Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:57:00 | WinXP | 211.7.246.166 (CATVNET.NE.JP): CATV NETWORK SERVICES(STNET INCORPORATED), JP. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:02:32:00 | Win2K-f | 216.228.95.190 (APID.COM): API DIGITAL COMMUNICATIONS GROUP LLC, HUNTSVILLE, ALABAMA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 32 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | c0db465ed2 NEW |
none[none] | none:none |
none|none | none | none | |
T:02:35:00 | WinXP | 202.142.160.35 (MULTI.NET.PK): MULTINETBROADBAND, LAHORE, PUNJAB, PK. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 123 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
70a78a9c0e NEW f64cd919b7 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:03:13:00 | WinXP | 46.211.114.36 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
T:03:54:00 | WinXP | 212.233.202.32 (OPTISPRINT.NET): OPTISPRINT INTERNET POOLS, BG. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 76d2a5a1ef NEW |
none[none] | none:none |
none|none | none | none |
T:05:39:00 | WinXP | 118.83.174.168 (NKNO.J-CNET.JP): CITY TV NAKANO LIMITED, JP. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:07:52:00 | WinXP | 74.115.72.254 (MTCBROADBAND.NET): MTC BROADBAND INC, US. (DSL) |
n/a | :siliconfireware.ru GB:welcome3.smile.co.uk :wpad GB:195.92.84.198:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:08:29:00 | WinXP | 75.38.94.33 (SBCGLOBAL.NET): DANNY CHON DBA, PLANO, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:09:17:00 | WinXP | 130.180.49.218 (BEA.COM): VARIOUS REGISTRIES, UK. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
20 of 41 | abed6a29a9 NEW |
none[none] | none:none |
none|none | none | none | |
T:11:24:00 | WinXP | 92.86.74.172 (TELELINK-RO.COM): ARTELECOM, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
T:13:15:00 | WinXP | 46.102.170.64 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 | a4140e4032 NEW |
none[none] | none:none |
none|none | none | none |