Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:04:48:00 | WinXP | 86.56.67.12 (BLUE-CABLE.DE): TELECOLUMBUS KUNDENSERVICE GMBH, BERLIN, BERLIN, DE. (DSL) |
n/a | :moscow-advokat.ru 50.19.104.123:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 75a57521b7 NEW |
none[none] | none:none |
none|none | none | none |
T:08:19:00 | WinXP | 199.117.151.167 (TRANQUILITY.NET): CORAL WIRELESS LLC, HONOLULU, HAWAII, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | e92ed9f79c NEW |
none[none] | none:none |
none|none | none | none |
11:30:00 | Win2K-f | 210.212.242.69 (-): COMMISSIONER TIRUNELVELI MUNICIPAL CORPORATION, TIRUNELVELI, TAMIL NADU, IN. (100Mbps) |
n/a | :www.maxmind.com :getmyip.co.uk EU:checkip.dyndns.org 174.36.207.186:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:12:50:00 | WinXP | 173.80.220.158 (SUDDENLINK.NET): SUDDENLINK COMMUNICATIONS, TYLER, TEXAS, US. (100Mbps) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | 751685117f NEW |
none[none] | none:none |
none|none | none | none |
T:13:27:00 | WinXP | 216.119.0.66 (DARIENTEL.NET): THE DARIEN TELEPHONE CO. INC, TOWNSEND, MASSACHUSETTS, US. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | be27c77fb5 NEW |
none[none] | none:none |
none|none | none | none |
T:17:11:00 | Win2K-f | 74.195.187.234 (SUDDENLINK.NET): SUDDENLINK COMMUNICATIONS, MUSKOGEE, OKLAHOMA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 187 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | 0afff56a4c NEW |
none[none] | none:none |
none|none | none | none | |
T:17:17:00 | WinXP | 72.15.111.98 (NEWNANUTILITIES.ORG): NEWNAN UTILITIES, NEWNAN, GEORGIA, US. (100Mbps) |
n/a | :moscow-advokat.ru 50.19.104.123:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 267b33fd90 NEW |
none[none] | none:none |
none|none | none | none |
T:22:14:00 | WinXP | 95.59.42.42 (DIAL.ONLINE.KZ): JSC KAZAKHTELECOM AKMOLA AFFILIATE, ALMATY, ALMATY CITY, KZ. (DSL) |
n/a | DE:moscow-advokat.ru 50.19.104.123:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |