Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
01:01:00 | Win2K-f | 212.28.83.198 (-): INTERSATCOM, RU. (DSL) |
n/a | US:trafficconverter.biz US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:02:18:00 | WinXP | 219.115.226.134 (ZAQ.NE.JP): K CABLE TELEVISION CORPORATION INC, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
none:none ASM:Graph |
Armadillo| tElock| |
lines=90 lines=75 embedded dns |
trace trace |
02:41:00 | Win2K-f | 87.247.76.176 (INTURBO.LT): OPTICAL RESIDENT CLIENT POOL, KAUNAS, KAUNO APSKRITIS, LT. (DSL) |
n/a | :www.ask.com :gvswwyil.net :bcryzs.net :ndtcmqp.info :zawwfisowyz.org :fznkg.org :gzquzad.info :eugnyfbtc.org :hjauubcri.net US:wlmlilhy.biz US:cdycapfc.biz :kbhiruj.org :lwbltwssjs.com US:xsfos.biz :mpmlku.info :nzoclrcxsbd.info :rmyxp.com :inwmavyt.com US:serrpbtdq.biz :kpjgrtmn.com US:vnwenpys.biz :urehg.net US:uvekw.biz :plyhxiyfzs.net NL:lpvmkb.info :rjcwbhyq.net :qxxnxmxpr.net :iabeafe.net :qdmmrv.net :iatizdvpg.info :aqcdj.org US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
05:46:00 | Win2K-f | 89.228.116.14 (MM.PL): SZEL-SAT, OLSZTYN, WARMINSKO-MAZURSKIE, PL. (DSL) |
n/a | US:www.ask.com US:veannoevc.biz :aqcdj.org :lztsyr.info :zwwbnfo.info :sqgfwg.net :vbfwrxgh.info :plyhxiyfzs.net :sacwjfc.org US:cdycapfc.biz :kpjgrtmn.com :hakckpdafy.net :cjwpmxul.org US:wellxweu.biz US:qxriyywf.biz :ipqxvupqez.com :cwhhuwtw.net :iabeafe.net :weukutitd.org :vkyqk.info :byxqoht.org US:yadfoa.biz US:ifvbdiwe.biz :chlvkkze.com :aaabshqig.net :mjqgimmdb.org US:sbwsswx.biz :evjpe.org :gwfnmcgzude.org :eqmjc.info :ndtcmqp.info US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:08:32:00 | WinXP | 186.34.234.56 (-): . |
n/a | DE:moscow-advokat.ru SE:ozbytes.dal.net NL:diemen.nl.eu.undernet.org :caen.fr.eu.undernet.org NL:broekhuisjuweliers.nl SE:qis.md.us.dal.net TH:btech.ac.th AT:graz.at.eu.undernet.org TR:btr.gen.tr SE:viking.dal.net TR:burakasansor.com ES:bytegraf.com SE:ced.dal.net TH:nt.go.th :cizreemlak.net SE:vancouver.dal.net :brussels.be.eu.undernet.org DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |
08:51:00 | Win2K-f | 46.109.103.15 (-): . |
n/a | US:www.ask.com :nccdihmz.com :lbucfp.org :mcuplek.org :bghedm.com :gnidlirr.net :sqgfwg.net :maghdsrp.com :nwgrupkcebr.net :odctugjv.org US:nnnpag.biz US:azfjahexych.biz :hjauubcri.net :hpenvgo.com :vrjvulsnjsn.org :zaatgxrycfl.info :hakckpdafy.net :vtrubqr.com :eiczjedlgmq.info :ygqjuxbn.com :yxhfv.com US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:09:10:00 | WinXP | 94.52.71.104 (-): NEW COM TELECOMUNICATII SA, BUCHAREST, BUCURESTI, RO. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
11:56:00 | Win2K-f | 90.51.2.204 (ABO.WANADOO.FR): IP2000-ADSL-BAS, CAEN, BASSE-NORMANDIE, FR. (DSL) |
n/a | US:www.ask.com US:yhhaziym.biz :lwbltwssjs.com :agpsqu.net :gvswwyil.net :cxlno.com US:azfjahexych.biz US:sbwsswx.biz US:ifvbdiwe.biz US:dkrehwed.biz :isvhnma.org :ulkngthcgqs.net US:ljekloevcfj.biz :kxwurc.info :ndtcmqp.info US:yofaalabw.biz :aaabshqig.net :nzoclrcxsbd.info :nexvioqkwoc.info US:meflgxxvbz.biz :iubbuywish.net US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:12:01:00 | WinXP | 46.119.160.169 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:13:53:00 | Win2K-f | 117.218.62.9 (10/24.BSNL.IN): NIB (NATIONAL INTERNET BACKBONE), NEW DELHI, DELHI, IN. (DSL) |
n/a | :g.0x20.biz EE:www.starman.ee FI:www.if.ee :telephone.dd.blueline.be :phonewire.dd.blueline.be :phonelogin.dd.blueline.be JP:ufospace.etowns.net KR:theforums.bbsindex.com LT:phonewire.dnip.net GB:phonelogin.dnip.net KR:koopa.dnip.net :fx010413.whyI.org |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:15:31:00 | WinXP | 109.110.132.155 (JWS.COM): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru :albat.somee.com **:boemaclasic.ro TH:www2.bpp.go.th :caetanojrecruz.adv.br DE:buyukfirsat.bu.funpic.org GB:www.bsnlondon.co.uk GR:dincermakinasanayi.com.tr |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
15:55:00 | Win2K-f | 201.186.224.115 (-): . |
n/a | :www.maxmind.com US:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | d60e538e72 NEW |
none[3] | none:none |
UPX| | none | trace |
18:06:00 | Win2K-f | 46.120.63.154 (-): . |
n/a | CN:www.baidu.com :ishbehdns.info US:gdsnzaruzx.biz US:qyxfmm.biz US:idrdflfi.biz US:ltnjezvldec.biz :rjggyfkt.info :kwpnvl.info :ongibeflks.info :ypodfacvc.info :aiqvk.com US:yuaemjrb.biz :rzikapffs.org :jefsdnvmn.org :zlgycewl.net US:exsntmhedn.biz US:cxomxie.biz :jbahbxdhg.net :shhtcwvia.org :kfbrbe.net :wqzmytq.com :nklpuoj.net :mvqoax.org :yblobq.com :qkuxbqeu.net :cyantnvo.org :hvuhzmbentm.info :qukvmxysxa.com :hkpju.net :vfqrs.com :tdhdcwdtgur.com :asmbttvh.info :lbhurosvq.net :btymsqrx.net US:iiezzcqtdqm.biz :uuftajf.info :nfdxdgv.info DE:apeas.net :zqcplmly.com :vbuvhsnj.org US:cymshgghgn.biz US:vpzpo.biz :ycyovqhkgi.com :pmorihj.com :kjglr.info :jpgarn.net :hvbwz.info :tfjmlvgqb.com :bsiyedk.com :iknbxofkzwk.info :liezjcet.info :hrkuu.info :vsspxih.info :ofpqqriv.com :nwepgyutk.com US:oireln.biz :rrlmwwunitt.com :jtobsbarnw.net :eukbrhzhm.net :uajhvqdz.com US:qcztcmqcjk.biz US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 15 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:20:02:00 | WinXP | 218.1.65.26 (ONLINE.SH.CN): CHINANET SHANGHAI PROVINCE NETWORK, SHANGHAI, SHANGHAI, CN. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 8 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
20:59:00 | Win2K-f | 211.232.129.145 (NEXG.NET): KRNIC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
21:05:00 | Win2K-f | 1.172.181.215 (-): . |
n/a | US:trafficconverter.biz US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:23:06:00 | Win2K-f | 99.152.7.47 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, ROCKFORD, ILLINOIS, US. (DSL) |
n/a | EE:www.starman.ee US:microsoft.com FI:www.if.ee FI:194.215.38.135:80 EE:62.65.192.24:80 |
135 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |