Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:02:20:00 | WinXP | 109.191.28.211 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:02:37:00 | WinXP | 79.111.82.3 (NETBYNET.RU): CUSTOMERS BROADBAND AGGREGATION, MOSCOW, MOSCOW CITY, RU. (DIAL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
40 of 40 | d6997f4bc2 NEW |
none[none] | none:none |
none|none | none | none |
T:04:15:00 | WinXP | 114.204.232.73 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
114.112.255.81:65520 | DE:proxim.ircgalaxy.pl US:microsoft.com EU:rttyy.com EU:141.136.27.220:80 CN:61.160.221.205:66 |
135 | pcap | raw alerts ruleset |
irc http 140 lines |
Yeah : 1.8 profile |
none | summary tarball |
30 of 33 28 of 33 none |
533d15b5ce NEW 58c343a8d8 NEW ff5f5bc234 NEW |
c67adf46e2 [0] none [0] none [none] |
ASM:Graph none:none none:none |
tElock| Armadillo| none|none |
lines=126 embedded dns lines=91 none |
trace trace none |
T:05:47:00 | WinXP | 2.198.2.148 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 2fb42f775a NEW |
none[none] | none:none |
none|none | none | none |
T:08:58:00 | WinXP | 216.228.170.55 (BENDCABLE.COM): BEND CABLE COMMUNICATIONS LLC, BEND, OREGON, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
T:10:32:00 | WinXP | 37.1.45.206 (-): . |
n/a | :moscow-advokat.ru RU:195.24.71.31:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |
T:12:06:00 | WinXP | 188.29.94.141 (THREE.CO.UK): HUTCHISON 3G UK LIMITED, UK. (DSL) |
n/a | :moscow-advokat.ru RU:195.24.71.31:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |
T:12:36:00 | WinXP | 95.75.149.208 (-): TELECOM ITALIA MOBILE, IT. (DSL) |
n/a | :moscow-advokat.ru RU:195.24.71.31:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 735d25139c NEW |
none[none] | none:none |
none|none | none | none |
T:12:55:00 | Win2K-f | 24.155.25.14 (GRANDENETWORKS.NET): CLEARSOURCE INC, SAN ANTONIO, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:16:54:00 | Win2K-f | 122.151.69.137 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
18:23:00 | WinXP | 66.94.201.82 (FAMVID.COM): FAMILY VIDEO, GLENVIEW NAS, ILLINOIS, US. (DIAL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | 7a3dc969d4 NEW |
none[none] | none:none |
none|none | none | none |
19:33:00 | Win2K-f | 59.181.71.122 (MTNL.NET.IN): MTNL CAT B ISP, NEW DELHI, DELHI, IN. (DSL) |
n/a | :www.maxmind.com :getmyip.co.uk EU:checkip.dyndns.org 174.36.207.186:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |