Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:44:00 | WinXP | 92.41.212.14 (THREE.CO.UK): MOBILE BROADBAND SERVICE, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 5231b63b24 NEW |
none[none] | none:none |
none|none | none | none |
T:01:58:00 | WinXP | 114.25.42.148 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 52b50b6101 NEW |
none[none] | none:none |
none|none | none | none |
T:02:34:00 | WinXP | 223.19.254.136 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
03:26:00 | WinXP | 175.157.129.197 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 618eb5ba49 NEW |
none[none] | none:none |
none|none | none | none |
T:04:44:00 | WinXP | 4.248.73.214 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, BELLEVILLE, NEW JERSEY, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:05:42:00 | WinXP | 31.16.200.109 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 | e99261ba46 NEW |
none[none] | none:none |
none|none | none | none |
T:06:35:00 | WinXP | 114.207.85.62 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
210.83.80.160:65520 | :proxim.ircgalaxy.pl US:microsoft.com EU:ioio89.com CN:ga.9kusddaily.com CN:na.9kusddaily.com US:www.aaxml.com US:preownedcatamarans.com :www.google-analytics.com US:images01.tzimg.com :domdex.com EU:141.136.27.220:80 US:209.59.194.240:80 |
135 | pcap | raw alerts ruleset |
irc http 144 lines |
Yeah : 1.8 profile |
none | summary tarball |
none none 30 of 33 28 of 33 none none none none none |
30eeff8af6 NEW 3454074d58 NEW 533d15b5ce NEW 58c343a8d8 NEW a3ea0a87e0 NEW b04f1cd1fc NEW bbca496502 NEW c8b356d525 NEW ff5f5bc234 NEW |
none[none] none [none] c67adf46e2[0] none [0] none [none] none [none] none [none] none [none] none [none] |
none:none none:none ASM:Graph none:none none:none none:none none:none none:none none:none |
none|none none|none tElock| Armadillo| none|none none|none none|none none|none none|none |
none none lines=126 embedded dns lines=91 none none none none none |
none none trace trace none none none none none |
T:07:07:00 | WinXP | 2.192.237.63 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:07:22:00 | WinXP | 114.40.100.53 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
T:10:36:00 | WinXP | 190.209.44.222 (-): TELMEX CHILE S.A HFC, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:12:12:00 | WinXP | 37.252.70.44 (-): . |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |
14:47:00 | WinXP | 128.173.180.3 (VT.EDU): VIRGINIA POLYTECHNIC INSTITUTE AND STATE UNIV, BLACKSBURG, VIRGINIA, US. (100Mbps) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | e99261ba46 NEW |
none[none] | none:none |
none|none | none | none |
T:16:45:00 | WinXP | 75.110.109.74 (SUDDENLINK.NET): SUDDENLINK COMMUNICATIONS, ROCKY MOUNT, NORTH CAROLINA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:17:44:00 | WinXP | 100.42.148.108 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 | ff90c1ff00 NEW |
none[none] | none:none |
none|none | none | none |
T:20:14:00 | WinXP | 173.31.231.97 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, MIDDLETOWN, NEW YORK, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:20:27:00 | WinXP | 126.164.10.92 (BBTEC.NET): JAPAN NATION-WIDE NETWORK OF SOFTBANK BB CORP, TOKYO, TOKYO, JP. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru DK:bem.dk :banboon.com MY:bdb.com.my |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 43 | b3ed00d0db NEW |
none[none] | none:none |
none|none | none | none |
20:49:00 | WinXP | 126.164.10.92 (BBTEC.NET): JAPAN NATION-WIDE NETWORK OF SOFTBANK BB CORP, TOKYO, TOKYO, JP. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | b3ed00d0db NEW |
none[none] | none:none |
none|none | none | none |
T:23:17:00 | Win2K-f | 98.134.227.226 (WINDSTREAM.NET): ALLTEL MIP CUSTOMERS - LITTLE ROCK, WEST MONROE, LOUISIANA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 40 |
9bdd2c95b1 NEW cd456ac095 NEW |
d1bbd693ba [0] d75caee680[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |