01:32:00 | WinXP | 210.166.48.128 (MEGAEGG.NE.JP): ENERGIA COMMUNICATIONS INC, JP. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
43 of 43 | debeecd50c NEW |
none[none] | none:none |
none|none | none | none |
T:02:29:00 | WinXP | 24.121.118.174 (NPGCO.COM): CABLEVISION OF BULLHEAD, BULLHEAD CITY, ARIZONA, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 0ab0d85629 NEW |
none[none] | none:none |
none|none | none | none |
T:02:50:00 | WinXP | 151.59.73.127 (51-151.NET24.IT): IUNET-BNET, MILANO, LOMBARDIA, IT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:03:23:00 | WinXP | 4.158.204.50 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DELANO, MINNESOTA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 80 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:27:00 | Win2K-f | 118.83.148.118 (NKNO.J-CNET.JP): CITY TV NAKANO LIMITED, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 123 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 37 of 40 |
acabc6b6d1 NEW c70fcf30a3 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
03:29:00 | WinXP | 4.224.141.183 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, INDIANAPOLIS, INDIANA, US. (DIAL) |
n/a | DE:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:05:39:00 | WinXP | 213.111.84.86 (IPAPER.COM): BLOCK FOR PI ASSIGNMENTS, UK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:07:16:00 | WinXP | 41.151.204.6 (TELKOMADSL.CO.ZA): AFRINIC, PRETORIA, GAUTENG, ZA. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:07:44:00 | WinXP | 176.30.154.137 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 43 | ca3e3b13f3 NEW |
none[none] | none:none |
none|none | none | none |
T:07:59:00 | Win2K-f | 122.146.240.248 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:09:47:00 | WinXP | 151.63.130.85 (51-151.NET24.IT): IUNET-BNET, ROME, LAZIO, IT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 0d1eb4df79 NEW |
none[none] | none:none |
none|none | none | none |
10:13:00 | Win2K-f | 94.102.15.106 (-): NETINTERNET BILGISAYAR VE TELEKOMUNIKASYON SAN. VE TIC. LTD. STI, TR. (DSL) |
n/a | US:www.maxmind.com US:checkip.dyndns.org EU:getmyip.co.uk :www.getmyip.org US:208.43.124.51:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 8 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:10:22:00 | Win2K-f | 94.102.15.106 (-): NETINTERNET BILGISAYAR VE TELEKOMUNIKASYON SAN. VE TIC. LTD. STI, TR. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk US:checkip.dyndns.org :www.getmyip.org DE:131.220.6.26:80 EU:78.40.35.130:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:12:18:00 | WinXP | 188.195.89.236 (SUPERKABEL.DE): KABEL DEUTSCHLAND BREITBAND SERVICE GMBH, DE. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | dbf05175ec NEW |
none[none] | none:none |
none|none | none | none |
T:12:51:00 | WinXP | 31.200.176.165 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 42 | 0d1eb4df79 NEW |
none[none] | none:none |
none|none | none | none |
T:13:33:00 | WinXP | 109.60.243.83 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:14:16:00 | WinXP | 94.235.147.139 (-): WARID TELECOM GEORGIA LTD, GE. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:14:29:00 | WinXP | 217.203.151.173 (-): TELECOM ITALIA MOBILE, ROME, LAZIO, IT. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | 1a3cd151eb NEW |
none[none] | none:none |
none|none | none | none |
T:15:11:00 | WinXP | 109.86.151.87 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | aad01847fa NEW |
none[none] | none:none |
none|none | none | none |
T:15:36:00 | Win2K-f | 210.120.52.238 (BORA.NET): BORANET-NET, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:20:07:00 | WinXP | 61.61.235.137 (UBBN.NET): UNION BROADBAND NETWORK, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
35 of 35 | 9716d7995a NEW |
c3a5354b6f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |