Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:13:00 | WinXP | 207.191.211.105 (MCLEODUSA.NET): MCLEODUSA INCORPORATED, CEDAR RAPIDS, IOWA, US. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |
T:01:24:00 | WinXP | 178.44.205.8 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | ee774ca8f4 NEW |
none[none] | none:none |
none|none | none | none |
T:03:00:00 | WinXP | 178.17.124.169 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:03:03:00 | WinXP | 116.0.159.214 (CATV-YOKOHAMA.NE.JP): YOKOHAMA CABLEVISION INC, YOKOHAMA, KANAGAWA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:05:33:00 | WinXP | 221.127.247.252 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:06:04:00 | WinXP | 24.112.204.5 (ZOOMINTERNET.NET): ARMSTRONG CABLE SERVICES, BUTLER, PENNSYLVANIA, US. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:06:22:00 | WinXP | 94.248.157.238 (KABELNET.HU): VIDANET CABLE TELEVISION PROVIDER LTD, HU. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | 412a3c6dfe NEW |
none[none] | none:none |
none|none | none | none |
T:09:28:00 | WinXP | 31.22.173.48 (-): . |
n/a | **:169.254.212.48:1712 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:09:30:00 | WinXP | 188.173.222.221 (RIPE.NET): EUROPEAN REGIONAL REGISTRY, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 44 | dd0a92984c NEW |
none[none] | none:none |
none|none | none | none |
T:10:05:00 | WinXP | 72.0.173.121 (BENDBROADBAND.COM): BEND CABLE COMMUNICATIONS LLC, BEND, OREGON, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
T:10:11:00 | WinXP | 70.184.157.221 (COX.NET): COX COMMUNICATIONS, OKLAHOMA CITY, OKLAHOMA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 100 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:44:00 | WinXP | 46.202.95.243 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:13:02:00 | WinXP | 109.161.60.1 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 44 | dd0a92984c NEW |
none[none] | none:none |
none|none | none | none |
T:13:44:00 | Win2K-f | 24.139.153.177 (-): LIBERTY CABLEVISION - HUMACAO, HUMACAO, PUERTO RICO, PR. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:50:00 | WinXP | 181.10.98.78 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace | |
T:14:28:00 | WinXP | 212.225.200.238 (PTVTELECOM.COM): ES-PROCONO-AS, CóRDOBA, ANDALUCIA, ES. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 | fe4bbd07ca NEW |
none[none] | none:none |
none|none | none | none |
T:14:43:00 | WinXP | 37.110.111.103 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:15:00:00 | WinXP | 98.151.190.5 (RR.COM): ROAD RUNNER HOLDCO LLC, CHATSWORTH, CALIFORNIA, US. (DSL) |
n/a | DE:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 32a0d7d0e0 NEW |
none[0] | none:none |
tElock| | lines=81 embedded dns |
trace |
15:19:00 | WinXP | 98.151.190.5 (RR.COM): ROAD RUNNER HOLDCO LLC, CHATSWORTH, CALIFORNIA, US. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 32a0d7d0e0 NEW |
none[0] | none:none |
tElock| | lines=81 embedded dns |
trace |
T:17:09:00 | Win2K-f | 68.114.82.49 (CHARTER.COM): CHARTER COMMUNICATIONS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:53:00 | WinXP | 206.74.17.107 (INFOAVE.NET): SPIRIT TELECOM, ROCK HILL, SOUTH CAROLINA, US. (100Mbps) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:23:42:00 | Win2K-f | 14.98.94.165 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 55 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | c6ad8229ff NEW |
none[none] | none:none |
none|none | none | none |