Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:03:55:00 | Win2K-f | 211.133.210.196 (THN.NE.JP): TOKAI CORPORATION, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 40 of 41 |
71e6f60517 NEW ab4e3226c4 NEW |
1ef1781501 [0] c2d0313e73[0] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=91 none |
trace trace |
T:07:23:00 | WinXP | 67.248.52.210 (RR.COM): ROAD RUNNER HOLDCO LLC, WEST CHICAGO, ILLINOIS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 43 40 of 43 |
1817d10a0f NEW 6b5627c444 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:07:29:00 | WinXP | 46.119.121.63 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:09:27:00 | WinXP | 67.197.144.77 (COMPORIUM.NET): COMPORIUM COMMUNICATIONS, ROCK HILL, SOUTH CAROLINA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 81140ffade NEW |
none[none] | none:none |
none|none | none | none |
T:10:54:00 | WinXP | 75.110.64.232 (SUDDENLINK.NET): SUDDENLINK COMMUNICATIONS, GREENVILLE, NORTH CAROLINA, US. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 1002 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 41 | 43b8f21924 NEW |
none[3] | none:none |
none|none | none | trace | |
T:11:22:00 | WinXP | 217.203.207.167 (-): TELECOM ITALIA MOBILE, ROME, LAZIO, IT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
11:41:00 | WinXP | 217.203.207.167 (-): TELECOM ITALIA MOBILE, ROME, LAZIO, IT. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:13:22:00 | WinXP | 212.225.237.40 (-): PROCONO-AS, CóRDOBA, ANDALUCIA, ES. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | fe4bbd07ca NEW |
none[none] | none:none |
none|none | none | none |
T:17:27:00 | WinXP | 68.150.173.120 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SPRUCE GROVE, ALBERTA, CA. (DSL) |
210.83.84.151:65520 | CN:proxim.ircgalaxy.pl DE:soulandmore.com :joposdv.pl NL:hardertolocate.ru :ga.9kusddaily.com CN:ali.9kusddaily.com US:www.zzxml.com :www.lddwj.com :wpad :www.zkaoo.com US:sockslot.com US:i.dotzup.com EU:141.136.27.220:80 US:216.57.210.200:80 |
139 | pcap | raw alerts ruleset |
irc http 45 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none none none none none none none |
02834b25c5 NEW 0a4523e2da NEW a9b75cb8e3 NEW b04f1cd1fc NEW b6e98042fd NEW bd14ff9a0e NEW bee8517e77 NEW ff5f5bc234 NEW |
none[none] none [none] none [none] none [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none none|none none|none none|none |
none none none none none none none none |
none none none none none none none none |
T:19:46:00 | WinXP | 65.113.116.196 (TRANQUILITY.NET): CORAL WIRELESS LLC, HONOLULU, HAWAII, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | e92ed9f79c NEW |
none[none] | none:none |
none|none | none | none |
T:22:54:00 | WinXP | 201.173.95.187 (INTERCABLE.NET): TELEVISION INTERNACIONAL S.A. DE C.V, MONTERREY, NUEVO LEON, MX. (100Mbps) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 29af3321de NEW |
none[none] | none:none |
none|none | none | none |