Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:03:01:00 | Win2K-f | 39.121.179.21 (-): . |
114.112.255.81:65520 | US:microsoft.com DE:proxim.ircgalaxy.pl US:baliroomz.com :bestpspgame.com :yerty90.com EU:141.136.27.220:80 |
135 | pcap | raw alerts ruleset |
irc http 129 lines |
Yeah : 1.8 profile |
none | summary tarball |
none 33 of 42 39 of 42 none |
0ed0348cd2 NEW 69f59a0454 NEW f4c93e7909 NEW ff5f5bc234 NEW |
none[none] none [none] none [none] none [none] |
none:none none:none none:none none:none |
none|none none|none none|none none|none |
none none none none |
none none none none |
T:06:17:00 | WinXP | 216.51.249.156 (NETINS.NET): COMMUNICATIONS 1 NETWORK INC, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:07:41:00 | WinXP | 46.119.247.168 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | 22340630ac NEW |
none[none] | none:none |
none|none | none | none |
T:09:48:00 | WinXP | 178.90.19.240 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | a2579804fc NEW |
none[none] | none:none |
none|none | none | none |
T:09:57:00 | WinXP | 46.50.37.111 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:10:59:00 | WinXP | 79.111.92.97 (NETBYNET.RU): CUSTOMERS BROADBAND AGGREGATION, MOSCOW, MOSCOW CITY, RU. (DIAL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 9276456bf8 NEW |
none[none] | none:none |
none|none | none | none |
T:12:43:00 | WinXP | 67.197.78.111 (COMPORIUM.NET): ROCK HILL TELEPHONE COMPANY, LANCASTER, SOUTH CAROLINA, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 81140ffade NEW |
none[none] | none:none |
none|none | none | none |
T:18:38:00 | Win2K-f | 173.31.96.183 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, MIDDLETOWN, NEW YORK, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | 0afff56a4c NEW |
none[none] | none:none |
none|none | none | none | |
T:19:38:00 | WinXP | 41.96.1.17 (196-46-248-WIMAX.SLC.DZ): AFRINIC, ALGIERS, ALGER, DZ. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 43 | b3ed00d0db NEW |
none[none] | none:none |
none|none | none | none |