Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:02:13:00 | Win2K-f | 219.112.180.149 (THN.NE.JP): TOKAI CORPORATION, SHIZUOKA, SHIZUOKA, JP. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 191 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | 89747f56b8 NEW |
bd6821b297 [0] | ASM:Graph |
Armadillo| | lines=91 | trace | |
T:02:33:00 | WinXP | 160.80.101.106 (NET.UNIROMA2.IT): UNIVERSITA' DEGLI STUDI DI ROMA 'TOR VERGATA', ROME, LAZIO, IT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
43 of 43 | c049e988f2 NEW |
none[none] | none:none |
none|none | none | none |
T:02:43:00 | WinXP | 180.217.21.36 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:07:19:00 | WinXP | 219.110.164.148 (CATV02.ITSCOM.JP): ITS COMMUNICATIONS INC, YOKOHAMA, KANAGAWA, JP. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | 22340630ac NEW |
none[none] | none:none |
none|none | none | none |
T:09:00:00 | WinXP | 77.23.155.254 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, MUNICH, BAYERN, DE. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | ffac98b5d9 NEW |
none[none] | none:none |
none|none | none | none |
T:09:52:00 | WinXP | 212.233.202.32 (OPTISPRINT.NET): OPTISPRINT INTERNET POOLS, BG. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 76d2a5a1ef NEW |
none[none] | none:none |
none|none | none | none |
T:10:10:00 | WinXP | 46.197.91.150 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 5c0d35f121 NEW |
none[none] | none:none |
none|none | none | none |
T:10:34:00 | WinXP | 92.49.164.95 (ESOO.RU): ORENBURG BRANCH OFFICE OF OJSC VOLGATELECOM, ORENBURG, ORENBURG, RU. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | ee774ca8f4 NEW |
none[none] | none:none |
none|none | none | none |
T:10:50:00 | WinXP | 106.76.14.124 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | 412a3c6dfe NEW |
none[none] | none:none |
none|none | none | none |
12:24:00 | Win2K-f | 210.7.71.147 (DIRECT.NET.IN): TATA COMMUNICATIONS INTERNET SERVICES LTD, NEW DELHI, DELHI, IN. (DSL) |
n/a | :www.maxmind.com :getmyip.co.uk EU:checkip.dyndns.org :www.getmyip.org DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:12:32:00 | Win2K-f | 210.7.71.147 (DIRECT.NET.IN): TATA COMMUNICATIONS INTERNET SERVICES LTD, NEW DELHI, DELHI, IN. (DSL) |
n/a | :www.maxmind.com :getmyip.co.uk :www.getmyip.org US:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:13:32:00 | WinXP | 61.109.73.139 (-): HANVITINB-INFRA, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | be27c77fb5 NEW |
none[none] | none:none |
none|none | none | none |
17:17:00 | Win2K-f | 190.5.60.127 (TECHTELNET.NET): AR. (DSL) |
n/a | :www.maxmind.com :getmyip.co.uk US:checkip.dyndns.org :www.getmyip.org DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | d60e538e72 NEW |
none[3] | none:none |
UPX| | none | trace |
T:18:15:00 | WinXP | 208.94.177.52 (KARIBCABLE.COM): KARIB CABLE, KINGSTOWN, SAINT GEORGE, VC. (100Mbps) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | 751685117f NEW |
none[none] | none:none |
none|none | none | none |