Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:15:00 | WinXP | 79.133.154.44 (-): ADSL USERS, RU. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 835c481730 NEW |
none[none] | none:none |
none|none | none | none |
T:00:29:00 | WinXP | 217.17.102.202 (-): CS-SAT-TRAKT, CS. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:02:37:00 | Win2K-f | 4.154.124.211 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, LITHIA SPRINGS, GEORGIA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 81 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
|
03:37:00 | Win2K-f | 202.129.196.138 (WLS.NET.IN): WIRELESS SOLUTION INDIA PVT LTD, IN. (DSL) |
n/a | :www.maxmind.com US:checkip.dyndns.org EU:getmyip.co.uk :www.getmyip.org 174.36.207.186:80 EU:78.40.35.130:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | 71afca1665 NEW |
none[3] | none:none |
StarForce| | none | trace |
T:03:46:00 | Win2K-f | 202.129.196.138 (WLS.NET.IN): WIRELESS SOLUTION INDIA PVT LTD, IN. (DSL) |
n/a | :www.maxmind.com EU:getmyip.co.uk :www.getmyip.org US:checkip.dyndns.org DE:131.220.6.26:80 174.36.207.186:80 |
445 | pcap | raw alerts ruleset |
http 10 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | 71afca1665 NEW |
none[3] | none:none |
StarForce| | none | trace |
T:04:56:00 | WinXP | 123.192.180.205 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:05:41:00 | WinXP | 220.228.87.13 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:06:05:00 | WinXP | 24.155.205.225 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS CORPUS CHRISTI HUB, CORPUS CHRISTI, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:06:36:00 | WinXP | 141.136.94.112 (TERMBILLING.COM): VARIOUS REGISTRIES, UK. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |
T:07:24:00 | WinXP | 50.27.235.43 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:08:18:00 | WinXP | 79.133.128.228 (-): ADSL USERS, RU. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 835c481730 NEW |
none[none] | none:none |
none|none | none | none |
T:08:28:00 | Win2K-f | 220.216.62.78 (THN.NE.JP): TOKAI CORPORATION, SHIZUOKA, SHIZUOKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 40 of 41 |
6a6aaa5b73 NEW 8bde6dd126 NEW |
63889c9976 [0] 885c68f500[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=42 lines=64 embedded dns |
trace trace |
T:08:49:00 | WinXP | 91.65.255.3 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BERLIN, BERLIN, DE. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:08:56:00 | WinXP | 46.235.176.208 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | c19c8a2776 NEW |
none[none] | none:none |
none|none | none | none |
T:11:15:00 | WinXP | 188.192.248.120 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 2acefaf1dc NEW |
none[none] | none:none |
none|none | none | none |
T:11:26:00 | WinXP | 95.90.73.101 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BERLIN, BERLIN, DE. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | 412a3c6dfe NEW |
none[none] | none:none |
none|none | none | none |
T:12:15:00 | WinXP | 88.134.106.24 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, LANDAU, RHEINLAND-PFALZ, DE. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:12:25:00 | WinXP | 151.59.191.229 (51-151.NET24.IT): IUNET-BNET, IT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:15:23:00 | WinXP | 1.163.152.24 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | d583927fe4 NEW |
none[none] | none:none |
none|none | none | none |
T:15:32:00 | WinXP | 78.130.101.251 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, LISBON, LISBOA, PT. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | ec7ef0a16b NEW |
none[none] | none:none |
none|none | none | none |
T:15:46:00 | WinXP | 211.124.226.180 (ZAQ.NE.JP): K CABLE TELEVISION CORPORATION INC, OSAKA, OSAKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
none:none ASM:Graph |
Armadillo| tElock| |
lines=90 lines=75 embedded dns |
trace trace |
T:15:48:00 | WinXP | 70.60.191.151 (RR.COM): ROAD RUNNER HOLDCO LLC, MEMPHIS, TENNESSEE, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:04:00 | WinXP | 112.199.38.134 (EASTERN-TELE.COM): EASTERN TELECOM PHILIPPINES INC, PH. (DSL) |
n/a | DE:citi-bank.ru :arqdesigngv.com.br :asch-bourj.org :asli.gencbeta.com :asmadania.com DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 43 | d1091a9c6d NEW |
none[none] | none:none |
none|none | none | none |
T:17:58:00 | WinXP | 92.229.11.13 (ALICEDSL.DE): HANSENET-ADSL, DE. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | 3310ff58b4 NEW |
none[none] | none:none |
none|none | none | none |
T:18:02:00 | Win2K-f | 117.104.31.61 (T-COM.NE.JP): TOKAI CORPORATION, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 41 |
6b315f5dbc NEW 7938865f8c NEW |
7604b94520 [0] a9b9e4904b[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
T:18:25:00 | WinXP | 4.152.165.182 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, NASHVILLE, TENNESSEE, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 100 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:56:00 | WinXP | 89.214.193.240 (-): GPRS COSTUMERS, LISBON, LISBOA, PT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 42 | 79abfc94b7 NEW |
none[none] | none:none |
none|none | none | none |
T:19:12:00 | WinXP | 176.59.133.104 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 1096ba143e NEW |
none[none] | none:none |
none|none | none | none | |
19:27:00 | WinXP | 176.59.133.104 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 1096ba143e NEW |
none[none] | none:none |
none|none | none | none |
T:19:57:00 | WinXP | 221.121.243.222 (CCNW.NE.JP): CHUBU CABLE NETWORK COMPANY INCORPORATED, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
none:none ASM:Graph |
Armadillo| tElock| |
lines=90 lines=75 embedded dns |
trace trace |
T:21:09:00 | WinXP | 98.135.17.169 (WINDSTREAM.NET): ALLTEL MIP CUSTOMERS - OMAHA, LITTLE ROCK, ARKANSAS, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | ca345ba31a NEW |
none[none] | none:none |
none|none | none | none |
21:28:00 | Win2K-f | 78.111.104.127 (TEKLAN.COM.TR): TEKLAN INTERNET ERISIM HIZMETLERI KOMUNIKASYON ELEKTRONIK SAN A.S, ISTANBUL, ISTANBUL, TR. (DSL) |
n/a | :www.maxmind.com EU:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
36 of 43 | 138706aee9 NEW |
none[none] | none:none |
none|none | none | none |
T:21:43:00 | Win2K-f | 49.135.92.94 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 44 41 of 44 |
99f212a9df NEW 9fa81e360b NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:22:44:00 | Win2K-f | 112.206.85.14 (PLDT.NET): IPG, PH. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 671 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 787e28a9ca NEW |
none[none] | none:none |
none|none | none | none | |
T:23:59:00 | WinXP | 218.228.21.202 (CTT.NE.JP): CABLE TELEVISION TOYAMA INCORPORETED, TOYAMA, TOYAMA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
761a66b891 NEW 98d05c039b NEW |
b469dac5dc [0] none [none] |
ASM:Graph none:none |
tElock| none|none |
lines=64 embedded dns none |
trace none |