Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:43:00 | WinXP | 88.134.58.11 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, LANDAU, RHEINLAND-PFALZ, DE. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
00:58:00 | Win2K-f | 202.69.58.149 (-): NETDOOR COMMUNICATIONS PVT LTD, KARACHI, SINDH, PK. (DSL) |
n/a | :www.maxmind.com :www.getmyip.org EU:checkip.dyndns.org 174.36.207.186:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | 216ec67841 NEW |
none[3] | none:none |
StarForce| | none | trace |
T:01:51:00 | WinXP | 223.237.73.243 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
37 of 43 | ca3e3b13f3 NEW |
none[none] | none:none |
none|none | none | none |
T:02:58:00 | WinXP | 121.243.200.132 (VSNL.NET.IN): INTERNET SERVICE PROVIDER, CHENNAI, TAMIL NADU, IN. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:17:00 | WinXP | 91.66.95.137 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BAYREUTH, BAYERN, DE. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 1511a3f219 NEW |
none[none] | none:none |
none|none | none | none |
T:03:47:00 | WinXP | 182.63.35.102 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
43 of 43 | c049e988f2 NEW |
none[none] | none:none |
none|none | none | none |
T:05:55:00 | WinXP | 37.110.224.179 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:06:05:00 | WinXP | 151.28.109.71 (28-151.LIBERO.IT): FREE INTERNET DIAL-UP SERVICES, ROME, LAZIO, IT. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:07:40:00 | WinXP | 178.89.44.191 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 6455904435 NEW |
none[none] | none:none |
none|none | none | none |
T:08:18:00 | WinXP | 61.198.99.72 (THN.NE.JP): TOKAI CORPORATION, FUJI, SHIZUOKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 100 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 40 of 41 |
6a6aaa5b73 NEW 8bde6dd126 NEW |
63889c9976 [0] 885c68f500[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=42 lines=64 embedded dns |
trace trace |
T:09:37:00 | WinXP | 124.11.164.26 (TFN.NET.TW): TAIWAN FIXED NETWORK CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 43 | ca3e3b13f3 NEW |
none[none] | none:none |
none|none | none | none |
T:10:13:00 | WinXP | 111.254.222.66 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 43 | 11709c3a96 NEW |
none[none] | none:none |
none|none | none | none |
T:10:31:00 | WinXP | 50.27.235.43 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:10:55:00 | WinXP | 98.101.249.6 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:10:59:00 | WinXP | 118.171.132.66 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 43 | 283970c2d1 NEW |
none[none] | none:none |
none|none | none | none |
T:11:43:00 | WinXP | 79.133.147.33 (-): ADSL USERS, RU. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | 835c481730 NEW |
none[none] | none:none |
none|none | none | none |
T:11:51:00 | WinXP | 92.47.21.198 (DIAL.ONLINE.KZ): JSC KAZAKHTELECOM SOUTH KAZAKHSTAN AFFILIATE, ALMATY, ALMATY CITY, KZ. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 43 | e01ddca98c NEW |
none[none] | none:none |
none|none | none | none |
T:12:01:00 | WinXP | 178.25.77.91 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 42 | 0c3e031d4a NEW |
none[none] | none:none |
none|none | none | none |
T:13:07:00 | WinXP | 188.214.220.43 (TIM.RO): JUMP NETWORK SERVICES S.R.L, RO. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 42 | 8a2553433c NEW |
none[none] | none:none |
none|none | none | none |
T:13:55:00 | WinXP | 151.28.96.109 (28-151.LIBERO.IT): FREE INTERNET DIAL-UP SERVICES, BRESCIA, LOMBARDIA, IT. (DIAL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | 412a3c6dfe NEW |
none[none] | none:none |
none|none | none | none |
T:14:56:00 | WinXP | 46.153.87.74 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
15:12:00 | WinXP | 41.70.182.125 (-): . |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 43 | eda86b4a1c NEW |
none[none] | none:none |
none|none | none | none |
T:15:40:00 | Win2K-f | 61.150.5.66 (163DATA.COM.CN): XI'AN DATA BRANCH XIAN CITY SHAANXI PROVINCE, XIAN, SHAANXI, CN. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 41 of 43 |
5799ab6538 NEW ddbe111920 NEW |
2713679411 [0] none [none] |
ASM:Graph none:none |
tElock| none|none |
lines=64 embedded dns none |
trace none |
T:15:47:00 | WinXP | 65.36.22.226 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS ODESSA HUB, SAN MARCOS, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:16:08:00 | WinXP | 85.152.74.160 (CM-85-152-74-10.TELECABLE.ES): TELECABLE, ES. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
16:26:00 | Win2K-f | 190.111.22.250 (GRUPONAVEGA.COM): NAVEGA.COM S.A, GT. (DSL) |
n/a | :www.maxmind.com EU:getmyip.co.uk :www.getmyip.org US:checkip.dyndns.org DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 11 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
16:42:00 | Win2K-f | 121.242.205.168 (VSNL.NET.IN): INTERNET SERVICE PROVIDER, NEW DELHI, DELHI, IN. (DSL) |
n/a | :www.maxmind.com US:checkip.dyndns.org EU:getmyip.co.uk :www.getmyip.org DE:131.220.6.26:80 EU:91.198.22.70:80 |
139 | pcap | raw alerts ruleset |
http 11 lines |
Yeah : 0.8 profile |
none | summary tarball |
4 of 37 | 8ce32ded17 NEW |
none[3] | none:none |
Armadillo| | none | trace |
T:16:51:00 | Win2K-f | 121.242.205.168 (VSNL.NET.IN): INTERNET SERVICE PROVIDER, NEW DELHI, DELHI, IN. (DSL) |
n/a | :www.maxmind.com :www.getmyip.org EU:checkip.dyndns.org DE:131.220.6.26:80 |
139 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
4 of 37 | 8ce32ded17 NEW |
none[3] | none:none |
Armadillo| | none | trace |
T:17:31:00 | WinXP | 182.11.43.244 (-): . |
213.155.14.161:80 | :hny.rulm.ru DE:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 43 | e0f049796e NEW |
none[none] | none:none |
none|none | none | none |
17:37:00 | WinXP | 182.11.43.244 (-): . |
213.155.14.161:80 | :hny.rulm.ru DE:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 43 | e0f049796e NEW |
none[none] | none:none |
none|none | none | none |
T:17:41:00 | WinXP | 216.119.0.66 (DARIENTEL.NET): THE DARIEN TELEPHONE CO. INC, TOWNSEND, MASSACHUSETTS, US. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | be27c77fb5 NEW |
none[none] | none:none |
none|none | none | none |
18:19:00 | WinXP | 138.210.48.222 (EMBARQHSD.NET): EMBARQ CORPORATION, NAPLES, FLORIDA, US. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:18:57:00 | WinXP | 201.204.218.78 (-): ALAJUELA, SAN JOSE, SAN JOSE, CR. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 43 | d2c5aa9563 NEW |
none[none] | none:none |
none|none | none | none |
19:00:00 | WinXP | 201.204.218.78 (-): ALAJUELA, SAN JOSE, SAN JOSE, CR. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 43 | d2c5aa9563 NEW |
none[none] | none:none |
none|none | none | none |
T:19:04:00 | Win2K-f | 68.114.87.186 (CHARTER.COM): CHARTER COMMUNICATIONS, WORCESTER, MASSACHUSETTS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:16:00 | WinXP | 151.59.158.47 (51-151.NET24.IT): IUNET-BNET, TURIN, PIEMONTE, IT. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 42 | d41848bb61 NEW |
none[none] | none:none |
none|none | none | none |
T:21:51:00 | WinXP | 124.123.157.121 (BEAMCABLESYSTEM.IN): INTERNET TELEPHONY SERVICE PROVIDER, HYDERABAD, ANDHRA PRADESH, IN. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 269ce49eb2 NEW |
none[none] | none:none |
none|none | none | none |
T:22:10:00 | WinXP | 122.36.237.87 (-): POWERCOMM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | DE:proxima.ircgalaxy.pl | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 581c39a041 NEW |
none[none] | none:none |
none|none | none | none |
T:22:24:00 | Win2K-f | 120.138.158.136 (STARCAT.NE.JP): KMN CORPORATION, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
6a1dc43309 NEW 94e49d5627 NEW |
522dace6c1 [0] 777259292a[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
23:45:00 | WinXP | 66.94.194.152 (FAMVID.COM): FAMILY VIDEO, GLENVIEW NAS, ILLINOIS, US. (DIAL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | 7a3dc969d4 NEW |
none[none] | none:none |
none|none | none | none |