Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
01:40:00 | Win2K-f | 183.82.239.224 (-): . |
n/a | :www.maxmind.com DE:131.220.6.26:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
03:11:00 | Win2K-f | 122.54.193.38 (PLDT.NET): IPG, PH. (DSL) |
n/a | US:www.w3.org :qeqajetpjcb.info :osrnqaz.net US:vxhzseig.biz :oufgd.info CN:zjfjq.com :qcycfyc.org :hphrzcxztm.info :crxic.net :kjuwo.com :ppsqntju.info US:ltbttrhymf.biz :uhseifbuq.com :vmrljn.org :uwawygyb.net :dpmgxjhbvkr.com :tdzymn.info :lgnflpsw.net :cwpuhfyu.net :qowgtgdwdn.org :nzlhgttg.com US:128.30.52.37:80 US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:03:47:00 | Win2K-f | 5.57.216.173 (-): . |
n/a | EE:www.starman.ee FI:www.if.ee :commgr.co.cc AP:g.0x20.biz :telephone.dd.blueline.be :phonewire.dd.blueline.be :phonelogin.dd.blueline.be JP:ufospace.etowns.net KR:theforums.bbsindex.com LT:phonewire.dnip.net GB:phonelogin.dnip.net FI:194.215.38.135:80 EE:62.65.192.25:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:03:53:00 | WinXP | 94.52.71.104 (-): NEW COM TELECOMUNICATII SA, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | DE:citi-bank.ru :adult-empire.com DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
05:53:00 | Win2K-f | 116.203.192.171 (-): . |
n/a | :www.maxmind.com :getmyip.co.uk EU:checkip.dyndns.org 174.36.207.186:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
09:29:00 | Win2K-f | 41.82.153.187 (-): . |
n/a | US:www.w3.org :fchmvaqj.net :rfthveyf.org :uhrocotu.info :dbzeayrjrw.org :mpgbxn.net US:rxwzhmb.biz :kfpvgdsky.org US:urbuzfpelle.biz :vqxwaqdh.net :rvetwgjd.info :tqmqje.com :lcdpzz.org :yyeujtabmcg.org US:wmmsf.biz :lhxmsatsdv.com :okfiumrmgft.info :psyiwbj.net US:ncrywrk.biz :qcycfyc.org US:jrowvktqpv.biz :kizysmkun.org :etxjb.org :epcflqmonkw.org :kucokhcv.info :nrmjw.org :rgphiknnqa.com :pfzetoyw.org :bxiyqppnn.net US:loznnlpe.biz :jdaltvp.org US:128.30.52.37:80 US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:09:34:00 | WinXP | 106.206.128.150 (-): . |
n/a | DE:citi-bank.ru NL:broekhuisjuweliers.nl TH:btech.ac.th TR:btr.gen.tr TR:burakasansor.com ES:bytegraf.com TH:nt.go.th :cizreemlak.net |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
38 of 43 | d2c5aa9563 NEW |
none[none] | none:none |
none|none | none | none |
T:10:27:00 | WinXP | 186.180.89.3 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:11:05:00 | WinXP | 46.211.114.200 (-): . |
n/a | DE:citi-bank.ru :albat.somee.com **:boemaclasic.ro TH:www2.bpp.go.th :caetanojrecruz.adv.br DE:buyukfirsat.bu.funpic.org GB:www.bsnlondon.co.uk GR:dincermakinasanayi.com.tr |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
T:11:26:00 | Win2K-f | 189.80.94.138 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, RIO DE JANEIRO, RIO DE JANEIRO, BR. (DSL) |
n/a | EE:www.starman.ee FI:194.215.38.135:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
irc 4 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:13:40:00 | Win2K-f | 89.230.174.79 (MM.PL): MULTIMEDIA POLSKA S. A, WARSAW, WARSZAWA, PL. (DSL) |
n/a | EE:www.starman.ee | 445 | pcap | raw alerts ruleset |
irc 3 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:13:50:00 | Win2K-f | 151.56.61.173 (51-151.NET24.IT): IUNET-BNET, VENICE, VENETO, IT. (DSL) |
n/a | EE:www.starman.ee | 445 | pcap | raw alerts ruleset |
irc 3 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:15:38:00 | Win2K-f | 60.55.8.20 (-): NBIP TONGLIAN(NINGBO)INFO-PORT CO. LTD, NINGBO, ZHEJIANG, CN. (DSL) |
n/a | EE:www.starman.ee FI:194.215.38.135:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
irc 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
15:39:00 | Win2K-f | 1.174.45.94 (-): . |
n/a | US:www.w3.org :jzwecv.com :viwvrjeygu.info US:qeuogejo.biz :ppsqntju.info US:uniubi.biz :gndkkm.info :iybbtbmwu.org US:urbuzfpelle.biz US:bmmgm.biz :iltcvvphxre.info :fohenpcj.com CN:zjfjq.com US:qbihiqxn.biz US:hjoif.biz :knfcd.org :kucokhcv.info **:glzfb.com :bxiyqppnn.net US:rmvpp.biz :wfzxv.net US:128.30.52.37:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
16:36:00 | Win2K-f | 111.68.107.60 (10.PERN.PK): PERN-PAKISTAN EDUCATION & RESEARCH NETWORK IS AN, PK. (DSL) |
n/a | :www.maxmind.com :www.getmyip.org :getmyip.co.uk US:checkip.dyndns.org 174.36.207.186:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:17:44:00 | WinXP | 24.155.199.42 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS CORPUS CHRISTI HUB, CORPUS CHRISTI, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
19:20:00 | Win2K-f | 189.35.182.93 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, SãO PAULO, SAO PAULO, BR. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:19:27:00 | WinXP | 222.39.183.200 (HERBALQC.COM): CHINA RAILWAY TELECOMMUNICATIONS CENTER, BEIJING, BEIJING, CN. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 | bcb3ec60f2 NEW |
none[none] | none:none |
none|none | none | none |
19:32:00 | Win2K-f | 182.73.10.254 (-): . |
n/a | :www.maxmind.com US:checkip.dyndns.org :www.getmyip.org :getmyip.co.uk 174.36.207.186:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | 917c085aca NEW |
none[3] | none:none |
Armadillo| | none | trace |
T:19:43:00 | Win2K-f | 182.73.10.254 (-): . |
n/a | :www.maxmind.com :www.getmyip.org :getmyip.co.uk EU:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | 917c085aca NEW |
none[3] | none:none |
Armadillo| | none | trace |
T:21:57:00 | WinXP | 218.45.118.102 (CABLENET.NE.JP): CABLENET SAITAMA CO. LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
761a66b891 NEW 98d05c039b NEW |
b469dac5dc [0] none [none] |
ASM:Graph none:none |
tElock| none|none |
lines=64 embedded dns none |
trace none |
23:18:00 | Win2K-f | 116.203.15.64 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
23:25:00 | Win2K-f | 92.112.116.30 (UKRTEL.NET): UKRTELECOM IP ACCESS NETWORK, UA. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
23:31:00 | Win2K-f | 200.158.93.10 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
23:38:00 | Win2K-f | 121.67.7.176 (-): BORANET, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
23:45:00 | Win2K-f | 122.117.133.54 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
23:51:00 | Win2K-f | 209.190.46.75 (XLHOST.COM): COLUMBUS NETWORK ACCESS POINT INC, COLUMBUS, OHIO, US. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |