Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:42:00 | Win2K-f | 76.199.117.130 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, DALLAS, TEXAS, US. (DSL) |
n/a | US:microsoft.com EE:www.starman.ee FI:www.if.ee FI:194.215.38.135:80 EE:62.65.192.24:80 |
135 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:02:52:00 | WinXP | 111.252.47.206 (-): . |
n/a | DE:moscow-advokat.ru :washington.dc.us.undernet.org SE:vancouver.dal.net :lia.zanet.net :caen.fr.eu.undernet.org AT:graz.at.eu.undernet.org :gaspode.zanet.org.za NL:broekhuisjuweliers.nl :los-angeles.ca.us.undernet.org :lulea.se.eu.undernet.org SE:broadway.ny.us.dal.net TH:btech.ac.th TR:btr.gen.tr SE:viking.dal.net TR:burakasansor.com SE:coins.dal.net ES:bytegraf.com :brussels.be.eu.undernet.org TH:nt.go.th :cizreemlak.net :flanders.be.eu.undernet.org NL:london.uk.eu.undernet.org SE:ced.dal.net DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |
03:22:00 | Win2K-f | 41.202.2.210 (MYZIPNET.COM): AFRINIC, ACCRA, GREATER ACCRA, GH. (DSL) |
n/a | :www.maxmind.com :getmyip.co.uk US:checkip.dyndns.org :www.getmyip.org DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
03:22:00 | Win2K-f | 200.168.7.168 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:03:41:00 | WinXP | 46.162.198.91 (-): . |
213.155.14.161:80 | DE:citi-bank.ru :parex-bank.ru |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 | a4140e4032 NEW |
none[none] | none:none |
none|none | none | none |
T:05:51:00 | WinXP | 24.55.74.25 (ONELINKPR.NET): SAN JUAN CABLE LLC, PR. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
none | 0c38af69f4 NEW |
none[none] | none:none |
none|none | none | none |
T:07:11:00 | WinXP | 66.234.196.41 (ASTOUND.NET): ASTOUND BROADBAND, WALNUT CREEK, CALIFORNIA, US. (DSL) |
n/a | DE:citi-bank.ru US:kidos-bank.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 | bcb3ec60f2 NEW |
none[none] | none:none |
none|none | none | none |
T:07:31:00 | Win2K-f | 99.111.42.129 (-): . |
n/a | EE:www.starman.ee FI:www.if.ee US:microsoft.com FI:194.215.38.135:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
irc 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:07:38:00 | WinXP | 186.34.234.56 (-): . |
n/a | DE:citi-bank.ru US:kidos-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
07:51:00 | Win2K-f | 125.224.166.61 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
07:56:00 | Win2K-f | 31.134.243.167 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
08:03:00 | Win2K-f | 185.2.186.0 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:08:21:00 | WinXP | 46.117.120.39 (-): . |
n/a | DE:citi-bank.ru US:kidos-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:09:55:00 | Win2K-f | 118.83.33.10 (HTOJ.J-CNET.JP): JCN-HTMNET, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 122 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 36 34 of 36 |
0b951c2832 NEW e4ed4df0f0 NEW |
5fe761661a [0] de471fc380[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
09:56:00 | Win2K-f | 37.147.228.198 (-): . |
n/a | US:www.w3.org :rtzok.org :rzqkegve.com US:zlqzp.biz :jkgwddvh.com :yyzgxcelhe.org :gfpfwrophg.com US:lxztqh.biz US:bbeqp.com :uuoxyttbjhh.com :bdlnbgclf.info :afmqqd.info :qibsbwnoiha.info :atuthnizh.info :dppfznit.info US:qlamc.biz :pafaxzbkzzo.org :cjbzjsg.com :xycwqrft.net US:ahzhyyw.biz :hkxkxlyt.info US:gdnpu.biz :yzpntvcl.com :thqcu.com :dukdfv.info US:lyvvyskr.biz :eqmoqdgucat.net :nzvcfllxze.com :lxviap.info :vcglv.com :oarbtxmj.net :mdnply.info US:isbdruel.biz :kkitl.org :sunynneundr.com :arfjznkct.org :jovjju.org :mqeyt.org :ppwcbswr.info :eqrlrnsc.com :vcxozavswrs.com :daitrx.info :qajbmlin.com US:rsoksdv.biz :etfguhuily.org :nuzhkm.info :tvwhg.info :mckwadmt.net :pfnwlxpwbrv.net :yregp.org :vwdmgwutiur.com US:128.30.52.37:80 US:149.20.56.32:80 US:204.152.184.139:80 US:69.56.159.6:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:11:35:00 | Win2K-f | 216.14.153.222 (OLP.NET): BTC BROADBAND INC, BIXBY, OKLAHOMA, US. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee FI:194.215.38.135:80 EE:62.65.192.24:80 |
139 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:12:29:00 | WinXP | 94.248.156.149 (KABELNET.HU): VIDANET CABLE TELEVISION PROVIDER LTD, HU. (DSL) |
n/a | DE:citi-bank.ru CA:jewellerybazaar.net BR:casaebar.com.br :canossadhule.in :cansesiasknefesi.com DE:how2gethazanat.ho.funpic.de :www.evishop.de :chihuahuaupinghome.com IN:dehaspas.com TR:devdijital.com US:sobrenaturalbr.net DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | 412a3c6dfe NEW |
none[none] | none:none |
none|none | none | none |
T:12:44:00 | WinXP | 31.200.184.116 (-): . |
n/a | DE:citi-bank.ru :www.kelesoglugroup.com :bleublanc.net TH:kabinburi.ac.th :bilimegitim.org :juvenopolis.org.br :buyukkarapinar.com EU:karenoil.com US:cajovnanazemi.cz **:beautiful-shop.rv.ua :cannabisverificationcenter.com US:clinicadematematica.com.br DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
38 of 42 | 0d1eb4df79 NEW |
none[none] | none:none |
none|none | none | none |
13:01:00 | Win2K-f | 64.17.91.239 (WARPDRIVEONLINE.COM): US CABLE - HOBBS NM, BUFFALO, NEW YORK, US. (DSL) |
n/a | :www.google.com US:sszwuoygl.biz :quosfenvc.com US:cbvckzgc.biz US:yubogd.biz US:oivrhnrg.biz :haqybs.org :sfmzns.com :qjxyfhpo.net :qygmrgvjl.net :fbgwsafq.net :yvkjwkte.info US:bbeqp.com :hqpprore.info US:quixisppk.biz :bsfhnhodrw.org :qmdtdnzol.org US:iqaycoz.biz :pivstfzqvt.info :bnwumkop.com US:fuyirq.biz US:vmpczuyc.biz :qajbmlin.com :joaqktbf.info :jdjqtoghutb.info :swluoibu.net :lnfwhahovbj.org :oyabvkpn.com US:kjmuqi.biz :thshk.org US:jcnbe.biz :dfjrzlku.com :wbcygf.com :gfpfwrophg.com :fjejzk.org US:isbdruel.biz US:qlamc.biz US:wtohlucyil.biz US:hchpeo.biz :bdlnbgclf.info :gdruu.net US:sxkocnvpq.biz :qlkfzhoao.info :daitrx.info :mckwadmt.net US:awwjx.biz :oxyzwzzvtkw.org :wauqubyw.com :jdugoznjbs.net :mhfdgowfa.info :exvyho.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:18:19:00 | WinXP | 206.74.117.172 (SPIRITTELECOM.COM): TRUVISTA COMMUNICATIONS, WINNSBORO, SOUTH CAROLINA, US. (DSL) |
n/a | DE:citi-bank.ru :parex-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
19:12:00 | Win2K-f | 128.72.55.248 (TERMBILLING.COM): VARIOUS REGISTRIES, UK. (DSL) |
n/a | CA:www.msn.com :xsqbkjyg.info :snxclghgfk.com :qyqxjrissl.info US:buhqwubu.biz :ppnofe.net :jgahnhugk.org US:fwugzqxzc.biz :mejdyvtm.org :xfttqdhc.com :hdetqmwugn.com US:ktbpqohekca.biz :zmfmlcbxqw.com US:svglbdck.biz :nxrtvuia.info :wbnccidpa.net US:pipuwkiduh.biz :vlocazus.net :snedhgjjcji.net :wnhgooz.info :syuispkc.net US:vqysqexso.biz US:ljedq.biz :pivcknv.net :mssndg.info :yhrqnur.com :korfrffds.info :uyexgsrdzs.info :soyefvjfziz.net US:vgzroahhdsz.biz :cuyfpvnu.org :gvolxbcv.net US:xqazgnzip.biz :wdsoysst.org US:zjhjwl.biz :oltfwadqtd.com :ucjjze.org US:sqrhbxpnxc.biz :fagdufdvvrb.com :shddssnf.org US:zqvuteu.biz :eartj.info :wkneskxu.org :rwnrbjvx.com US:xxgsvkgya.biz :kxyhfkk.org US:vmcmwitg.biz US:liqoatlgj.biz :etqrzcp.org US:cganvwmufv.biz :jnpcigxzfuh.net :sowzg.info :fztti.info :ljcihfgxsc.com :hijuwp.org :gwqfmyou.net :ilnxley.net :debrqavvd.org :bbhjqqqf.com US:qihlbkagwtz.biz :sttfujxtqg.net US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:20:28:00 | Win2K-f | 211.5.17.49 (DION.NE.JP): DION (KDDI CORPORATION), YOKOHAMA, KANAGAWA, JP. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |