Time
|
Victim OS
|
Infection Source
|
C&C Server
|
DNS Lookups & Failed Connects
|
Infection Port
|
Packet Trace
|
Detection Signatures
|
Infection Chatter
|
BotHunter Analysis
|
Behavioral Cluster
|
Forensic Logs
|
Antivirus Labels
|
Packed Malware_Binary
|
Unpacked egg.exe
|
Unpacked egg.asm
|
Packer PEID
|
Data Strings
|
Syscall Trace
|
T:05:49:00
|
WinXP
|
125.230.232.5 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL)
|
n/a
|
DE:citi-bank.ru
|
445
|
pcap
|
raw alerts ruleset
|
http 1 line
|
Yeah : 0.8
profile
|
none
|
summary tarball
|
41 of 42 |
22340630ac NEW
|
none[none]
|
none:none
|
none|none
|
none
|
none
|
T:08:20:00
|
WinXP
|
46.119.233.40 (-): .
|
n/a
|
DE:citi-bank.ru DE:213.155.14.161:80
|
445
|
pcap
|
raw alerts ruleset
|
http 2 lines
|
Yeah : 0.8
profile
|
none
|
summary tarball
|
26 of 28 |
7d99b0e910 NEW
|
none[0]
|
none:none
|
PolyEnE|
|
lines=68
|
trace
|
T:14:09:00
|
WinXP
|
175.118.96.138 (-): .
|
n/a
|
US:microsoft.com
|
135
|
pcap
|
raw alerts ruleset
|
other 110 lines
|
Yeah : 1.3
profile
|
none
|
summary tarball
|
39 of 41 37 of 40 |
5d445c59d8 NEW 8a54950abb NEW
|
892e12db7b [0] f6b9e43917[0]
|
ASM:Graph ASM:Graph
|
tElock| Armadillo|
|
lines=64 embedded dns lines=91
|
trace trace
|
T:15:03:00
|
WinXP
|
66.234.202.21 (ASTOUND.NET): ASTOUND BROADBAND, WALNUT CREEK, CALIFORNIA, US. (DSL)
|
213.155.14.161:80
|
DE:citi-bank.ru
|
445
|
pcap
|
raw alerts ruleset
|
http 2 lines
|
Yeah : 1.3
profile
|
none
|
summary tarball
|
40 of 42 |
bcb3ec60f2 NEW
|
none[none]
|
none:none
|
none|none
|
none
|
none
|
T:15:49:00
|
WinXP
|
37.110.105.27 (-): .
|
n/a
|
DE:citi-bank.ru DE:213.155.14.161:80
|
445
|
pcap
|
raw alerts ruleset
|
http 1 line
|
Yeah : 0.8
profile
|
none
|
summary tarball
|
26 of 28 |
7d99b0e910 NEW
|
none[0]
|
none:none
|
PolyEnE|
|
lines=68
|
trace
|