Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:18:00 | WinXP | 46.119.162.92 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:01:34:00 | Win2K-f | 203.95.48.74 (THN.NE.JP): TOKAI CORPORATION, FUJI, SHIZUOKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 40 of 41 |
71e6f60517 NEW ab4e3226c4 NEW |
1ef1781501 [0] c2d0313e73[0] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=91 none |
trace trace |
T:02:07:00 | WinXP | 49.132.99.208 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 134 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 44 41 of 44 |
99f212a9df NEW 9fa81e360b NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:03:18:00 | WinXP | 125.228.46.47 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 20 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | 60b530c219 NEW |
none[none] | none:none |
none|none | none | none |
T:04:21:00 | Win2K-f | 202.89.70.2 (-): UNILINX MULUND-MUMBAI, MUMBAI, MAHARASHTRA, IN. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 138 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
2957695b16 NEW b209aff64b NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:04:53:00 | WinXP | 84.224.247.206 (PGSM.HU): PANNON GSM TELECOMMUNICATIONS INC, HU. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 712bcf9f8a NEW |
none[none] | none:none |
none|none | none | none |
T:07:30:00 | WinXP | 2.194.237.15 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:08:45:00 | WinXP | 75.108.174.69 (SUDDENLINK.NET): SUDDENLINK COMMUNICATIONS, BECKLEY, WEST VIRGINIA, US. (DSL) |
n/a | US:gg.arrancar.org US:204.13.160.107:555 |
135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | 0afff56a4c NEW |
none[none] | none:none |
none|none | none | none |
T:09:14:00 | WinXP | 1.187.206.230 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 9276456bf8 NEW |
none[none] | none:none |
none|none | none | none |
T:10:39:00 | WinXP | 91.65.253.27 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, NEUMARKT, BAYERN, DE. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:11:22:00 | WinXP | 122.18.135.63 (OCN.NE.JP): OPEN COMPUTER NETWORK, YOKOHAMA, KANAGAWA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:12:08:00 | WinXP | 199.117.150.248 (TRANQUILITY.NET): CORAL WIRELESS LLC, HONOLULU, HAWAII, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | e92ed9f79c NEW |
none[none] | none:none |
none|none | none | none |
T:12:31:00 | WinXP | 37.155.92.161 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | e99261ba46 NEW |
none[none] | none:none |
none|none | none | none |
T:14:58:00 | WinXP | 91.65.253.27 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, NEUMARKT, BAYERN, DE. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:15:19:00 | WinXP | 92.251.209.132 (NETWORK-IE.NET): PROVIDER LOCAL REGISTRY, IE. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
43 of 43 | 24e8de6cb2 NEW |
none[none] | none:none |
none|none | none | none |
T:15:56:00 | WinXP | 94.197.224.33 (THREE.CO.UK): MOBILE BROADBAND SERVICE, MANCHESTER, ENGLAND, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:17:51:00 | WinXP | 75.110.128.6 (SUDDENLINK.NET): SUDDENLINK COMMUNICATIONS, NEW BERN, NORTH CAROLINA, US. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 267b33fd90 NEW |
none[none] | none:none |
none|none | none | none |
T:19:38:00 | WinXP | 74.192.87.62 (SUDDENLINK.NET): SUDDENLINK COMMUNICATIONS, LINDALE, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
27455f0674 NEW 562a25ec95 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:22:12:00 | WinXP | 203.81.119.160 (KBN.NE.JP): KAGAWA T.V BROADCAST NETWORK CO .LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |