Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:02:07:00 | WinXP | 109.102.188.121 (JWS.COM): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 5efa033137 NEW |
none[none] | none:none |
none|none | none | none |
02:43:00 | Win2K-f | 122.224.125.162 (-): STANDARD CHARTERED BANK(CHINA) LTD.HANGZHOU BRANCH, HANGZHOU, ZHEJIANG, CN. (100Mbps) |
n/a | :www.maxmind.com :www.getmyip.org :getmyip.co.uk US:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:04:12:00 | WinXP | 114.39.241.79 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 42 | 8689eac5d3 NEW |
none[none] | none:none |
none|none | none | none |
05:24:00 | Win2K-f | 202.142.161.170 (MULTI.NET.PK): MULTINETBROADBAND, LAHORE, PUNJAB, PK. (DSL) |
n/a | :www.maxmind.com US:checkip.dyndns.org :getmyip.co.uk :www.getmyip.org 174.36.207.186:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:06:42:00 | WinXP | 118.87.223.22 (HTOJ.J-CNET.JP): JCN-HTMNET, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 95 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 2 of 32 |
607b60ad51 NEW e5c7bce70e NEW |
none[4] e5c7bce70e[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:07:58:00 | WinXP | 50.75.113.134 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
T:10:57:00 | WinXP | 49.14.105.114 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:12:09:00 | WinXP | 113.211.37.9 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, MY. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 42 | 6d5a2a1d23 NEW |
none[none] | none:none |
none|none | none | none |
12:26:00 | WinXP | 113.211.37.9 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, MY. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 42 | 6d5a2a1d23 NEW |
none[none] | none:none |
none|none | none | none |
T:12:52:00 | WinXP | 112.110.4.163 (-): GPRS VAS SERVICES, DELHI, DELHI, IN. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 43 | 2044b2416f NEW |
none[none] | none:none |
none|none | none | none |
T:13:05:00 | WinXP | 31.63.158.157 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 9ebcc2e373 NEW |
none[none] | none:none |
none|none | none | none |
T:13:47:00 | WinXP | 94.52.71.104 (-): NEW COM TELECOMUNICATII SA, BUCHAREST, BUCURESTI, RO. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:15:16:00 | WinXP | 75.79.188.245 (DSLEXTREME.COM): DSL EXTREME, CHATSWORTH, CALIFORNIA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:16:35:00 | WinXP | 208.100.183.2 (BENDCABLE.COM): BEND CABLE COMMUNICATIONS LLC, BEND, OREGON, US. (100Mbps) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
T:18:28:00 | WinXP | 74.195.187.234 (SUDDENLINK.NET): SUDDENLINK COMMUNICATIONS, MUSKOGEE, OKLAHOMA, US. (DSL) |
n/a | US:gg.arrancar.org US:204.13.162.123:555 |
135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | 0afff56a4c NEW |
none[none] | none:none |
none|none | none | none |
T:22:48:00 | WinXP | 84.224.194.11 (PGSM.HU): PANNON GSM TELECOMMUNICATIONS INC, BUDAPEST, BUDAPEST, HU. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 735d25139c NEW |
none[none] | none:none |
none|none | none | none |
T:22:49:00 | Win2K-f | 122.146.227.136 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |