Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:03:27:00 | Win2K-f | 118.169.60.251 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee KR:theforums.bbsindex.com LT:phonewire.dnip.net GB:phonelogin.dnip.net GB:fx010413.whyI.org :commgr.co.cc |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:03:36:00 | WinXP | 114.47.196.75 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:moscow-advokat.ru SE:brussels.be.eu.undernet.org SE:broadway.ny.us.dal.net NL:broekhuisjuweliers.nl SE:qis.md.us.dal.net TH:btech.ac.th :london.uk.eu.undernet.org TR:btr.gen.tr TR:burakasansor.com ES:bytegraf.com NL:diemen.nl.eu.undernet.org DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |
03:54:00 | Win2K-f | 212.233.208.109 (OPTISPRINT.NET): OPTISPRINT INTERNET POOLS, RUSE, RAZGRAD, BG. (DSL) |
n/a | US:www.ask.com :nefqw.info :dhgsxjid.info :jrsafb.net :tbewjofqe.info :akzqnov.info :nsdwnkig.com :gwavrvts.com US:dmtdnctyq.biz US:kabakssaned.biz US:xysyexo.biz :ypqzlpiasxu.net :ukrxhdtcwcb.info :jbiemmlf.info :hvlixj.com US:xwwhfgo.biz :iamajgv.net US:dymgfdrb.biz :gqcguzpzuou.com :bkrnf.com :egnwm.com :oltvdilltgp.com :jcqkqx.info US:chmak.biz :xmnbvhas.org :swxlsntd.info :hmlte.com :nhpwwwzcos.net :kwhjnbdf.info :gukai.org :hrcwib.com US:nbhlujditfg.biz :vrgaavkqcsi.org :rnaost.info :rxnevgbeq.org :jtrryof.com :huhgvqv.net :gysdoya.info :pyfddk.info :thyux.com :mdplv.org US:nhvayb.biz :slxkdhevhnu.org :irqibb.info :abihg.com US:wxtiplwvfkx.biz :tsvoif.net US:ksvdnjq.biz :isoho.net :snttdezo.net US:wfodrl.biz :styfogxbnj.net :gvuttrin.info :orqshcazc.net :zlwgh.org US:aoiuugkqwwi.biz :euurw.info :citzwr.org :ticwn.net :glpvcr.com :ofmexwxgfa.org US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:06:48:00 | WinXP | 37.229.171.222 (-): . |
213.155.14.161:80 | DE:citi-bank.ru :cikmayedekparca.com :brucegarrod.com :cbbasimevi.com :brandaoematos.com.br **:caglarteknik.com :bharatisangli.in BR:cacs.org.br RO:butacm.go.ro EU:boyabateml.k12.tr :casbygroup.com |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 42 | 8a2553433c NEW |
none[none] | none:none |
none|none | none | none |
T:07:07:00 | WinXP | 93.102.42.172 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, PORTO, PORTO, PT. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru :albat.somee.com **:boemaclasic.ro TH:www2.bpp.go.th :caetanojrecruz.adv.br DE:buyukfirsat.bu.funpic.org GB:www.bsnlondon.co.uk |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | ed0df96d4b NEW |
none[none] | none:none |
none|none | none | none |
T:07:37:00 | WinXP | 24.155.199.47 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS CORPUS CHRISTI HUB, CORPUS CHRISTI, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
08:01:00 | WinXP | 12.193.208.2 (THOMSON.COM): THE THOMSON CORPORATION ON BEHALF OF MEDICAL ECM, STAMFORD, CONNECTICUT, US. (DSL) |
n/a | EE:www.online.if.ee FI:www.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
http 9 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
10:04:00 | Win2K-f | 128.71.86.52 (TERMBILLING.COM): VARIOUS REGISTRIES, UK. (DSL) |
n/a | CN:www.baidu.com :ofmexwxgfa.org :tceaxhawdwa.info US:nhvayb.biz :swxlsntd.info US:jqvztox.biz :hvlixj.com :feazdttnx.com :rcfpjwvd.info US:fuyxxq.biz US:hmcag.com US:rplvfvdqndf.biz :xiogxbzi.net :qvflmsijf.info :jdncrtslc.org US:fyinmmo.biz US:yhratiyxgl.biz :kmvbhvrxp.com :pyfddk.info :qyenwhxfbc.net :dyyuy.com US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 18 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
12:10:00 | Win2K-f | 212.156.115.205 (-): TURK TELEKOM TTNET NATIONAL BACKBONE, ISTANBUL, ISTANBUL, TR. (DSL) |
n/a | :www.maxmind.com :www.getmyip.org :getmyip.co.uk US:checkip.dyndns.org DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | 2daf861bde NEW |
none[3] | none:none |
Armadillo| | none | trace |
13:10:00 | Win2K-f | 195.8.46.203 (-): SC-ATIPIC-SOLUTIONS-SRL, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | :wchxmfhaplk.net :rxnevgbeq.org :mmnaroycu.net :octumrlsaj.org :khzyvvcdnzz.net :egnwm.com :ixezvukwi.net :sohwir.net US:flscqpuaw.biz :kldrcaq.info :hpljqzspvvg.org :xoqqqt.info :nsdwnkig.com :udznoy.net :sfmfys.info :jjwgubvgqa.info :kmvbhvrxp.com :dobgfkbu.info US:eiifnehz.biz :pettbdohwto.org :nraewmail.com :kqgwau.com :jojlynrn.info :jrsafb.net :jdncrtslc.org :iauopvhv.net :jcnrc.com :yvagydcw.com US:wxtiplwvfkx.biz US:fuyxxq.biz :ksyaptnyx.org :mgofiqdb.info :vyciknaaov.org US:rxthj.biz :ukrxhdtcwcb.info :cvjdafmh.com :dibmxhiv.com :rmdalfguog.info :mscweplg.net :wsjuml.info :isoho.net :hvlixj.com :xmnbvhas.org US:vweadjpvfq.biz US:jxsuv.biz :ofmexwxgfa.org :tyuklfzr.com US:gocgcf.biz :gaeghmqd.net :pbmqbunqp.info US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:13:31:00 | WinXP | 46.40.34.32 (-): . |
213.155.14.161:80 | DE:citi-bank.ru CA:jewellerybazaar.net BR:casaebar.com.br :canossadhule.in :cansesiasknefesi.com DE:how2gethazanat.ho.funpic.de :www.evishop.de :chihuahuaupinghome.com IN:dehaspas.com TR:devdijital.com |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 9276456bf8 NEW |
none[none] | none:none |
none|none | none | none |
T:14:35:00 | WinXP | 216.212.232.167 (ROSE.NET): CITY OF THOMASVILLE UTILITIES, THOMASVILLE, GEORGIA, US. (DSL) |
n/a | DE:citi-bank.ru :albat.somee.com **:boemaclasic.ro TH:www2.bpp.go.th :caetanojrecruz.adv.br DE:buyukfirsat.bu.funpic.org GB:www.bsnlondon.co.uk GR:dincermakinasanayi.com.tr |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
T:15:01:00 | WinXP | 87.14.142.71 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A. TIN EASY LITE, MONZA, LOMBARDIA, IT. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
15:25:00 | Win2K-f | 202.198.0.85 (-): JILIN AGRICULTURE UNIVERSITY, BEIJING, BEIJING, CN. (DSL) |
n/a | :www.google.com US:trafficconverter.biz US:ginsinjyam.biz :vrnklxgh.org :nkxsojghfw.info US:vwshigcdpog.biz :bkrnf.com :wsjuml.info :uywcunbxwxw.org :ebvbkjusei.org :tbztmca.net :zejhnhjg.info :lwamcr.net :subtyrnom.org :gysdoya.info :chqin.info :gsjzsksf.net :nikcbtfqt.net :rclketqinry.org :vmuzui.info :uskfnhsp.net :zomrgawmbxq.org :kldrcaq.info :ogepqdab.net :jcnrc.com US:zjurrzll.biz :cvjdafmh.com :kbrjqaut.info :styfogxbnj.net :dyyuy.com :ofmexwxgfa.org :zhwlgkwgkp.org :pbmqbunqp.info US:rplvfvdqndf.biz :ekeqbjuqro.com :dadbslww.net :jjwgubvgqa.info US:vqqostozhq.biz :bdkxw.net :rxnevgbeq.org :snttdezo.net :qvflmsijf.info :ukrxhdtcwcb.info :yvagydcw.com US:eiifnehz.biz :mdplv.org :dvqqpwoy.org :uwaqgpjyxka.org :ospvsfhodp.net :ccxpuuuxx.org :fiipxgyzen.org US:ixuckzxut.biz :thyux.com :wndmtt.net US:yblkjspb.biz US:cxrxntnubi.biz :imjwkojipcy.net :ppsevllzrn.net US:flscqpuaw.biz :isoho.net :egnwm.com :octumrlsaj.org US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:16:52:00 | WinXP | 186.34.234.56 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
18:30:00 | Win2K-f | 189.5.156.194 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, GOIâNIA, GOIAS, BR. (DSL) |
n/a | US:www.ask.com :lgrovkfk.org US:hozxhexl.biz :aonpy.net :gzvaibunc.com :xkyqmdfyowg.info :sykab.info :cqropoouwkh.net :kdhymnkazp.org :pgvbok.org :nzoclrcxsbd.info :ipqxvupqez.com :pzfshd.net :andnohj.org :daevhohgyf.info :kstzxgrmrbn.com :lljofdfytoo.com US:kfmvtms.biz :ixisj.info :fbmpklko.net :iatizdvpg.info US:gxrrkaoihi.biz :ulkngthcgqs.net :wqqhbvr.org :fyjbbo.info :krpsz.org :kpjgrtmn.com :maghdsrp.com :sqgfwg.net :zodmfukq.info US:meflgxxvbz.biz US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:56:00 | Win2K-f | 79.45.49.30 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA NET, BERGAMO, LOMBARDIA, IT. (DSL) |
n/a | :www.maxmind.com :getmyip.co.uk :www.getmyip.org EU:checkip.dyndns.org DE:131.220.6.26:80 US:204.152.184.139:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:20:35:00 | WinXP | 87.14.142.71 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A. TIN EASY LITE, MONZA, LOMBARDIA, IT. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:23:46:00 | Win2K-f | 77.253.142.191 (INETIA.PL): INTERNETIA, WARSAW, WARSZAWA, PL. (DSL) |
n/a | US:microsoft.com :telephone.dd.blueline.be EE:www.starman.ee FI:www.if.ee :phonewire.dd.blueline.be :phonelogin.dd.blueline.be JP:ufospace.etowns.net KR:theforums.bbsindex.com LT:phonewire.dnip.net GB:phonelogin.dnip.net KR:koopa.dnip.net :gynoman.weedns.com :commgr.co.cc |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |