Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:19:00 | WinXP | 92.36.30.150 (SKYLINK.RU): MOSCOW CELLULAR COMMUNICATIONS, RU. (DSL) |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 267b33fd90 NEW |
none[none] | none:none |
none|none | none | none |
T:04:30:00 | WinXP | 212.182.19.8 (POLLUB.PL): TECHNICAL UNIVERSITY LUBLIN POLAND, LUBLIN, LUBELSKIE, PL. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 54077666f8 NEW |
none[none] | none:none |
none|none | none | none |
T:05:34:00 | WinXP | 41.96.95.230 (196-46-248-WIMAX.SLC.DZ): AFRINIC, DZ. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | b3ed00d0db NEW |
none[none] | none:none |
none|none | none | none |
T:05:49:00 | WinXP | 212.225.234.193 (-): ATALAYA TELEVISION S.L, ES. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 | fe4bbd07ca NEW |
none[none] | none:none |
none|none | none | none |
T:07:23:00 | WinXP | 101.111.196.63 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:11:54:00 | Win2K-f | 74.195.187.234 (SUDDENLINK.NET): SUDDENLINK COMMUNICATIONS, MUSKOGEE, OKLAHOMA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1002 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 41 | 43b8f21924 NEW |
none[3] | none:none |
none|none | none | trace | |
T:12:28:00 | WinXP | 111.90.87.188 (NKNO.J-CNET.JP): CITY TV NAKANO LIMITED, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 122 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 36 34 of 36 |
0b951c2832 NEW e4ed4df0f0 NEW |
5fe761661a [0] de471fc380[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:13:02:00 | WinXP | 46.118.125.228 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:13:14:00 | WinXP | 93.95.187.112 (-): LAN_MM, KIEV, KYYIV, UA. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 43 | 28f2ecc4cd NEW |
none[none] | none:none |
none|none | none | none |
T:15:47:00 | WinXP | 37.110.99.245 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:16:14:00 | WinXP | 211.7.244.190 (CATVNET.NE.JP): CATV NETWORK SERVICES(STNET INCORPORATED), JP. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:16:47:00 | WinXP | 75.110.148.114 (SUDDENLINK.NET): SUDDENLINK COMMUNICATIONS, NEW BERN, NORTH CAROLINA, US. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 8a226c3a84 NEW |
none[none] | none:none |
none|none | none | none |
T:18:10:00 | WinXP | 75.110.54.226 (SUDDENLINK.NET): SUDDENLINK COMMUNICATIONS, GREENVILLE, NORTH CAROLINA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
562a25ec95 NEW ecf2da2654 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
18:33:00 | Win2K-f | 61.12.24.213 (DIRECT.NET.IN): TATA COMMUNICATIONS INTERNET SERVICES LTD, NEW DELHI, DELHI, IN. (DSL) |
n/a | :www.maxmind.com EU:checkip.dyndns.org :www.getmyip.org :getmyip.co.uk 174.36.207.186:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:19:27:00 | WinXP | 75.79.188.6 (DSLEXTREME.COM): DSL EXTREME, CHATSWORTH, CALIFORNIA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:19:33:00 | Win2K-f | 110.93.111.59 (CABLENET.NE.JP): CABLENET SAITAMA CO. LTD, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 41 |
5bbb57c115 NEW 75ac189d9e NEW |
03e5cb3c4a [0] 705dbaa801[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:19:35:00 | WinXP | 202.137.186.94 (CCNET-AI.NE.JP): COMMUNITY NETWORK CENTER INC, TOYOKAWA, AICHI, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 88 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 none |
53bfe15e91 NEW c5f5a81c60 NEW |
1473091351 [0] none [none] |
ASM:Graph none:none |
tElock| none|none |
lines=75 embedded dns none |
trace none |
21:00:00 | Win2K-f | 117.102.95.139 (-): BIZNET-METRONET-BLOCK, JAKARTA, JAKARTA RAYA, ID. (DSL) |
n/a | :www.maxmind.com US:checkip.dyndns.org :www.getmyip.org :getmyip.co.uk 174.36.207.186:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |