Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:26:00 | Win2K-f | 125.167.130.35 (TELKOM.NET.ID): TLKM_D7_BB_SPEEDY_MKS, MANADO, SULAWESI UTARA, ID. (DSL) |
n/a | US:www.microsoft.com | 445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | 28fd14f95d NEW |
none[none] | none:none |
none|none | none | none |
T:01:06:00 | WinXP | 93.102.128.113 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, COIMBRA, COIMBRA, PT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
none | 37322a044d NEW |
none[none] | none:none |
none|none | none | none |
T:02:11:00 | WinXP | 31.40.212.118 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:02:59:00 | WinXP | 31.147.175.229 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:03:46:00 | WinXP | 202.89.70.11 (-): UNILINX MULUND-MUMBAI, MUMBAI, MAHARASHTRA, IN. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 125 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
2957695b16 NEW b209aff64b NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
04:42:00 | Win2K-f | 118.97.32.52 (TELKOM.NET.ID): PT TELEKOMUNIKASI INDONESIA, JAKARTA, JAKARTA RAYA, ID. (100Mbps) |
n/a | :www.maxmind.com :getmyip.co.uk EU:checkip.dyndns.org :www.getmyip.org 174.36.207.186:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:04:42:00 | Win2K-f | 125.167.132.158 (TELKOM.NET.ID): TLKM_D7_BB_SPEEDY_MKS, MANADO, SULAWESI UTARA, ID. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 3 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:04:50:00 | Win2K-f | 118.97.32.52 (TELKOM.NET.ID): PT TELEKOMUNIKASI INDONESIA, JAKARTA, JAKARTA RAYA, ID. (100Mbps) |
n/a | :www.maxmind.com :getmyip.co.uk :www.getmyip.org US:checkip.dyndns.org DE:131.220.6.26:80 174.36.207.186:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:04:51:00 | Win2K-f | 41.72.29.186 (-): . |
n/a | :www.maxmind.com :getmyip.co.uk :www.getmyip.org US:checkip.dyndns.org DE:131.220.6.26:80 174.36.207.186:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:07:53:00 | WinXP | 188.29.64.142 (THREE.CO.UK): HUTCHISON 3G UK LIMITED, UK. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
08:00:00 | WinXP | 188.29.64.142 (THREE.CO.UK): HUTCHISON 3G UK LIMITED, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:10:23:00 | Win2K-f | 67.198.34.96 (GRANDENETWORKS.NET): HOST THE GALAXY, FLOWER MOUND, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:11:37:00 | WinXP | 77.23.190.99 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BAMBERG, BAYERN, DE. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 6ce2f9af19 NEW |
none[none] | none:none |
none|none | none | none |
T:14:04:00 | WinXP | 112.208.116.110 (PLDT.NET): IPG, PH. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
16:42:00 | Win2K-f | 122.225.53.238 (163DATA.COM.CN): CHINANET-ZJ JIAXING NODE NETWORK, BEIJING, BEIJING, CN. (DSL) |
n/a | :www.maxmind.com :getmyip.co.uk EU:checkip.dyndns.org :www.getmyip.org 174.36.207.186:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:19:33:00 | WinXP | 220.215.217.167 (CATV02.ITSCOM.JP): ITS COMMUNICATIONS INC, YOKOHAMA, KANAGAWA, JP. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:22:11:00 | WinXP | 223.19.205.55 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |