Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:38:00 | WinXP | 175.177.175.88 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:00:48:00 | WinXP | 66.94.195.119 (FAMVID.COM): FAMILY VIDEO, GLENVIEW NAS, ILLINOIS, US. (DIAL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 | 7a3dc969d4 NEW |
none[none] | none:none |
none|none | none | none |
T:04:46:00 | WinXP | 46.109.72.76 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | 67db574df4 NEW |
none[none] | none:none |
none|none | none | none |
T:06:50:00 | WinXP | 130.239.84.201 (UMU.SE): UMEA UNIVERSITY, UMEA, VASTERBOTTENS LAN, SE. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | 5309ec15c8 NEW |
none[none] | none:none |
none|none | none | none |
T:07:11:00 | WinXP | 50.20.58.123 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:57:00 | WinXP | 114.178.193.2 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:08:01:00 | WinXP | 120.138.151.105 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 39 of 39 |
b8e6f4caf7 NEW fb92b91fe7 NEW |
f81eac6379 [0] fe88ab8768[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:08:17:00 | WinXP | 216.228.168.89 (BENDCABLE.COM): BEND CABLE COMMUNICATIONS LLC, BEND, OREGON, US. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 43 | 26afabae82 NEW |
none[none] | none:none |
none|none | none | none |
T:08:24:00 | WinXP | 2.192.242.159 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 42 | 0d1eb4df79 NEW |
none[none] | none:none |
none|none | none | none |
T:09:06:00 | Win2K-f | 114.204.58.181 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 37 of 40 |
5d445c59d8 NEW 8a54950abb NEW |
892e12db7b [0] f6b9e43917[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
12:15:00 | WinXP | 178.158.139.26 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |
T:12:22:00 | WinXP | 118.87.28.118 (ODWR.J-CNET.JP): ODAWARA CABLETV INTERNET SERVICE, ODAWARA, KANAGAWA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 122 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 36 34 of 36 |
0b951c2832 NEW e4ed4df0f0 NEW |
5fe761661a [0] de471fc380[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:13:25:00 | Win2K-f | 4.153.69.150 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, NASHVILLE, TENNESSEE, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:15:21:00 | WinXP | 93.102.43.122 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, PORTO, PORTO, PT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:16:51:00 | WinXP | 123.194.130.19 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | d464f16648 NEW |
none[none] | none:none |
none|none | none | none |
20:00:00 | WinXP | 75.79.188.96 (DSLEXTREME.COM): DSL EXTREME, CHATSWORTH, CALIFORNIA, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
21:11:00 | WinXP | 123.194.130.19 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | d464f16648 NEW |
none[none] | none:none |
none|none | none | none |
T:23:01:00 | WinXP | 117.20.169.138 (-): STARHUB HSPA, SINGAPORE, SINGAPORE, SG. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 43 | af614537c1 NEW |
none[none] | none:none |
none|none | none | none |
T:23:27:00 | WinXP | 109.52.130.179 (JWS.COM): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 43 | 6c7154fbdd NEW |
none[none] | none:none |
none|none | none | none |
T:23:28:00 | WinXP | 110.12.70.128 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
83.133.119.197:65520 | :proxim.ircgalaxy.pl US:microsoft.com EU:tyui89.com CN:www.herher.com US:hiringspecialists.com :www.google-analytics.com US:images01.tzimg.com :domdex.com :www.zzxml.com EU:www.lddwj.com :wpad EU:141.136.16.20:80 |
135 | pcap | raw alerts ruleset |
irc http 351 lines |
Yeah : 1.8 profile |
none | summary tarball |
17 of 42 37 of 43 none 28 of 32 20 of 42 38 of 43 |
42158bd0c4 NEW 69f32b85f1 NEW 8fd94dbad5 NEW 9276c8b36b NEW a7c4685c23 NEW acb3cb2acf NEW |
none[none] none [none] none [none] none [0] none [none] none [none] |
none:none none:none none:none none:none none:none none:none |
none|none none|none none|none Armadillo| none|none none|none |
none none none lines=90 none none |
none none none trace none none |
T:23:55:00 | WinXP | 101.13.206.54 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |