Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:08:00 | Win2K-f | 130.193.130.105 (TERMBILLING.COM): VARIOUS REGISTRIES, UK. (DSL) |
59.124.27.180:3305 | :cx10man.weedns.com US:fx010413.whyI.org 176.74.176.167:3305 |
135 | pcap | raw alerts ruleset |
shell ftp irc 22 lines |
Yeah : 1.8 profile |
none | summary tarball |
26 of 39 | bf3e95a24e NEW |
9ad25eb0be [0] | none:none |
StarForce| | none | trace |
02:13:00 | Win2K-f | 121.67.7.179 (-): BORANET, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
03:09:00 | Win2K-f | 114.143.8.96 (RDPLGLOBAL.COM): TATA TELESERVICES MAHARASHTRA LTD, IN. (DSL) |
n/a | US:www.ask.com :zdryovvm.net :kgzsl.com :hvopttpvdl.info US:kopznuuu.biz :pirgx.org :ohokyt.net :uapbwa.com :vcmyhvx.info :icxdc.net :uesvfwxdw.net :xnxxtup.org :rbjzgu.net :mxcbocyxrvo.info :qmmnkdstas.net US:rjhrmdump.biz US:fukfsobn.biz :ahzgl.com :ynsawoipfmy.info :amukyf.net :ecdjycmc.info :utjilyzusb.net :idhxcyru.info :clhsdyjoqzu.com :dzrslpxt.net :aakfwcei.com US:heeqdtrr.biz US:ovswlxsf.biz :asaluilff.com US:teycii.biz :jfqttdce.net US:ylbzi.biz US:dxqqdfsqy.biz US:vbyimqay.biz :mcakldj.com :vmnvmqmmii.com :nobeqyyoaa.org :axbgupzzgwn.net :qmpxmzsdypg.org :oiotgr.net :dvqfwj.com :zdxozcsm.org :uagusxag.info :zwnmtgwinz.info :oprqlax.net :ykhcadee.info :rezcoitwheq.org :tyqysgs.com :atslses.org :sjwfjbazkmy.net :bsxjncbg.org :koyslwkc.org :axtxxxfx.info :asjechr.org :jqycctne.com :gcjtndcf.info :omniqaze.com :dzjxkdomjxw.info US:xykfclpe.biz US:axpcfuss.biz :yidpzw.org US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
06:14:00 | Win2K-f | 98.108.241.185 (VERIZON.NET): VERIZON INTERNET SERVICES INC, US. (DSL) |
n/a | US:www.ask.com :sultvtgpwpa.org US:ovswlxsf.biz :zwnmtgwinz.info :uesvfwxdw.net :tsuidjhi.org US:vegonfeyqq.biz US:cmkduxwu.biz :pyjxjnhv.org :qcrcsqs.info :utcayybq.info :rmgwofv.net :emegba.com US:lpoelm.biz :klgslg.net :wuaxnptbg.org US:oltbkayz.biz :ecdjycmc.info :xuwswqu.com :sagupjnkk.net :djsmmx.net US:escxi.biz :vjvswkmdbye.org :jqycctne.com :kgzsl.com :ngxwbpnq.org :amukyf.net :rdiabfr.org :ilgvzdts.org :rndclslhdqj.net :jaunuqzspa.org US:yvogpomg.biz :mecwcybvgj.info :sgmpewqghb.net :prlni.com :qaagps.info :hivgqydq.net :fljosog.info :bzjbhmmnw.info :vlgcxkmqsa.com :phvkflszybv.info :blkmbwc.com :axtxxxfx.info US:plygig.biz :fnawuild.com US:dxqqdfsqy.biz US:vyeuzavbsn.biz :znxxtivmpm.info :pmxysmc.com US:xykfclpe.biz :nzcbcmvqwg.info :pfkhcfxgsm.org :jcqzixfettb.net :asrmmbmd.info :jjsavy.org US:flxxigt.biz US:enehh.biz :uywjcn.net :ulikqiqqc.net US:kdtrtyjq.biz :hvzvv.info US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:06:27:00 | WinXP | 79.121.70.187 (SUPRAKTV.HU): SUPRA KABELTELEVIZIOS KERESKEDELMI ES SZOLGALTATO KFT, BUDAPEST, BUDAPEST, HU. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | bb460ddce2 NEW |
none[none] | none:none |
none|none | none | none |
T:07:51:00 | Win2K-f | 211.5.15.60 (DION.NE.JP): DION (KDDI CORPORATION), TOKYO, TOKYO, JP. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:09:11:00 | WinXP | 199.117.151.126 (TRANQUILITY.NET): CORAL WIRELESS LLC, HONOLULU, HAWAII, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | e92ed9f79c NEW |
none[none] | none:none |
none|none | none | none |
T:09:15:00 | WinXP | 46.162.199.191 (-): . |
213.155.14.161:80 | DE:citi-bank.ru :adult-empire.com |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 | a4140e4032 NEW |
none[none] | none:none |
none|none | none | none |
09:19:00 | Win2K-f | 2.193.219.247 (-): . |
n/a | US:www.ask.com :dvreao.com :vlgcxkmqsa.com :mrgmohvgv.org US:oltbkayz.biz US:hbglprmg.biz :whbvsiynqs.org :tyydzgpw.org :zwnmtgwinz.info :exrdwhkiori.org US:yvogpomg.biz :mrmbsfn.info :hlujchqui.info US:pobin.biz :idufbe.net :zdxozcsm.org :koyslwkc.org :omniqaze.com :eezyqo.info US:bvbffsjx.biz :ohokyt.net :fvojex.info :sfpbcs.info :clvokcrbr.info US:tjbmne.biz US:eveqqlzhmur.biz US:rjhrmdump.biz :ykhcadee.info :cobipgv.net US:yrjpmlm.biz :rndclslhdqj.net US:axpcfuss.biz :oiotgr.net :ebgrxyiucf.org US:tzvgd.biz :lomlbve.com :rbjzgu.net :fjqnysooka.com :joyqellkazw.info US:lpoelm.biz :jqycctne.com :xzzsauups.net :ointwhclvsy.net :fxnsxnocuat.org :xuwswqu.com :axbgupzzgwn.net :mxbrdeokioh.net :mmzfylxackr.com US:fkqcdfrj.biz :uywjcn.net :kgzsl.com :zdryovvm.net :sultvtgpwpa.org US:gdxfrttz.biz US:vbyimqay.biz :dvqfwj.com :jxulropzrf.info :dykxyvi.org :vivhjleu.com :sjwfjbazkmy.net :sqqecs.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:09:22:00 | Win2K-f | 122.121.27.91 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, KAOHSIUNG, T'AI-WAN, TW. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee JP:ufospace.etowns.net KR:theforums.bbsindex.com LT:phonewire.dnip.net GB:phonelogin.dnip.net KR:koopa.dnip.net TW:fx010413.whyI.org :commgr.co.cc TW:g.0x20.biz :telephone.dd.blueline.be :cx10man.weedns.com :gynoman.weedns.com US:microsoft.com FI:194.215.38.135:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:09:53:00 | WinXP | 46.119.232.226 (-): . |
n/a | DE:citi-bank.ru :parex-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:10:22:00 | WinXP | 93.102.62.198 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, PORTO, PORTO, PT. (DSL) |
n/a | DE:moscow-advokat.ru :lulea.se.eu.undernet.org SE:ozbytes.dal.net SE:vancouver.dal.net :flanders.be.eu.undernet.org :gaspode.zanet.org.za CA:jewellerybazaar.net SE:broadway.ny.us.dal.net BR:casaebar.com.br NL:diemen.nl.eu.undernet.org :canossadhule.in :lia.zanet.net :washington.dc.us.undernet.org :cansesiasknefesi.com :los-angeles.ca.us.undernet.org :brussels.be.eu.undernet.org DE:how2gethazanat.ho.funpic.de AT:graz.at.eu.undernet.org :www.evishop.de :chihuahuaupinghome.com IN:dehaspas.com TR:devdijital.com US:sobrenaturalbr.net BR:direitopublico.com.br SE:coins.dal.net :caen.fr.eu.undernet.org SE:qis.md.us.dal.net DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
42 of 42 | d1e8440870 NEW |
none[none] | none:none |
none|none | none | none |
18:16:00 | Win2K-f | 207.71.52.44 (TWTELECOM.NET): TW TELECOM HOLDINGS INC, AUSTIN, TEXAS, US. (DSL) |
n/a | US:www.ask.com US:ogngy.biz :dzttg.org US:tamoanz.biz :mrylxlinjcd.com :unbswjbz.info :lyapc.com :vmvsrx.com :dtozu.info :ajyhjtgzlgx.net :lpqlsqwf.info :udoopfzp.net :uochvk.info :gnkuzhnbw.info :ydshtfbmw.org :dxtwgc.info :stlvokdxz.org :rtqnb.org :blpanpjc.info US:ibxwdjcnoj.biz :pdrjaaxz.net :yefagybuigl.net US:rycdyeh.biz :tlolvkayzo.info :mdbnacq.com :vmijserqzv.net :jyipbfqnzh.org :vmcsiaxc.org :mxsetbs.com :zahlwrfo.org :mlyelg.org :wgwcdbncz.com US:lxykhfxw.biz :aleyjc.com :egghsxh.net US:kwpeqnofa.biz :xmumr.info :xmsivh.info :wgszmrqf.org :ittcnses.info :qsunbuznh.org :kfiaoyoq.org :ubhwyvlblm.net :xobvboaq.com :pmwaj.net :ccezspmdu.com :oqeikh.org :peyygwss.org :ukocqrdtw.com :xmtzgbqdvb.org :zzlozyeod.info :cjrwguo.org :ymxqxfs.net US:uqytu.biz :tutvk.info :ghlusgun.org :uybeu.net :jnudvpsercx.com US:gciwudivpvz.biz US:meoudanz.biz :rbfqbtuz.info US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:29:00 | Win2K-f | 69.40.88.127 (WINDSTREAM.NET): ALLTEL COMMUNICATIONS OF GEORGIA, DALTON, GEORGIA, US. (DSL) |
n/a | :www.maxmind.com :www.getmyip.org US:checkip.dyndns.org :getmyip.co.uk DE:131.220.6.26:80 US:204.152.184.139:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:21:37:00 | Win2K-f | 27.122.111.115 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 145 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
56703b9d17 NEW c55e86f7e9 NEW |
de8764ef05 [0] c790c10ad1[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
23:47:00 | Win2K-f | 82.160.30.104 (-): GLOBAL4U SP. Z O.O, WARSAW, WARSZAWA, PL. (100Mbps) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |