Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:02:03:00 | Win2K-f | 193.105.35.151 (IPAPER.COM): BLOCK FOR PI ASSIGNMENTS, UK. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee LT:phonewire.dnip.net GB:phonelogin.dnip.net KR:koopa.dnip.net :phonewire.dd.blueline.be :cx10man.weedns.com |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:08:13:00 | WinXP | 66.234.196.41 (ASTOUND.NET): ASTOUND BROADBAND, WALNUT CREEK, CALIFORNIA, US. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 | bcb3ec60f2 NEW |
none[none] | none:none |
none|none | none | none |
08:52:00 | Win2K-f | 1.170.3.135 (-): . |
n/a | US:www.yahoo.com :wakhudtxy.info :qgixhcxiizo.info :celiwlkdb.org :mclpxtsuvz.info US:qlblz.biz :qrunv.com :tmhik.com :aluwzivf.com :lzrdnyju.com :rrgivglql.info :hsryjv.org :qegpsacp.info :cuskhujf.net :tlbpispxo.info :alehu.org :guoqdpthy.org :ivnwpsvckqu.net :qydng.org :ohivhvsp.org :ustuvnvu.net US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:08:53:00 | WinXP | 81.29.255.202 (-): PARDIS ETTELA RESAAN SEPEHR, IR. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 | bcb3ec60f2 NEW |
none[none] | none:none |
none|none | none | none |
T:11:07:00 | WinXP | 79.163.74.112 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
n/a | DE:citi-bank.ru CA:jewellerybazaar.net BR:casaebar.com.br :canossadhule.in :cansesiasknefesi.com DE:how2gethazanat.ho.funpic.de :www.evishop.de :chihuahuaupinghome.com DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | 64d2ddff53 NEW |
none[none] | none:none |
none|none | none | none |
11:39:00 | Win2K-f | 90.206.151.188 (SKY.COM): SKY BROADBAND, UK. (DSL) |
n/a | :www.maxmind.com :www.getmyip.org EU:checkip.dyndns.org 174.36.207.186:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:11:55:00 | Win2K-f | 91.195.182.240 (-): EDUCATION BRADFORD, UK. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee :telephone.dd.blueline.be JP:ufospace.etowns.net FI:194.215.38.135:80 |
135 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:12:05:00 | WinXP | 176.8.117.8 (-): . |
213.155.14.161:80 | DE:citi-bank.ru :albat.somee.com **:boemaclasic.ro TH:www2.bpp.go.th :caetanojrecruz.adv.br DE:buyukfirsat.bu.funpic.org GB:www.bsnlondon.co.uk GR:dincermakinasanayi.com.tr US:kidos-bank.ru |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.8 profile |
none | summary tarball |
none | 8c282472f0 NEW |
none[none] | none:none |
none|none | none | none |
T:13:39:00 | Win2K-f | 118.83.33.10 (HTOJ.J-CNET.JP): JCN-HTMNET, JP. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee :telephone.dd.blueline.be KR:theforums.bbsindex.com :cx10man.weedns.com :c010x1.co.cc FI:194.215.38.135:80 |
135 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
14:34:00 | Win2K-f | 62.197.79.231 (62-197-79-254.TELEDISNET.BE): TELEDISNET ISP, BRUSSELS, BRUSSELS HOOFDSTEDELIJK GEWEST, BE. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:15:16:00 | Win2K-f | 86.35.134.198 (PLATINUM-IFN.RO): ROMTELECOM DATA NETWORK, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | FI:www.if.ee EE:www.starman.ee FI:194.215.38.135:80 EE:62.65.192.24:80 |
135 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
17:51:00 | Win2K-f | 113.108.69.214 (163DATA.COM.CN): CHINANET GUANGDONG PROVINCE NETWORK, GUANGZHOU, GUANGDONG, CN. (DSL) |
n/a | :www.maxmind.com DE:131.220.6.26:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:18:33:00 | WinXP | 46.117.120.39 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
18:39:00 | Win2K-f | 177.34.47.121 (-): . |
n/a | US:www.w3.org :tyuklfzr.com :gwavrvts.com US:aoiuugkqwwi.biz :ixezvukwi.net US:dqhuqarklr.biz US:wzgdqbtqti.biz :abvfmos.com :kldrcaq.info :kwhjnbdf.info :pjptnrqe.info US:rplvfvdqndf.biz :xkgdugkmxj.net :rlxrhij.info :qpmzlerm.com :nkxsojghfw.info :wffhujdrmib.net :zwwfdmyx.info :rxnevgbeq.org US:zggjvpehrax.biz US:vweadjpvfq.biz US:mmfpfz.biz :wqcovondl.net :ndmobw.com US:vqqostozhq.biz :pbmqbunqp.info :zomrgawmbxq.org :dhdarw.com :tbztmca.net :ekeqbjuqro.com :qvflmsijf.info :rclketqinry.org :jbiemmlf.info :khzyvvcdnzz.net :jojlynrn.info :pettbdohwto.org US:dmtdnctyq.biz :swxlsntd.info :nhpwwwzcos.net US:dymgfdrb.biz :zlwgh.org US:wxtiplwvfkx.biz :nraewmail.com :klrbep.org US:yblkjspb.biz :fsdmtqus.com :zsnthjcm.org :rxavgxll.net :sfmfys.info :fiipxgyzen.org :xqghqtvzk.info US:djgxriwf.biz :bdkxw.net :vrnklxgh.org :piqjlod.org :rmdalfguog.info US:vwshigcdpog.biz :jrsafb.net :akzqnov.info :iscag.com :fjdcf.info US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:21:15:00 | WinXP | 36.224.179.91 (-): . |
n/a | DE:citi-bank.ru DK:bem.dk US:banboon.com MY:bdb.com.my TH:baulaung.org IR:bazyar-arya.com :barlikinsaat.com.tr TR:basamakhalisi.com US:kidos-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 43 | bbafbfe1df NEW |
none[none] | none:none |
none|none | none | none |