Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:20:00 | Win2K-f | 218.45.124.32 (CABLENET.NE.JP): CABLENET SAITAMA CO. LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 41 |
5bbb57c115 NEW 75ac189d9e NEW |
03e5cb3c4a [0] 705dbaa801[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:00:22:00 | WinXP | 166.164.124.22 (MYVZW.COM): SERVICE PROVIDER CORPORATION, WEST MONROE, LOUISIANA, US. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 29af3321de NEW |
none[none] | none:none |
none|none | none | none |
T:00:33:00 | WinXP | 101.111.159.192 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:04:08:00 | WinXP | 118.83.25.113 (HTOJ.J-CNET.JP): JCN-HTMNET, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 123 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 43 37 of 42 |
3f22951423 NEW b0b073d141 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:05:10:00 | WinXP | 181.0.21.32 (-): . |
n/a | DE:ilo.brenz.pl DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | 659c5d1d1f NEW |
none[none] | none:none |
none|none | none | none |
T:05:59:00 | WinXP | 87.8.155.50 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A. TIN EASY LITE, BERGAMO, LOMBARDIA, IT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 33919ce836 NEW |
none[none] | none:none |
none|none | none | none |
06:19:00 | WinXP | 87.8.155.50 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A. TIN EASY LITE, BERGAMO, LOMBARDIA, IT. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | f4325a5e1e NEW |
none[none] | none:none |
none|none | none | none |
T:06:24:00 | WinXP | 173.81.78.148 (SUDDENLINK.NET): SUDDENLINK COMMUNICATIONS, TYLER, TEXAS, US. (100Mbps) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:06:49:00 | WinXP | 94.139.0.84 (BLUE-CABLE.DE): CABLE-TV BROADBAND NETWORK, BERLIN, BERLIN, DE. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 38f513105a NEW |
none[none] | none:none |
none|none | none | none |
T:08:35:00 | WinXP | 173.81.115.79 (SUDDENLINK.NET): SUDDENLINK COMMUNICATIONS, TYLER, TEXAS, US. (100Mbps) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 270fa009a3 NEW |
none[none] | none:none |
none|none | none | none |
T:11:30:00 | WinXP | 72.48.210.249 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS AUSTIN HUB, AUSTIN, TEXAS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | d031b42d3f NEW |
none[none] | none:none |
none|none | none | none | |
T:11:37:00 | WinXP | 68.185.98.4 (CHARTER.COM): CHARTER COMMUNICATIONS, BARRE, VERMONT, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 42 40 of 42 |
26fa50f7e1 NEW 28682ab74c NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:11:52:00 | WinXP | 74.192.249.103 (SUDDENLINK.NET): SUDDENLINK COMMUNICATIONS, TYLER, TEXAS, US. (100Mbps) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 | bcb3ec60f2 NEW |
none[none] | none:none |
none|none | none | none |
14:04:00 | Win2K-f | 186.34.36.173 (-): . |
n/a | :www.maxmind.com :www.getmyip.org :getmyip.co.uk US:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 08f384b76a NEW |
none[3] | none:none |
MEW| | none | trace |
T:15:00:00 | WinXP | 12.74.35.144 (ATT.NET): AT&T WORLDNET SERVICES, INDIANAPOLIS, INDIANA, US. (DIAL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | d6df3972a0 NEW |
none[0] | none:none |
PolyEnE| | lines=65 | trace |
T:16:21:00 | WinXP | 50.9.236.217 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | 22340630ac NEW |
none[none] | none:none |
none|none | none | none |
T:17:01:00 | WinXP | 27.98.6.82 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 40 of 41 |
6a6aaa5b73 NEW 8bde6dd126 NEW |
63889c9976 [0] 885c68f500[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=42 lines=64 embedded dns |
trace trace |
T:18:12:00 | WinXP | 88.156.22.206 (VECTRANET.PL): VECTRA S.A, OLSZTYN, WARMINSKO-MAZURSKIE, PL. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 5db1eb6a36 NEW |
none[none] | none:none |
none|none | none | none |
T:19:40:00 | WinXP | 74.193.212.66 (SUDDENLINK.NET): SUDDENLINK COMMUNICATIONS, SULPHUR, LOUISIANA, US. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 61 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | 73f1082158 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:20:21:00 | WinXP | 111.252.24.76 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:23:39:00 | WinXP | 117.99.40.219 (-): GPRS-SUBSCRIBERS-IN-EAST, BHUBANESHWAR, ORISSA, IN. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:23:53:00 | WinXP | 101.111.157.126 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |