Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:02:25:00 | WinXP | 119.157.184.27 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, ISLAMABAD, ISLAMABAD, PK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | d11b1f56f9 NEW |
none[none] | none:none |
none|none | none | none |
02:35:00 | Win2K-f | 187.50.189.16 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | :www.yahoo.com US:trafficconverter.biz :sooupnvp.org :jzutkbdqudu.net :xxrcvootihu.net :dtozu.info :vvhlbiwq.org :ldovk.info :wiysnviy.net :hhxhnxpeneu.net :rnfklgdm.net :ajyhjtgzlgx.net :wgwcdbncz.com US:wavecm.biz :pygsvnth.info :mcdpdthr.net :bwzfk.com :gfwrzmubhut.com US:zmxwxthbnr.biz US:tuxzrfanqnp.biz :rjeqcjc.org US:uqytu.biz US:aiofd.biz :ittcnses.info US:hgmpczmk.biz :mnoeyq.org US:pgekbahc.biz :lrpdwnod.com :dloeeptgy.org :kofcgyyojyq.net :vofdbtlwgjq.net :vuvtdit.org US:brmka.biz US:xgtxwgg.biz :dxtwgc.info :lidhqjg.com :jwhhhaxutrk.info US:yvehhbje.biz :kmvwouxm.org :yqbpjpth.com :dlorieeh.com US:ardvkwikp.biz :ccezspmdu.com :mrylxlinjcd.com :eglst.com :wzjqpk.org :oqeikh.org :bsqladtlq.info :krdptuqs.org :hctuirwmabl.com :ukocqrdtw.com :jngnrpdaf.com :cnzyfme.com :dwlufrmo.info US:clzfkhmcnfs.biz US:geuggdrnhr.biz :tcjmixhb.org :cjrwguo.org :gnkuzhnbw.info :eihoa.info :ngcirsko.info US:wjingfmlyva.biz US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:03:01:00 | WinXP | 46.162.196.61 (-): . |
n/a | DE:moscow-advokat.ru NL:diemen.nl.eu.undernet.org SE:coins.dal.net AT:graz.at.eu.undernet.org SE:ced.dal.net NL:broekhuisjuweliers.nl :lia.zanet.net NL:london.uk.eu.undernet.org TH:btech.ac.th :washington.dc.us.undernet.org :los-angeles.ca.us.undernet.org :flanders.be.eu.undernet.org SE:vancouver.dal.net TR:btr.gen.tr :caen.fr.eu.undernet.org SE:qis.md.us.dal.net TR:burakasansor.com ES:bytegraf.com :lulea.se.eu.undernet.org SE:brussels.be.eu.undernet.org TH:nt.go.th :gaspode.zanet.org.za SE:broadway.ny.us.dal.net :cizreemlak.net SE:viking.dal.net DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |
T:03:28:00 | Win2K-f | 118.163.247.79 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | EE:www.starman.ee :telephone.dd.blueline.be FI:www.if.ee :phonewire.dd.blueline.be :phonelogin.dd.blueline.be JP:ufospace.etowns.net KR:theforums.bbsindex.com GB:phonelogin.dnip.net :cx10man.weedns.com :commgr.co.cc TW:g.0x20.biz |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:08:02:00 | WinXP | 2.146.27.190 (-): . |
213.155.14.161:80 | DE:citi-bank.ru DE:utenti.lycos.it :vx9.users.freebsd.at NL:broekhuisjuweliers.nl TH:btech.ac.th TR:btr.gen.tr TR:burakasansor.com ES:bytegraf.com |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | f9e9b12776 NEW |
none[none] | none:none |
none|none | none | none |
08:33:00 | Win2K-f | 70.248.29.2 (WEBBCOUNTYTX.GOV): WEBB COUNTY, LAREDO, TEXAS, US. (100Mbps) |
n/a | :www.maxmind.com :getmyip.co.uk :www.getmyip.org US:checkip.dyndns.org 174.36.207.186:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
12:08:00 | Win2K-f | 188.255.116.203 (RIPE.NET): EUROPEAN REGIONAL REGISTRY, UK. (DSL) |
n/a | :www.ask.com :otblha.com :ydshtfbmw.org US:oiyku.biz :fgcajccflg.net US:ndzhekv.biz US:qettgph.biz :ueuxprsylzp.org US:kwpeqnofa.biz :dxtwgc.info US:jpzmpzdjv.biz :oqeikh.org :gptwhdelqbk.org :xobvboaq.com :dqrbdvzh.info :wgwcdbncz.com :tssbiilg.com :odfmm.net :vmvsrx.com US:khxhwiupb.biz :oiezgonzbm.info :ogqykwwcgzl.com US:ngeihpsqxtu.biz US:geuggdrnhr.biz :wxoiisi.org US:oakebdhtkdq.biz :gizpahcptjb.com :vmijserqzv.net US:lsukfsq.biz :spmqbpsr.com :krdptuqs.org :okufydorzqw.net :jiuekhel.net US:hwlbuweao.biz :mdbnacq.com :ekuzyvjaak.net :ubhwyvlblm.net :pygsvnth.info :peyygwss.org US:zmxwxthbnr.biz :mlyelg.org :sxuwdqkqdlu.net :tutvk.info :pgiilbofnhl.com :vxfoznrij.net :ittcnses.info :jopdqo.net :mxmceyljxqb.net :yhlusaol.info :yefagybuigl.net :bwzfk.com US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:13:05:00 | Win2K-f | 61.175.243.100 (-): QINGTIAN TV UNIVERSITY, BEIJING, BEIJING, CN. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:30:00 | Win2K-f | 189.242.206.118 (PROD-INFINITUM.COM.MX): UNINET S.A. DE C.V, MEXICO, DISTRITO FEDERAL, MX. (DSL) |
n/a | KR:theforums.bbsindex.com EE:www.starman.ee FI:www.if.ee LT:phonewire.dnip.net GB:phonelogin.dnip.net KR:koopa.dnip.net :cx10man.weedns.com US:microsoft.com US:fx010413.whyI.org :gynoman.weedns.com |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:14:05:00 | WinXP | 95.74.170.234 (-): TELECOM ITALIA MOBILE, GROSSETO, TOSCANA, IT. (DSL) |
n/a | DE:citi-bank.ru :albat.somee.com **:boemaclasic.ro TH:www2.bpp.go.th :caetanojrecruz.adv.br DE:buyukfirsat.bu.funpic.org GB:www.bsnlondon.co.uk GR:dincermakinasanayi.com.tr DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
T:14:43:00 | WinXP | 199.120.66.166 (NETINS.NET): NETINS INC, NEWTON, IOWA, US. (100Mbps) |
n/a | DE:moscow-advokat.ru :flanders.be.eu.undernet.org SE:broadway.ny.us.dal.net SE:ced.dal.net SE:coins.dal.net NL:diemen.nl.eu.undernet.org :caen.fr.eu.undernet.org SE:ozbytes.dal.net DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | ff851345d8 NEW |
none[none] | none:none |
none|none | none | none |
15:13:00 | Win2K-f | 187.75.82.123 (CAMPUSEAI.ORG): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | CN:www.baidu.com :oiezgonzbm.info :xxrcvootihu.net :nmmlmaxxik.info :cjrwguo.org :ubhwyvlblm.net :dtxgoo.org :eglst.com :tvbbaonpwg.org :bulpqh.com :bzvtwuns.org :pgiilbofnhl.com :fihdz.info :scerppgplgx.net :moasqyhgwl.info US:nsshnaht.biz :okufydorzqw.net :jqlfdg.info :rnfklgdm.net :yefagybuigl.net :gptwhdelqbk.org US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 9 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
16:07:00 | Win2K-f | 95.25.203.84 (CORBINA.NET): INVESTELEKTROSVIAZ LTD, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:16:17:00 | WinXP | 24.43.158.219 (RR.COM): ROAD RUNNER HOLDCO LLC, LOS ANGELES, CALIFORNIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:18:00:00 | WinXP | 218.1.65.26 (ONLINE.SH.CN): CHINANET SHANGHAI PROVINCE NETWORK, SHANGHAI, SHANGHAI, CN. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:18:53:00 | WinXP | 199.117.150.147 (TRANQUILITY.NET): CORAL WIRELESS LLC, HONOLULU, HAWAII, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | e92ed9f79c NEW |
none[none] | none:none |
none|none | none | none |
20:52:00 | Win2K-f | 95.24.104.95 (CORBINA.RU): INVESTELEKTROSVIAZ LTD, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | :www.maxmind.com :getmyip.co.uk EU:checkip.dyndns.org 174.36.207.186:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:23:45:00 | WinXP | 199.117.150.98 (TRANQUILITY.NET): CORAL WIRELESS LLC, HONOLULU, HAWAII, US. (DSL) |
n/a | DE:citi-bank.ru :parex-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | e92ed9f79c NEW |
none[none] | none:none |
none|none | none | none |