Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:28:00 | WinXP | 49.14.140.44 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 43 | bbafbfe1df NEW |
none[none] | none:none |
none|none | none | none | |
T:04:53:00 | Win2K-f | 77.255.124.177 (COM.PL): NETIA, PL. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
other 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:06:50:00 | WinXP | 2.197.128.163 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 8a2553433c NEW |
none[none] | none:none |
none|none | none | none |
T:10:13:00 | WinXP | 72.184.247.22 (RR.COM): ROAD RUNNER HOLDCO LLC, LAND O LAKES, FLORIDA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a0139d7ad8 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:10:50:00 | WinXP | 114.181.177.36 (PLALA.OR.JP): NTT PLALA INC, TOKYO, TOKYO, JP. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | c703634c01 NEW |
none[none] | none:none |
none|none | none | none |
T:12:12:00 | WinXP | 46.104.144.56 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:12:13:00 | WinXP | 119.154.29.30 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, KARACHI, SINDH, PK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 5de871531b NEW |
none[none] | none:none |
none|none | none | none |
T:12:35:00 | WinXP | 201.173.95.187 (INTERCABLE.NET): TELEVISION INTERNACIONAL S.A. DE C.V, MONTERREY, NUEVO LEON, MX. (100Mbps) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 7b3bf4281f NEW |
none[none] | none:none |
none|none | none | none |
T:12:44:00 | Win2K-f | 4.228.30.185 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, LOVELAND, COLORADO, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 330 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:48:00 | WinXP | 4.161.99.102 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, COLUMBUS, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 177 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:53:00 | WinXP | 24.155.215.206 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS CORPUS CHRISTI HUB, CORPUS CHRISTI, TEXAS, US. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:19:48:00 | WinXP | 36.239.96.85 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 42 | 8689eac5d3 NEW |
none[none] | none:none |
none|none | none | none |
T:19:53:00 | WinXP | 113.10.82.207 (-): STARHUB HSDPA SG, SG. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 339afbfda0 NEW |
none[none] | none:none |
none|none | none | none |
20:10:00 | WinXP | 113.10.82.207 (-): STARHUB HSDPA SG, SG. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 339afbfda0 NEW |
none[none] | none:none |
none|none | none | none |
T:21:29:00 | WinXP | 190.203.193.113 (CANTV.NET): CANTV SERVICIOS VENEZUELA, CARACAS, DISTRITO FEDERAL, VE. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 3119ad634e NEW |
none[none] | none:none |
none|none | none | none |
T:23:34:00 | WinXP | 180.215.209.154 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | bcb3ec60f2 NEW |
none[none] | none:none |
none|none | none | none |