Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:11:00 | WinXP | 94.50.179.230 (PERMONLINE.RU): DYNAMIC DISTRIBUTION IP'S FOR BROADBAND SERVICES, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | 488d27fe97 NEW |
none[none] | none:none |
none|none | none | none |
T:01:42:00 | WinXP | 96.15.181.199 (-): ALLTEL SIP CUSTOMERS - LITTLE ROCK, HOT SPRINGS NATIONAL PARK, ARKANSAS, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | c6f2bacc00 NEW |
none[none] | none:none |
none|none | none | none |
T:01:48:00 | WinXP | 122.146.241.185 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:25:00 | WinXP | 106.199.86.212 (-): . |
n/a | :siliconfireware.ru RU:www.bbin.ru RU:www.binbank.ru :wpad |
445 | pcap | raw alerts ruleset |
http http 22 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:03:16:00 | WinXP | 2.193.201.205 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:03:22:00 | Win2K-f | 101.111.206.43 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:04:18:00 | WinXP | 31.42.162.69 (-): . |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 43 | 283970c2d1 NEW |
none[none] | none:none |
none|none | none | none |
T:06:32:00 | Win2K-f | 122.146.227.227 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:08:10:00 | Win2K-f | 14.98.109.131 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 91 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:08:25:00 | WinXP | 91.67.213.223 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, LEIPZIG, SACHSEN, DE. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | b429369c96 NEW |
none[none] | none:none |
none|none | none | none |
T:09:10:00 | WinXP | 87.8.155.152 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A. TIN EASY LITE, BERGAMO, LOMBARDIA, IT. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 42 | d1e8440870 NEW |
none[none] | none:none |
none|none | none | none |
T:12:54:00 | WinXP | 37.252.69.37 (-): . |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |
13:22:00 | WinXP | 93.102.143.180 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, PT. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 42 | aad3f711c8 NEW |
none[none] | none:none |
none|none | none | none |
13:48:00 | WinXP | 37.252.69.37 (-): . |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |
14:44:00 | Win2K-f | 77.104.74.41 (-): RESPINA NETWORKS & BEYOND, IR. (100Mbps) |
n/a | :www.maxmind.com :getmyip.co.uk :www.getmyip.org EU:checkip.dyndns.org DE:131.220.6.26:80 EU:91.198.22.70:80 |
139 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:15:27:00 | Win2K-f | 220.216.47.21 (TNC.NE.JP): TOKAI CORPORATION, TOKYO, TOKYO, JP. (DSL) |
83.133.119.197:65520 | :proxim.ircgalaxy.pl US:microsoft.com :kiju745.com CN:tn.ddcxlayer.net |
135 | pcap | raw alerts ruleset |
irc http 249 lines |
Yeah : 1.8 profile |
none | summary tarball |
none 39 of 41 none none none 36 of 40 none |
0a4523e2da NEW 66d44f331b NEW 6c5bcc1b0d NEW 77a2ef6082 NEW 8a52290181 NEW ed7a92b1d0 NEW ff5f5bc234 NEW |
none[none] 10e6736afc[0] none [none] none [none] none [none] 543ebb463c[0] none [none] |
none:none ASM:Graph none:none none:none none:none ASM:Graph none:none |
none|none Armadillo| none|none none|none none|none tElock| none|none |
none lines=91 none none none lines=126 embedded dns none |
none trace none none none trace none |
T:16:49:00 | WinXP | 72.191.148.60 (RR.COM): ROAD RUNNER HOLDCO LLC, HARLINGEN, TEXAS, US. (100Mbps) |
n/a | :siliconfireware.ru RU:ebookfinaltrash.ru :wpad |
445 | pcap | raw alerts ruleset |
http http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:18:58:00 | Win2K-f | 211.133.213.167 (THN.NE.JP): TOKAI CORPORATION, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 40 of 41 |
71e6f60517 NEW ab4e3226c4 NEW |
1ef1781501 [0] c2d0313e73[0] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=91 none |
trace trace |
T:20:06:00 | WinXP | 184.0.13.192 (EMBARQHSD.NET): EMBARQ CORPORATION, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:21:05:00 | WinXP | 123.192.18.40 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | 80159a51c5 NEW |
none[none] | none:none |
none|none | none | none |
T:22:09:00 | WinXP | 216.228.169.33 (BENDCABLE.COM): BEND CABLE COMMUNICATIONS LLC, BEND, OREGON, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
T:23:28:00 | WinXP | 68.114.80.208 (CHARTER.COM): CHARTER COMMUNICATIONS, CHICOPEE, MASSACHUSETTS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |