Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:02:43:00 | WinXP | 37.1.30.26 (-): . |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |
T:02:54:00 | WinXP | 94.248.143.202 (KABELNET.HU): VIDANET CABLE TELEVISION PROVIDER LTD, HU. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 | 412a3c6dfe NEW |
none[none] | none:none |
none|none | none | none |
T:03:06:00 | Win2K-f | 125.58.92.154 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 39 of 41 |
23018e5a28 NEW 41eec40656 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:03:21:00 | WinXP | 106.76.135.77 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | e99261ba46 NEW |
none[none] | none:none |
none|none | none | none |
T:03:47:00 | WinXP | 203.81.115.59 (KBN.NE.JP): KAGAWA T.V BROADCAST NETWORK CO .LTD, TOKYO, TOKYO, JP. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:04:20:00 | WinXP | 77.254.24.78 (INETIA.PL): INTERNETIA, ZAWIERCIE, KATOWICE, PL. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | aad01847fa NEW |
none[none] | none:none |
none|none | none | none |
T:05:33:00 | WinXP | 95.81.211.148 (CHTTS.RU): ROUTE TO VOLGATELECOM CHEBOXARY, RU. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | e99261ba46 NEW |
none[none] | none:none |
none|none | none | none |
T:06:28:00 | Win2K-f | 4.130.134.184 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, RIVERSIDE, CALIFORNIA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 165 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:10:19:00 | WinXP | 84.245.211.103 (LIVAS.LV): CABLE INTERNET HOME USERS BASED ON DOCSIS STANDARD, RIGA, RIGA, LV. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 43 | 123c0e2b72 NEW |
none[none] | none:none |
none|none | none | none |
T:10:59:00 | WinXP | 79.121.71.168 (SUPRAKTV.HU): SUPRA KABELTELEVIZIOS KERESKEDELMI ES SZOLGALTATO KFT, BUDAPEST, BUDAPEST, HU. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | bb460ddce2 NEW |
none[none] | none:none |
none|none | none | none |
T:11:23:00 | WinXP | 182.188.157.75 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
T:11:36:00 | WinXP | 173.81.240.134 (SUDDENLINK.NET): SUDDENLINK COMMUNICATIONS, TYLER, TEXAS, US. (100Mbps) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | b76758d4ca NEW |
none[none] | none:none |
none|none | none | none |
T:11:49:00 | WinXP | 95.75.167.113 (-): TELECOM ITALIA MOBILE, IT. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | c73335028d NEW |
none[none] | none:none |
none|none | none | none |
T:12:05:00 | WinXP | 178.167.243.163 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | 28f2ecc4cd NEW |
none[none] | none:none |
none|none | none | none |
T:12:16:00 | WinXP | 74.194.177.232 (SUDDENLINK.NET): SUDDENLINK COMMUNICATIONS, MOUNTAIN HOME, ARKANSAS, US. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 082572b94b NEW |
none[none] | none:none |
none|none | none | none |
T:13:19:00 | WinXP | 37.114.137.115 (-): . |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 267b33fd90 NEW |
none[none] | none:none |
none|none | none | none |
15:28:00 | Win2K-f | 46.45.137.125 (-): . |
n/a | :www.maxmind.com :www.getmyip.org US:checkip.dyndns.org :getmyip.co.uk DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:17:27:00 | WinXP | 46.117.121.172 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:18:52:00 | WinXP | 208.104.254.87 (COMPORIUM.NET): COMPORIUM COMMUNICATIONS, NEW YORK, NEW YORK, US. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:19:39:00 | WinXP | 39.116.72.4 (-): . |
210.83.84.151:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com DE:soulandmore.com CH:0daymusic.biz :joposdv.pl DE:hardertodetect.ru :ga.9kusddaily.com FR:7atable.be US:www.download.windowsupdate.com :4darabians.nl CN:ali.9kusddaily.com DE:4every1.cc :4evernails.nl 109.237.208.85:443 EU:141.136.27.220:80 CH:80.82.66.123:443 |
135 | pcap | raw alerts ruleset |
irc http 148 lines |
Yeah : 1.8 profile |
none | summary tarball |
none none none none 33 of 42 none none none 39 of 42 none |
02834b25c5 NEW 095d2d9c20 NEW 0a4523e2da NEW 134c94e38c NEW 69f59a0454 NEW 9b3bed8027 NEW a9b75cb8e3 NEW b04f1cd1fc NEW f4c93e7909 NEW ff5f5bc234 NEW |
none[none] none [none] none [none] none [none] none [none] none [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none none|none none|none none|none none|none none|none |
none none none none none none none none none none |
none none none none none none none none none none |
T:20:26:00 | WinXP | 111.220.235.188 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:21:06:00 | Win2K-f | 64.16.46.96 (MTNTEL.NET): INTEGRA TELECOM INC, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 37 of 41 |
c89b154681 NEW d2b40c91a1 NEW |
58d02dbffa [0] fbaa414397[0] |
ASM:Graph ASM:Graph |
StarForce| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
T:22:31:00 | WinXP | 194.165.181.42 (ESAT.NET): OCEAN FREE INTERNET DIAL UP SERVICE, DUBLIN, DUBLIN, IE. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 39 of 41 |
10759405e0 NEW d08e00dfaf NEW |
292d343248 [0] 854c49d8c4[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:23:32:00 | WinXP | 74.194.177.232 (SUDDENLINK.NET): SUDDENLINK COMMUNICATIONS, MOUNTAIN HOME, ARKANSAS, US. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 082572b94b NEW |
none[none] | none:none |
none|none | none | none |
T:23:48:00 | WinXP | 81.198.234.5 (-): ADDRESS POOL FOR LTC-HOME CUSTOMERS, RIGA, RIGA, LV. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | 9d38d43309 NEW |
none[none] | none:none |
none|none | none | none |