Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:05:00 | Win2K-f | 114.36.67.240 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
00:12:00 | Win2K-f | 81.73.183.98 (BUSINESS.TELECOMITALIA.IT): TELECOM ITALIA S.P.A, ROME, LAZIO, IT. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
00:20:00 | Win2K-f | 114.43.123.132 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 23 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
00:26:00 | Win2K-f | 89.35.118.167 (-): SC ENIGMA NET SRL, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
00:40:00 | Win2K-f | 210.101.158.76 (-): WOOLLALLA4033328D, SEOUL, SEOUL-T'UKPYOLSI, KR. (100Mbps) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
00:47:00 | Win2K-f | 182.52.139.45 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
00:54:00 | Win2K-f | 88.132.36.42 (PRTELECOM.HU): PRTELECOM-CP, SZOLNOK, JASZ-NAGYKUN-SZOLNOK, HU. (DSL) |
n/a | CN:www.baidu.com :hygwtruxww.org :nmaqdwrzmq.org :huusgdgeirw.net :inbcevunum.com :yhekglbgcxr.info :oisgg.info :dtfhbfbsgb.net :chvtdfjwqp.net :lxornh.net :dmsicvf.net :gmhzylflhc.com :gjwcvqcqb.com :uvrlnzxfod.net :qydnlwnnhq.com :fnwgkqxmx.net US:oyrdqfeigbn.biz :thwxsqghheq.com :obcuqa.com :zjnlcuz.net US:jcfdkdpqxq.biz US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 34 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
01:00:00 | Win2K-f | 190.145.12.99 (CABLE.NET.CO): TELMEX COLOMBIA S.A, CO. (DSL) |
n/a | US:trafficconverter.biz US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
01:07:00 | Win2K-f | 64.15.155.25 (PRIVATEDNS.COM): IWEB DEDICATED CL, MONTREAL, QUEBEC, CA. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
01:14:00 | Win2K-f | 178.75.202.194 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:01:46:00 | Win2K-f | 189.70.138.175 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, RECIFE, PERNAMBUCO, BR. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee :commgr.co.cc AP:g.0x20.biz :telephone.dd.blueline.be |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:02:48:00 | WinXP | 217.245.187.57 (T-DIALIN.NET): DEUTSCHE TELEKOM AG, BERLIN, BERLIN, DE. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a0139d7ad8 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:03:19:00 | Win2K-f | 219.69.14.40 (GIGA.NET.TW): HOSHIN MULTIMEDIA CENTER INC, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee FI:194.215.38.135:80 EE:62.65.192.24:80 |
135 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
03:37:00 | Win2K-f | 114.36.150.244 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | :www.maxmind.com :www.getmyip.org :getmyip.co.uk US:checkip.dyndns.org 174.36.207.186:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:04:42:00 | WinXP | 95.68.22.58 (-): ADDRESS POOL FOR LTC-HOME CUSTOMERS, RIGA, RIGA, LV. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | 488d27fe97 NEW |
none[none] | none:none |
none|none | none | none |
T:05:28:00 | WinXP | 118.83.4.199 (HTOJ.J-CNET.JP): JCN-HTMNET, HACHIOJI, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 122 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 36 34 of 36 |
0b951c2832 NEW e4ed4df0f0 NEW |
5fe761661a [0] de471fc380[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:08:00:00 | WinXP | 217.203.172.125 (-): TELECOM ITALIA MOBILE, ROME, LAZIO, IT. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru **:monsterfm.us.lt PK:paktextileindustries.com :cem.zicomdizayn.com US:snkspace.com :patagonia-ambient.com.ar US:www.bijibali.com :inspiringgemsshop.com TH:www.ktscc.org :ieamensagem.com.br |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 33bacab4a4 NEW |
none[none] | none:none |
none|none | none | none |
T:09:20:00 | Win2K-f | 74.168.71.253 (BELLSOUTH.NET): BELLSOUTH.NET INC, MARTINEZ, GEORGIA, US. (DSL) |
n/a | EE:www.starman.ee US:microsoft.com EE:62.65.192.24:80 |
135 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
13:22:00 | Win2K-f | 175.100.104.6 (-): . |
n/a | US:www.ask.com :fgvjopdtgz.info :qergkb.info :ncxawvrgo.info US:ixmjg.biz :dmsicvf.net US:qrdjml.biz :yiqxhmja.org US:ifbnvgcj.biz US:jcanngpkbuv.biz :vwhmmroco.org US:binoub.biz :xzskkmipdp.info :ukpdyl.net :usavuino.info :scpaa.net :zbuphwy.net :gwvutqnhuhp.com :rkqribqf.info :mntnpmh.net :kmbuop.info :mvhbqsrjis.info :hhlzpcqj.info :opvmkhep.org :icqkcxwc.net :thwxsqghheq.com :tiwhuzpcx.net :azdcanlfht.org :sspspixedey.net :tgboledu.org :pvmtnycl.info :korybtnpkdz.net :xnprmbe.org :kyobmwlxpgd.com :dzwvanwg.info :qoyltuuv.com :hhzcv.info :kmyklsie.info :pqwceympbuj.org :peptagni.info :wvhkyx.net :fjoopzej.net :uvrlnzxfod.net US:yahxiwdlf.biz :ntheqrjh.org US:qtlwcwkz.biz :lgcvkbtpvcx.com :jrxhoeys.org :ggbvl.org :xjriph.info :vebsjh.info :xyzlb.net :vsjeqdnmqkf.com :ksrni.info US:yavqdyl.biz :eiztyrkkorx.net :uolgbgtimr.info :oisgg.info :rjhfge.com :npoqeruzc.net :rlksnp.com US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
14:55:00 | Win2K-f | 88.84.112.153 (-): SPSNET, RIYADH, AR RIYAD, SA. (DSL) |
n/a | :www.maxmind.com DE:131.220.6.26:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:15:23:00 | Win2K-f | 210.56.179.214 (AVIS.NE.JP): DENSAN CO. LTD, NAGANO, OITA, JP. (DSL) |
n/a | :telephone.dd.blueline.be :phonewire.dd.blueline.be :phonelogin.dd.blueline.be JP:ufospace.etowns.net KR:theforums.bbsindex.com US:microsoft.com LT:phonewire.dnip.net GB:phonelogin.dnip.net EE:www.starman.ee FI:www.if.ee KR:koopa.dnip.net :cx10man.weedns.com US:fx010413.whyI.org :gynoman.weedns.com :c010x1.co.cc GB:g.0x20.biz |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
17:53:00 | Win2K-f | 70.248.29.2 (WEBBCOUNTYTX.GOV): WEBB COUNTY, LAREDO, TEXAS, US. (100Mbps) |
n/a | :www.maxmind.com :www.getmyip.org :getmyip.co.uk US:checkip.dyndns.org 174.36.207.186:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:22:54:00 | WinXP | 123.224.120.217 (OCN.NE.JP): OPEN COMPUTER NETWORK, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace |