Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:48:00 | Win2K-f | 111.254.146.219 (-): . |
n/a | :www.maxmind.com EU:checkip.dyndns.org 174.36.207.186:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
01:22:00 | Win2K-f | 190.137.153.250 (NET.AR): TORANZO HECTOR, AR. (100Mbps) |
n/a | :www.maxmind.com :getmyip.co.uk :www.getmyip.org US:checkip.dyndns.org 174.36.207.186:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
04:23:00 | Win2K-f | 195.199.242.170 (-): INFORMATIKAI KOZGAZDASAGI NYOMDAIPARI SZAKKOZEPISKOLA ES SZAKISKOLA, BUDAPEST, BUDAPEST, HU. (100Mbps) |
n/a | US:www.w3.org :qwbaahqbe.info :qfbfqfv.info :snedhgjjcji.net :uufhcov.net :hinsymif.com :wnxevaimbbp.net US:hvcrm.biz :ffaucrxt.com US:ktbpqohekca.biz :rwnrbjvx.com :etqrzcp.org :iuhic.com :ednkkwno.com :lctdjavwkou.net :ftght.com US:qsrelb.biz :ppqyygtq.net :fcxurzxb.org US:vwwxai.biz :pivcknv.net :itgnpdg.org :ljccligfp.info :ttrjxfbnpl.org :upgynksnnut.info :mnypvpzt.org :hdetqmwugn.com :bbhjqqqf.com US:vmcmwitg.biz :jngwocov.net :irogkdr.org :nygddnop.org US:ituqkqfgnum.biz :ngsazbhmgf.net US:ynisaeqpwyf.biz US:dzewxsychva.biz :dqfshnt.net :rbixxix.com :ikvogulgc.org US:slkbzrmv.biz US:pipuwkiduh.biz US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 20 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:05:22:00 | Win2K-f | 118.221.56.86 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
178.132.202.196:65520 | EU:proxima.ircgalaxy.pl US:microsoft.com :uhjio12.com EU:superadsdomain.ru KZ:62.109.8.165:80 EU:91.217.90.237:80 92.63.103.53:80 |
135 | pcap | raw alerts ruleset |
irc http 169 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 41 31 of 33 none |
ab9c4b5f21 NEW d789c8d157 NEW e80356d073 NEW |
5fe48b2dcc [0] 5f6572479f[0] none [none] |
ASM:Graph ASM:Graph none:none |
Armadillo| PolyEnE| none|none |
lines=42 lines=113 embedded dns none |
trace trace none |
T:06:18:00 | Win2K-f | 46.73.185.16 (-): . |
n/a | US:fx010413.whyI.org EE:www.starman.ee FI:www.if.ee US:microsoft.com :gynoman.weedns.com :c010x1.co.cc :commgr.co.cc AP:g.0x20.biz :telephone.dd.blueline.be :phonewire.dd.blueline.be :phonelogin.dd.blueline.be JP:ufospace.etowns.net LT:phonewire.dnip.net :cx10man.weedns.com |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:07:26:00 | WinXP | 188.255.51.3 (RIPE.NET): EUROPEAN REGIONAL REGISTRY, UK. (DSL) |
n/a | :siliconfireware.ru :wpad EU:new.egg.com EU:www.egg.com :metrics.ybs.co.uk RU:www.masterbank.ru |
445 | pcap | raw alerts ruleset |
http http 34 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee NEW |
none[0] | none:none |
ASPack| | lines=298 embedded dns |
trace |
T:11:51:00 | WinXP | 181.16.32.128 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:12:11:00 | WinXP | 37.229.231.173 (-): . |
n/a | DE:citi-bank.ru :cikmayedekparca.com :brucegarrod.com :cbbasimevi.com :brandaoematos.com.br **:caglarteknik.com :bharatisangli.in BR:cacs.org.br RO:butacm.go.ro EU:boyabateml.k12.tr :casbygroup.com :parex-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 8a2553433c NEW |
none[none] | none:none |
none|none | none | none |
12:18:00 | WinXP | 37.229.231.173 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 8a2553433c NEW |
none[none] | none:none |
none|none | none | none |
13:39:00 | Win2K-f | 95.169.131.128 (E66.RU): LLC EUROTEL, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | US:www.ask.com :kgwbfoo.info US:qihlbkagwtz.biz :ehxevfbe.com :asrqnbndugb.net US:wnbzdw.biz US:liqoatlgj.biz :pcvts.info :hizvtnringu.info :lixgv.info US:dzewxsychva.biz US:zjhjwl.biz US:hvcrm.biz :dqfshnt.net :ucjjze.org :llcss.info US:iyqklnogir.biz :wdsoysst.org :debrqavvd.org :xjggffinrl.info :usjpkglla.org US:165.254.47.115:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:14:01:00 | Win2K-f | 69.9.241.193 (MIDCO.NET): MIDCONTINENT MEDIA INC, SIOUX FALLS, SOUTH DAKOTA, US. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee JP:ufospace.etowns.net KR:theforums.bbsindex.com LT:phonewire.dnip.net GB:phonelogin.dnip.net KR:koopa.dnip.net :cx10man.weedns.com US:fx010413.whyI.org :phonelogin.dd.blueline.be |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
15:12:00 | Win2K-f | 213.230.19.253 (FIRSTFFC.COM): MEDUNET, RIYADH, AR RIYAD, SA. (100Mbps) |
n/a | :www.maxmind.com :www.getmyip.org :getmyip.co.uk US:checkip.dyndns.org 174.36.207.186:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:15:54:00 | WinXP | 206.74.117.172 (SPIRITTELECOM.COM): TRUVISTA COMMUNICATIONS, WINNSBORO, SOUTH CAROLINA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:17:36:00 | Win2K-f | 213.230.19.253 (FIRSTFFC.COM): MEDUNET, RIYADH, AR RIYAD, SA. (100Mbps) |
n/a | EE:www.starman.ee FI:www.if.ee :commgr.co.cc :g.0x20.biz :telephone.dd.blueline.be KR:theforums.bbsindex.com |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:17:46:00 | Win2K-f | 190.253.95.227 (TELEFONICA.NET.CO): COLOMBIA TELECOMUNICACIONES S.A. ESP, SANTAFé DE BOGOTá, DISTRITO ESPECIAL, CO. (DSL) |
n/a | FI:www.if.ee EE:www.starman.ee :commgr.co.cc :g.0x20.biz :telephone.dd.blueline.be LT:phonewire.dnip.net |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:27:00 | Win2K-f | 84.228.159.139 (INTER.NET.IL): SMILE INTERNET GOLD, RAMAT GAN, TEL AVIV, IL. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:33:00 | Win2K-f | 198.15.110.135 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
20:47:00 | Win2K-f | 125.235.11.74 (ADSL.VIETTEL.VN): DAI IP CHO ADSL TAI HANOI, HANOI, DAC LAC, VN. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 23 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
23:04:00 | Win2K-f | 46.47.202.172 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
23:12:00 | Win2K-f | 92.241.107.99 (STREAM.RU): SMOLTELECOM, RU. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 23 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
23:20:00 | Win2K-f | 60.196.24.184 (-): DACOM INTERNET SERVICE PROVIDER SEOUL KOREA, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
23:28:00 | Win2K-f | 122.121.58.89 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
23:37:00 | Win2K-f | 117.206.190.176 (10/24.BSNL.IN): NIB (NATIONAL INTERNET BACKBONE), NEW DELHI, DELHI, IN. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
23:45:00 | Win2K-f | 219.85.218.35 (SO-NET.NET.TW): SONY NETWORK TAIWAN LIMITED, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 22 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
23:52:00 | Win2K-f | 121.246.75.21 (VSNL.NET.IN): INTERNET SERVICE PROVIDER, NEW DELHI, DELHI, IN. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |