Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:08:00 | Win2K-f | 69.108.32.27 (-): 3G INC, SANTA ANA, CALIFORNIA, US. (100Mbps) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 22 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
00:16:00 | Win2K-f | 189.146.36.254 (PROD-INFINITUM.COM.MX): GESTIN DE DIRECCIONAMIENTO UNINET, MEXICO, DISTRITO FEDERAL, MX. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 23 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
00:24:00 | Win2K-f | 61.9.79.88 (MOZCOM.NET): MOSAIC COMMUNICATIONS INC, MANILA, MANILA, PH. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
00:32:00 | Win2K-f | 199.16.57.9 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
00:41:00 | Win2K-f | 49.204.166.60 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
00:49:00 | Win2K-f | 81.182.73.2 (T-ONLINE.HU): T-ONLINE ADSL CLIENTS (DYNAMIC ADDRESS POOL), BUDAPEST, BUDAPEST, HU. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
00:56:00 | Win2K-f | 89.165.169.4 (HERTZA.RO): S.C. ARES TELECOM S.R.L, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 22 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
02:00:00 | Win2K-f | 49.204.52.105 (-): . |
n/a | US:trafficconverter.biz :www.yahoo.com :ttkwyjk.net US:enezbbor.biz :uidynnhe.info :coflzbtscw.net :fqfjee.net :zkyyrzckq.com US:btwewgxm.biz US:nvgcsh.biz US:uihtkxu.biz :vwrntvcysb.org :sppymfyxbb.com :cmitrzcm.com :uodgfm.com US:nidaik.biz :yiilwbjdo.com :msgnh.com US:vvuvnog.biz :upkzpc.org US:gjzcfnqd.biz :tdamgdglyf.net :liotimqcf.org :tgyjuem.net :ypbuvtxsxh.info :hdwbpodlleo.com :tgyrakkem.net US:sutylko.biz :rfvyntdcy.com US:wlkfpmf.biz :vlewiqsu.com :cerex.com :hlbftlnaoyj.com US:ubxtzqqd.biz :byqjoqsa.org :dagbscauy.com :jahogujfz.com :lfrukvpzvl.net :uklavlv.org :zitzqauje.com :onukkkempd.com :dfbnw.com :dkpbwg.net :untgwncig.org US:kftyzdzpv.biz US:mzythzp.biz :ubhqlgeu.org US:coihxrhu.biz :fmcunn.info :wlxwmygb.com :azfay.org :scdvbwb.info US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
05:05:00 | Win2K-f | 118.167.108.35 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | CA:www.msn.com :rrqydkciub.com :nhifqrh.org :mpfotlqg.org :sneuqvny.info :uylecyz.org US:fxyprcg.biz :bsmtkblj.com US:nvgcsh.biz :ncwkrcp.net US:gftraipabjn.biz :ofepyzpeshf.info :peobixd.com :fpwjjtngq.info :qbhdeyo.com :ngugkv.info US:gdfhrqlk.biz :xwailuvuakf.org :ewukbgpkyhe.net :onukkkempd.com US:cxzoxhrini.biz US:czbalav.biz US:kftyzdzpv.biz :eryzimfarfu.org US:fcrfrtw.biz :mupkw.org :dkogcwyl.org :xhpkjmrbig.info :rzeochnrthz.net :wobyhpn.com :shulgobs.com :untgwncig.org :fcdlyddul.org :mgbqpptww.org :qmxdsalvqi.info :jnvdgxgmhq.org :ajhasnv.com :mfogobcl.net :plhlfmjqz.com US:coihxrhu.biz :kurrfiiwaeg.org US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
06:43:00 | Win2K-f | 180.222.216.197 (-): . |
n/a | :www.maxmind.com :getmyip.co.uk :www.getmyip.org EU:checkip.dyndns.org DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:11:54:00 | Win2K-f | 193.126.6.18 (U8.EUNET.PT): KPNQWEST PORTUGAL BACKBONE, LISBON, LISBOA, PT. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee :cx10man.weedns.com :fx010413.whyI.org :gynoman.weedns.com :c010x1.co.cc US:g.0x20.biz :telephone.dd.blueline.be US:microsoft.com FI:194.215.38.135:80 |
139 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:12:08:00 | Win2K-f | 188.52.240.142 (SAUDI.NET.SA): SAUDINET SAUDI TELECOM COMPANY, RIYADH, AR RIYAD, SA. (DSL) |
n/a | FI:www.if.ee :telephone.dd.blueline.be EE:www.starman.ee :commgr.co.cc JP:ufospace.etowns.net US:microsoft.com |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:12:38:00 | WinXP | 216.212.232.167 (ROSE.NET): CITY OF THOMASVILLE UTILITIES, THOMASVILLE, GEORGIA, US. (DSL) |
n/a | DE:citi-bank.ru :albat.somee.com **:boemaclasic.ro TH:www2.bpp.go.th :caetanojrecruz.adv.br DE:buyukfirsat.bu.funpic.org GB:www.bsnlondon.co.uk GR:dincermakinasanayi.com.tr :parex-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
T:13:49:00 | Win2K-f | 117.204.50.137 (10/24.BSNL.IN): NIB (NATIONAL INTERNET BACKBONE), NEW DELHI, DELHI, IN. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee TW:g.0x20.biz :phonelogin.dd.blueline.be LT:phonewire.dnip.net :cx10man.weedns.com FI:194.215.38.135:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
14:21:00 | Win2K-f | 82.55.201.161 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A. TIN EASY LITE, IT. (DSL) |
n/a | :www.google.com :jauttxafl.net :coflzbtscw.net :azfay.org :vtraxgk.org :brjsftapra.org :ubhqlgeu.org :eryzimfarfu.org :qdyfwmktgd.com :jnvdgxgmhq.org :nyadgancrrm.com US:zsbyolswquu.biz :hcxkxkj.info :jahogujfz.com :ujwcuwinwg.com :pxelfdl.org :byqjoqsa.org US:gjzcfnqd.biz :uephdvd.com :scdvbwb.info :qohydoh.info :ersotw.info :dfbnw.com :awyhuvbuenu.net :wobyhpn.com US:gdfhrqlk.biz :hlqisp.info :enwizhd.com :manic.info :exbphndu.info :cbjprezvgez.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | b68b8a4602 NEW |
none[none] | none:none |
none|none | none | none |
T:14:48:00 | WinXP | 206.74.117.172 (SPIRITTELECOM.COM): TRUVISTA COMMUNICATIONS, WINNSBORO, SOUTH CAROLINA, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:16:09:00 | WinXP | 178.137.212.252 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 | 22340630ac NEW |
none[none] | none:none |
none|none | none | none |
19:09:00 | Win2K-f | 210.185.149.216 (N80B9D2.WI-COM.JP): WICOM INC, SAPPORO, HOKKAIDO, JP. (DSL) |
n/a | US:trafficconverter.biz US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 13 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:15:00 | Win2K-f | 180.211.96.14 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:31:00 | Win2K-f | 59.120.246.218 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | CN:www.baidu.com :ghjtcavd.com :nddkt.info :jveoedn.net :yqztaqen.net :huuogmldmip.com :bspgnnlrozc.info :uzrpl.info :vhcwzsobgs.info :ohivhvsp.org :wcunzs.com :yimmcxh.org :lzrdnyju.com :gbhwv.net :ugamekqzse.net :pommf.com :dthhjrz.info :qwqvs.net :llmzclsgmqt.info CA:woiks.com :wexdo.net :xnmoom.info US:gtuhojs.biz :hdlkepqujt.org :movjsuui.net :idrabrvy.com US:qlblz.biz :bbllqa.org :ekamgeuq.org :dzzucktm.info US:byghauihqr.biz :dlwkxmns.net :fkpmpc.org :srdolrgskfi.info :ustuvnvu.net US:kuxdgrdx.biz :ohkwjcsd.org :hgbplzir.info :ucfqvj.com :yslmjyny.net :ldquxtcqt.net :gcswznbtn.info :rjktijsf.com :hmdyx.org US:holdc.biz :brfja.org US:rfapunipc.biz :qkhvxvztkh.info US:edjnxxrbjzr.biz :jzxpfzc.com :diczbx.com :dubpzmhp.info :fjbrzzos.net :armmri.net :qcnkdmch.info US:iplcwlgg.biz :oszajzn.info :azpvvrch.net :cqqrbc.info :freilrclsdo.com :rmwmzmrh.org US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 9 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:20:35:00 | WinXP | 122.26.151.84 (OCN.NE.JP): OPEN COMPUTER NETWORK, YOKOHAMA, KANAGAWA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
23:36:00 | Win2K-f | 93.115.12.99 (-): SC SMART MEDIA SRL, RO. (DSL) |
n/a | CN:www.baidu.com :aiheenupje.info :sizqlodq.com :boqytk.org :kbitz.com :srrchc.org US:rfapunipc.biz :oeextdktu.org :dmwypdix.info :faftsvuqn.org :qodgmprp.org :guoqdpthy.org :kgbyqodve.info :rmhunja.info :huuogmldmip.com :gqxngxvyuf.org :szwzuay.net US:rpkjuaez.biz :vgltszp.info US:rlnguwlwp.biz :aglqirnlvg.org :btvkfhrjkrr.org :fxjokxvghl.info :uygaa.info :qgixhcxiizo.info :jzxpfzc.com :qpyzkmiurc.com :qwqvs.net :qegpsacp.info :gbhwv.net :aluwzivf.com US:204.152.184.139:80 CN:220.181.111.147:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |