Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:28:00 | WinXP | 190.203.193.1 (CANTV.NET): CANTV SERVICIOS VENEZUELA, CARACAS, DISTRITO FEDERAL, VE. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 3119ad634e NEW |
none[none] | none:none |
none|none | none | none |
T:02:27:00 | WinXP | 106.77.190.60 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | 412a3c6dfe NEW |
none[none] | none:none |
none|none | none | none |
T:03:16:00 | WinXP | 46.40.36.136 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:08:49:00 | WinXP | 70.45.242.182 (METROCAST.NET): SAN JUAN CABLE LLC, SAN JUAN, PUERTO RICO, PR. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 0c38af69f4 NEW |
none[none] | none:none |
none|none | none | none |
T:10:58:00 | WinXP | 66.81.171.6 (O1.COM): O1 DIALUP SERVICES, AUBURN, CALIFORNIA, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 32a0d7d0e0 NEW |
none[0] | none:none |
tElock| | lines=81 embedded dns |
trace | |
T:11:13:00 | Win2K-f | 111.90.87.188 (NKNO.J-CNET.JP): CITY TV NAKANO LIMITED, JP. (DSL) |
n/a | US:microsoft.com EU:146.185.246.92:80 |
135 | pcap | raw alerts ruleset |
other 122 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 36 34 of 36 |
0b951c2832 NEW e4ed4df0f0 NEW |
5fe761661a [0] de471fc380[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
12:16:00 | Win2K-f | 14.140.160.21 (-): . |
n/a | :www.maxmind.com US:checkip.dyndns.org :getmyip.co.uk :www.getmyip.org 174.36.207.186:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:12:37:00 | WinXP | 98.148.18.71 (RR.COM): ROAD RUNNER HOLDCO LLC, VALENCIA, CALIFORNIA, US. (DSL) |
n/a | US:db.arrancar.org US:204.13.162.123:555 |
135 | pcap | raw alerts ruleset |
http 275 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 15dd08ba1d NEW |
none[none] | none:none |
none|none | none | none |
T:12:38:00 | WinXP | 46.117.76.252 (-): . |
n/a | US:204.13.162.123:555 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:13:12:00 | WinXP | 66.94.200.197 (FAMVID.COM): FAMILY VIDEO, GLENVIEW NAS, ILLINOIS, US. (DIAL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | 7a3dc969d4 NEW |
none[none] | none:none |
none|none | none | none |
T:13:43:00 | WinXP | 46.104.137.241 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 | 412a3c6dfe NEW |
none[none] | none:none |
none|none | none | none |
T:13:45:00 | WinXP | 190.208.85.234 (-): TELMEX CHILE S.A HFC, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:16:29:00 | WinXP | 182.9.37.56 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:17:22:00 | WinXP | 87.204.219.134 (COM.PL): NETIA, WARSAW, WARSZAWA, PL. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 43 | bbafbfe1df NEW |
none[none] | none:none |
none|none | none | none |
T:17:29:00 | WinXP | 91.65.252.32 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, NEUMARKT, BAYERN, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace | |
T:19:52:00 | WinXP | 75.84.10.204 (RR.COM): ROAD RUNNER HOLDCO LLC, ANAHEIM, CALIFORNIA, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:23:17:00 | WinXP | 151.31.49.16 (31-151.LIBERO.IT): FREE INTERNET DIAL-UP SERVICES, IT. (DIAL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | fd145cb3ba NEW |
none[none] | none:none |
none|none | none | none |