Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:11:00 | WinXP | 90.149.93.108 (TELE2.NO): TELE2-ADSL-DYNAMIC, ASKER, AKERSHUS, NO. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:00:27:00 | WinXP | 112.67.125.126 (163DATA.COM.CN): CHINANET HAINAN PROVINCE NETWORK, BEIJING, BEIJING, CN. (DSL) |
n/a | TR:adiyamanlicigkoftecim.com **:akordketrzyn.ugu.pl TR:akcainsaat.com TR:akdari.com US:alsharqpaper.net :apadanapub.com |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:00:43:00 | WinXP | 213.6.11.177 (PALTEL.NET): PALESTINE TELECOMMUNICATIONS COMPANY (PALTEL), IL. (DSL) |
n/a | :jsthomes.com TR:adiyamanlicigkoftecim.com **:akordketrzyn.ugu.pl TR:akcainsaat.com TR:akdari.com US:alsharqpaper.net :apadanapub.com 182.50.134.1:80 TR:89.19.29.176:80 TR:89.19.30.180:80 |
445 | pcap | raw alerts ruleset |
http 20 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:01:47:00 | Win2K-f | 66.166.121.174 (COVAD.NET): COVAD COMMUNICATIONS CO, LOS ANGELES, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:01:51:00 | WinXP | 93.80.51.172 (CORBINA.RU): BROADBAND CUSTOMERS IN MOSCOW, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | US:alsharqpaper.net :apadanapub.com |
445 | pcap | raw alerts ruleset |
http 30 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:02:19:00 | WinXP | 95.104.45.153 (CAUCASUS.NET): CAUCASUS ONLINE BROADBAND NETWORK, GE. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:02:40:00 | WinXP | 196.202.123.142 (TEDATA.NET): TEDATA-RAMSIS- DSL, CAIRO, AL QAHIRAH, EG. (DSL) |
n/a | :jsthomes.com TR:adiyamanlicigkoftecim.com **:akordketrzyn.ugu.pl TR:akcainsaat.com TR:akdari.com US:alsharqpaper.net :apadanapub.com 182.50.134.1:80 US:63.251.171.80:80 TR:89.19.29.176:80 TR:89.19.30.180:80 |
445 | pcap | raw alerts ruleset |
http 18 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:02:51:00 | WinXP | 46.134.229.77 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
35 of 36 | f3440caba1 NEW |
none[none] | none:none |
none|none | none | none |
T:03:34:00 | Win2K-f | 118.83.45.86 (HTOJ.J-CNET.JP): JCN-HTMNET, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 122 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 36 34 of 36 |
0b951c2832 NEW e4ed4df0f0 NEW |
5fe761661a [0] de471fc380[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
04:03:00 | WinXP | 123.81.252.189 (JWS.COM): CHINA TIETONG TELECOMMUNICATIONS CORPORATION, BEIJING, BEIJING, CN. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 9276456bf8 NEW |
none[none] | none:none |
none|none | none | none |
T:06:08:00 | Win2K-f | 66.166.121.174 (COVAD.NET): COVAD COMMUNICATIONS CO, LOS ANGELES, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:06:20:00 | WinXP | 109.239.47.117 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 43 | ca3e3b13f3 NEW |
none[none] | none:none |
none|none | none | none |
T:07:49:00 | WinXP | 69.36.218.16 (SPEAKEASY.NET): NEW HAVEN, CONNECTICUT, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | be27c77fb5 NEW |
none[none] | none:none |
none|none | none | none |
T:07:53:00 | WinXP | 67.133.212.248 (-): CKY CITY OF BARDSTOWN, BARDSTOWN, KENTUCKY, US. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
08:11:00 | WinXP | 67.133.212.248 (-): CKY CITY OF BARDSTOWN, BARDSTOWN, KENTUCKY, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:08:27:00 | WinXP | 110.14.197.56 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
94.63.147.131:65520 91.226.212.159:65520 | EU:proxim.ircgalaxy.pl US:microsoft.com EU:ghyt54.com EU:largokal.net EU:adspecul.com EU:poilka09.com EU:gamesnetforum.ru EU:bdgoblin.com 184.173.252.243:443 184.173.252.246:443 EU:188.247.135.109:80 EU:188.247.135.69:80 EU:188.247.135.98:80 |
135 | pcap | raw alerts ruleset |
irc http http http 133 lines |
Yeah : 1.8 profile |
none | summary tarball |
22 of 43 33 of 42 21 of 43 17 of 43 39 of 42 |
1da4a43a39 NEW 69f59a0454 NEW 941c3fa895 NEW e3a3dd9f16 NEW f4c93e7909 NEW |
none[none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none |
none none none none none |
none none none none none |
T:08:45:00 | WinXP | 176.8.157.163 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:10:05:00 | WinXP | 98.101.249.6 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:10:58:00 | Win2K-f | 96.8.188.216 (GVTC.COM): GUADALUPE VALLEY TELEPHONE COOPERATIVE INC, NEW BRAUNFELS, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 40 |
9bdd2c95b1 NEW cd456ac095 NEW |
d1bbd693ba [0] d75caee680[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:11:34:00 | WinXP | 109.54.67.26 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 8a2553433c NEW |
none[none] | none:none |
none|none | none | none |
T:12:26:00 | WinXP | 95.173.13.138 (-): TT & TIM ILETISIM HIZMETLERI A.S, ISTANBUL, ISTANBUL, TR. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 7fc5cd8760 NEW |
none[none] | none:none |
none|none | none | none |
T:12:57:00 | WinXP | 85.152.74.160 (CM-85-152-74-10.TELECABLE.ES): TELECABLE, ES. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:13:24:00 | Win2K-f | 24.121.250.99 (NPGCO.COM): CABLEVISION OF BULLHEAD, BULLHEAD CITY, ARIZONA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 157 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | 51a03793ab NEW |
429f7618d3 [0] | ASM:Graph |
none|none | lines=546 | trace | |
T:13:43:00 | WinXP | 178.158.139.26 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:14:08:00 | Win2K-f | 70.182.76.81 (COX.NET): COX COMMUNICATIONS, TULSA, OKLAHOMA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1008 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 41 | 682a384fe9 NEW |
none[3] | none:none |
none|none | none | trace | |
T:14:48:00 | WinXP | 213.111.217.137 (IPAPER.COM): BLOCK FOR PI ASSIGNMENTS, UK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:15:12:00 | WinXP | 186.51.213.206 (-): . |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 309b295182 NEW |
none[none] | none:none |
none|none | none | none |
T:16:02:00 | Win2K-f | 98.141.163.84 (CAVTEL.NET): CAVALIER TELEPHONE, PHILADELPHIA, PENNSYLVANIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:16:29:00 | WinXP | 77.54.165.207 (REV.VODAFONE.PT): VODAFONE PORTUGAL, PT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:17:03:00 | WinXP | 46.117.123.213 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:19:26:00 | Win2K-f | 219.71.225.147 (GIGA.NET.TW): HOSHIN MULTIMEDIA CENTER INC, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:19:52:00 | WinXP | 190.241.201.250 (-): CABLE VISION, SAN JOSE, SAN JOSE, CR. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | bcb3ec60f2 NEW |
none[none] | none:none |
none|none | none | none |
T:20:09:00 | WinXP | 111.252.45.158 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:20:13:00 | WinXP | 211.76.76.192 (UBBN.NET): TAIWAN NETWORK INFORMATION CENTER, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 35 | 9716d7995a NEW |
c3a5354b6f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:20:44:00 | WinXP | 122.134.67.4 (MESH.AD.JP): NEC BIGLOBE LTD, SENDAI, MIYAGI, JP. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 9276456bf8 NEW |
none[none] | none:none |
none|none | none | none |
T:20:57:00 | WinXP | 113.10.100.76 (-): STARHUB HSDPA SG, SG. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 43 | 86ba17986b NEW |
none[none] | none:none |
none|none | none | none |
T:22:41:00 | Win2K-f | 70.60.191.151 (RR.COM): ROAD RUNNER HOLDCO LLC, MEMPHIS, TENNESSEE, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:45:00 | Win2K-f | 64.136.73.53 (64.IN-ADDR.ARPA): CENTRAMEDIA INCORPORATED, PAMPA, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 44 38 of 43 |
67c849c687 NEW fcd5ed4078 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:23:55:00 | WinXP | 180.176.85.62 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 9276456bf8 NEW |
none[none] | none:none |
none|none | none | none |