Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:03:22:00 | WinXP | 111.88.19.8 (HOSTS-WORLDCALL.NET.PK): WORLDCALL TELECOM LTD, PK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 8a2553433c NEW |
none[none] | none:none |
none|none | none | none |
T:06:01:00 | WinXP | 93.95.187.112 (-): LAN_MM, KIEV, KYYIV, UA. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | 28f2ecc4cd NEW |
none[none] | none:none |
none|none | none | none |
T:06:04:00 | Win2K-f | 14.98.146.71 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:06:08:00 | WinXP | 188.47.246.4 (-): IDEA, PL. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | eeb1c5dbb2 NEW |
none[none] | none:none |
none|none | none | none |
T:08:03:00 | WinXP | 114.176.181.65 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 4fb872b3d8 NEW |
none[none] | none:none |
none|none | none | none |
T:08:48:00 | WinXP | 67.55.129.113 (NETINS.NET): CENTRAL SCOTT TELEPHONE, BLAIR, NEBRASKA, US. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
43 of 43 | 6ffc4847e4 NEW |
none[none] | none:none |
none|none | none | none |
09:03:00 | WinXP | 114.176.181.65 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | 4fb872b3d8 NEW |
none[none] | none:none |
none|none | none | none |
T:09:26:00 | WinXP | 88.210.96.218 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, FARO, FARO, PT. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:13:03:00 | WinXP | 113.211.17.1 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, MY. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 42 | 6d5a2a1d23 NEW |
none[none] | none:none |
none|none | none | none |
T:13:09:00 | WinXP | 114.176.181.65 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 4fb872b3d8 NEW |
none[none] | none:none |
none|none | none | none |
T:19:40:00 | WinXP | 66.248.113.146 (MCLEODUSA.NET): PAETEC COMMUNICATIONS INC, KNOXVILLE, TENNESSEE, US. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
20:54:00 | Win2K-f | 190.5.58.231 (TECHTELNET.NET): AR. (DSL) |
n/a | :www.maxmind.com EU:checkip.dyndns.org :getmyip.co.uk :www.getmyip.org 174.36.207.186:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:21:15:00 | Win2K-f | 27.98.18.176 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 40 of 41 |
6a6aaa5b73 NEW 8bde6dd126 NEW |
63889c9976 [0] 885c68f500[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=42 lines=64 embedded dns |
trace trace |