Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:52:00 | Win2K-f | 182.177.47.227 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 873e46674e NEW |
none[none] | none:none |
none|none | none | none | |
T:03:50:00 | WinXP | 118.87.4.42 (ODWR.J-CNET.JP): ODAWARA CABLETV INTERNET SERVICE, ODAWARA, KANAGAWA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 122 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 36 34 of 36 |
0b951c2832 NEW e4ed4df0f0 NEW |
5fe761661a [0] de471fc380[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:05:29:00 | WinXP | 178.44.145.189 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | c5f9389fb0 NEW |
none[none] | none:none |
none|none | none | none |
T:08:09:00 | WinXP | 106.197.42.116 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:08:31:00 | WinXP | 46.237.44.6 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 9276456bf8 NEW |
none[none] | none:none |
none|none | none | none |
T:10:05:00 | WinXP | 91.65.255.1 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BERLIN, BERLIN, DE. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:12:44:00 | Win2K-f | 175.112.215.89 (-): . |
114.112.255.81:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com :kronokeus.in CN:k.russiamimi.net EU:hardersearch.ru CN:ga.9kusddaily.com CN:ali.9kusddaily.com :na.9kusddaily.com US:www.zzxml.com US:cricits.com 1.1.1.1:88 EU:141.136.27.220:80 US:209.59.194.20:80 50.7.224.146:80 |
135 | pcap | raw alerts ruleset |
irc http 140 lines |
Yeah : 1.8 profile |
none | summary tarball |
none none none none 33 of 42 none none 39 of 42 none |
02834b25c5 NEW 0a4523e2da NEW 2385d955c1 NEW 3454074d58 NEW 69f59a0454 NEW a9b75cb8e3 NEW b04f1cd1fc NEW f4c93e7909 NEW ff5f5bc234 NEW |
none[none] none [none] none [none] none [none] none [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none none|none none|none none|none none|none |
none none none none none none none none none |
none none none none none none none none none |
T:12:53:00 | Win2K-f | 87.17.15.186 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A. TIN EASY LITE, NAPOLI, CAMPANIA, IT. (DSL) |
n/a | US:loanbrokereducation.com US:ib.adnxs.com :a.collective-media.net US:content.pulse360.com US:tacoda.at.atwola.com :x.domdex.com US:view.atdmt.com US:context3.kanoodle.com US:fasionclothesmarket.com US:i.dotzup.com US:216.57.210.200:80 |
445 | pcap | raw alerts ruleset |
http 27 lines |
Argh : 0.3 profile |
none | summary tarball |
none | d531b67d70 NEW |
none[none] | none:none |
none|none | none | none |
T:13:01:00 | Win2K-f | 187.139.10.234 (PROD-INFINITUM.COM.MX): UNINET S.A. DE C.V, MX. (DSL) |
83.133.119.197:65520 | US:masterunblacker.com US:images01.tzimg.com :domdex.com CN:proxim.ircgalaxy.pl :kronokeus.in CN:k.russiamimi.net EU:hardersearch.ru :na.9kusddaily.com CN:ali.9kusddaily.com US:hotissue.biz US:i.dotzup.com 1.1.1.1:88 EU:141.136.27.220:80 US:216.57.210.200:80 50.7.224.146:80 |
445 | pcap | raw alerts ruleset |
http irc 26 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none none none none none none |
02834b25c5 NEW 0a4523e2da NEW 2385d955c1 NEW 3454074d58 NEW a9b75cb8e3 NEW b04f1cd1fc NEW ff5f5bc234 NEW |
none[none] none [none] none [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none none|none none|none |
none none none none none none none |
none none none none none none none |
T:15:27:00 | WinXP | 66.234.217.136 (ASTOUND.NET): ASTOUND BROADBAND, WALNUT CREEK, CALIFORNIA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | bcb3ec60f2 NEW |
none[none] | none:none |
none|none | none | none |
T:15:42:00 | WinXP | 180.217.5.52 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:16:13:00 | Win2K-f | 194.165.180.10 (ESAT.NET): OCEAN FREE INTERNET DIAL UP SERVICE, DUBLIN, DUBLIN, IE. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 39 of 41 |
10759405e0 NEW d08e00dfaf NEW |
292d343248 [0] 854c49d8c4[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
17:41:00 | WinXP | 121.115.150.70 (PLALA.OR.JP): NTT PLALA INC, TOKYO, TOKYO, JP. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | c703634c01 NEW |
none[none] | none:none |
none|none | none | none |
T:23:31:00 | WinXP | 119.154.185.19 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, ISLAMABAD, ISLAMABAD, PK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:23:37:00 | WinXP | 93.102.88.137 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, PORTO, PORTO, PT. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |