Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:08:00 | Win2K-f | 75.37.173.250 (SBCGLOBAL.NET): JASON LEE, PLANO, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:01:40:00 | WinXP | 37.252.69.31 (-): . |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |
T:02:25:00 | WinXP | 124.241.163.244 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 40 of 43 |
1b88348705 NEW 5eddc8fa8c NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:05:27:00 | WinXP | 111.168.62.80 (MESH.AD.JP): NEC BIGLOBE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | e92ed9f79c NEW |
none[none] | none:none |
none|none | none | none |
T:06:51:00 | WinXP | 151.97.126.255 (-): UNIVERSITA' DI CATANIA, CATANIA, SICILIA, IT. (100Mbps) |
n/a | :citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | b3c849c2f3 NEW |
none[none] | none:none |
none|none | none | none |
T:09:48:00 | WinXP | 184.170.86.151 (-): . |
n/a | RU:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:10:09:00 | WinXP | 220.215.219.69 (CATV02.ITSCOM.JP): ITS COMMUNICATIONS INC, YOKOHAMA, KANAGAWA, JP. (DSL) |
n/a | :citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | 22340630ac NEW |
none[none] | none:none |
none|none | none | none |
T:10:26:00 | WinXP | 178.89.165.88 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 43 | 8697d12974 NEW |
none[none] | none:none |
none|none | none | none |
T:11:53:00 | WinXP | 87.110.81.111 (-): ADDRESS POOL FOR LTC-HOME CUSTOMERS, RIGA, RIGA, LV. (DSL) |
213.155.14.161:80 | :citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | 67db574df4 NEW |
none[none] | none:none |
none|none | none | none |
T:11:59:00 | WinXP | 65.113.116.37 (TRANQUILITY.NET): CORAL WIRELESS LLC, HONOLULU, HAWAII, US. (DSL) |
213.155.14.161:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | fcaa926094 NEW |
none[none] | none:none |
none|none | none | none |
T:19:47:00 | WinXP | 118.1.198.62 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:23:12:00 | Win2K-f | 42.241.111.194 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |