Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:37:00 | WinXP | 188.255.62.225 (RIPE.NET): EUROPEAN REGIONAL REGISTRY, UK. (DSL) |
n/a | :siliconfireware.ru :wpad |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee NEW |
none[0] | none:none |
ASPack| | lines=298 embedded dns |
trace |
T:01:44:00 | WinXP | 46.40.34.32 (-): . |
213.155.14.161:80 | DE:citi-bank.ru CA:jewellerybazaar.net BR:casaebar.com.br :canossadhule.in :cansesiasknefesi.com DE:how2gethazanat.ho.funpic.de :www.evishop.de :chihuahuaupinghome.com IN:dehaspas.com TR:devdijital.com US:sobrenaturalbr.net BR:direitopublico.com.br |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 9276456bf8 NEW |
none[none] | none:none |
none|none | none | none |
T:02:21:00 | WinXP | 89.145.131.32 (-): HOME ETHERNET NETWORK, RU. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru :albat.somee.com **:boemaclasic.ro TH:www2.bpp.go.th :caetanojrecruz.adv.br DE:buyukfirsat.bu.funpic.org GB:www.bsnlondon.co.uk GR:dincermakinasanayi.com.tr :parex-bank.ru |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.8 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
05:40:00 | Win2K-f | 91.83.180.67 (SULINET.HU): INVITEL TAVKOZLESI SZOLGALTATO RT, HU. (DSL) |
n/a | US:trafficconverter.biz :www.google.com :fgdkg.org US:nycypgaihvl.biz :sqwjfl.com :emdka.org :yvjqprz.org :fufvvar.info US:yzeihsz.biz :lghxkmnur.org :xjywaarrof.org :qmrihdgyj.com US:kspprlbq.biz :oxbvgp.org :pdfmzrtyd.com :yimqzfbojrt.com :sydbxs.net :iiexik.info US:rupyjyp.biz :grinzgzvj.net :takzw.org US:kfzkkp.biz :dhyxejtp.org :fubfx.com :xrmppmcw.org :bmerzif.info :ovineqlv.info :pewsuho.net :ioptilux.net US:ibwuptz.biz US:ivoiwn.biz :gkkwjnpd.net :gfacwnhirwc.org :uitjgjutn.net :hagkqhw.info :edpejpivd.com :vvthl.com :cchftjojwro.com :xpxdnraoiir.net US:isdeceylnn.biz :khdjwazf.info :sgjcforr.com :jawiqjkjei.net :ewixi.net :krrpixbj.com :ejywqeua.info :jxmnepjkez.info :dhvobxlqmsw.info :rypstk.org :csqkazrital.com :kkryw.org :qskzirjvs.org :ufqdcalk.com :awqtimss.info US:htqmo.biz :syrvfajryb.net :rntlprxh.com US:prjbqjrs.biz :kslltf.com :zymsowq.info :kqhzzvjm.org :glhdqrh.org US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:10:57:00 | WinXP | 46.162.199.239 (-): . |
n/a | DE:moscow-advokat.ru :caen.fr.eu.undernet.org SE:qis.md.us.dal.net SE:broadway.ny.us.dal.net DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |
T:11:24:00 | WinXP | 46.162.199.239 (-): . |
n/a | DE:moscow-advokat.ru :lulea.se.eu.undernet.org SE:london.uk.eu.undernet.org SE:ozbytes.dal.net :brussels.be.eu.undernet.org NL:broekhuisjuweliers.nl TH:btech.ac.th NL:diemen.nl.eu.undernet.org TR:btr.gen.tr AT:graz.at.eu.undernet.org TR:burakasansor.com ES:bytegraf.com SE:viking.dal.net TH:nt.go.th :cizreemlak.net :caen.fr.eu.undernet.org SE:coins.dal.net SE:broadway.ny.us.dal.net :gaspode.zanet.org.za SE:qis.md.us.dal.net SE:vancouver.dal.net :lia.zanet.net DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |
T:11:48:00 | WinXP | 95.58.10.214 (DIAL.ONLINE.KZ): JSC KAZAKHTELECOM SOUTH KAZAKHSTAN AFFILIATE, ALMATY, ALMATY CITY, KZ. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru NL:broekhuisjuweliers.nl TH:btech.ac.th TR:btr.gen.tr TR:burakasansor.com ES:bytegraf.com TH:nt.go.th :cizreemlak.net |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 43 | e01ddca98c NEW |
none[none] | none:none |
none|none | none | none |
12:07:00 | Win2K-f | 2.94.188.6 (-): . |
n/a | :www.maxmind.com :www.getmyip.org EU:checkip.dyndns.org 174.36.207.186:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:12:35:00 | WinXP | 31.63.205.129 (-): . |
213.155.14.161:80 | DE:citi-bank.ru CA:jewellerybazaar.net BR:casaebar.com.br :canossadhule.in :cansesiasknefesi.com DE:how2gethazanat.ho.funpic.de :www.evishop.de :chihuahuaupinghome.com IN:dehaspas.com TR:devdijital.com US:sobrenaturalbr.net BR:direitopublico.com.br |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 9ebcc2e373 NEW |
none[none] | none:none |
none|none | none | none |
T:12:45:00 | WinXP | 2.195.138.150 (-): . |
213.155.14.161:80 | DE:citi-bank.ru :www.kelesoglugroup.com :bleublanc.net TH:kabinburi.ac.th :bilimegitim.org :juvenopolis.org.br :buyukkarapinar.com EU:karenoil.com US:cajovnanazemi.cz **:beautiful-shop.rv.ua :cannabisverificationcenter.com US:clinicadematematica.com.br US:construindia.com :adult-empire.com |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | fca087c49d NEW |
none[none] | none:none |
none|none | none | none |
13:51:00 | WinXP | 91.66.116.72 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, FRANKENTHAL, RHEINLAND-PFALZ, DE. (DSL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 1511a3f219 NEW |
none[none] | none:none |
none|none | none | none |
T:14:11:00 | WinXP | 5.248.21.54 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 | 22340630ac NEW |
none[none] | none:none |
none|none | none | none |
T:15:52:00 | WinXP | 181.16.32.128 (-): . |
n/a | DE:citi-bank.ru :parex-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:17:25:00 | Win2K-f | 189.166.91.130 (PROD-INFINITUM.COM.MX): GESTIN DE DIRECCIONAMIENTO UNINET, MX. (DSL) |
n/a | KR:koopa.dnip.net EE:www.starman.ee FI:www.if.ee :cx10man.weedns.com US:microsoft.com US:fx010413.whyI.org :commgr.co.cc :telephone.dd.blueline.be :phonewire.dd.blueline.be FI:194.215.38.135:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:18:42:00 | WinXP | 125.58.92.154 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 211 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 43 40 of 43 |
70affb1fe5 NEW ff20d4353a NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |