Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
03:21:00 | Win2K-f | 79.67.236.180 (AS9105.COM): TISCALI UK LTD, MANCHESTER, ENGLAND, UK. (DSL) |
n/a | US:www.ask.com :vfqrs.com :jttohmnjq.net US:cxomxie.biz :irqtasoer.com :igaonpeju.org :euvvadquvvh.com US:pittlze.biz US:zfgwgeg.biz :sptnqw.net :ongibeflks.info :fzvsht.net :btymsqrx.net :ifbrdzbbl.com US:zpvansphl.biz :bmfqxle.com :njmfw.info :lypshcelq.org :myrbfsamgg.net :zrqipl.net US:gcullb.biz :anbxng.net :mzdhtfmagjy.info US:dtsgyeawkd.biz :siddvpnoquz.info :dfruo.com :vwnku.org :rdfwqqhvz.info :mvqoax.org :ikcjdkocgg.net :rzikapffs.org US:xwzsxwva.biz US:vpzpo.biz US:qyxfmm.biz :hpufsx.org US:cymshgghgn.biz :zjdzanpsrx.org :nvrolzs.org :vsspxih.info US:aicfwqknuyg.biz US:zjmfvclxs.biz US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:03:37:00 | Win2K-f | 80.180.106.120 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A. TIN EASY LITE, MILANO, LOMBARDIA, IT. (DSL) |
n/a | EE:www.starman.ee US:microsoft.com FI:194.215.38.135:80 EE:62.65.192.24:80 EE:62.65.192.25:80 |
139 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:04:46:00 | WinXP | 178.150.178.37 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | 488d27fe97 NEW |
none[none] | none:none |
none|none | none | none |
06:26:00 | Win2K-f | 220.141.172.236 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:www.ask.com :msxvuptwr.net :azevcytm.com :zcyurvt.com :njetvbjaga.info :tqjtgyrw.com US:gdsnzaruzx.biz :mjfljswzk.org :gafzr.info :liezjcet.info :hrkuu.info :ypodfacvc.info US:qyxfmm.biz :txattdblsmq.org :mtumlbpuvpu.org :nqqvzlzyit.com US:xcgeq.biz :dhbpii.org :pgmoungqxrm.net :votpacnkra.org US:sxdkj.biz :rdhmidr.info US:aicfwqknuyg.biz :rzikapffs.org :acbxoy.net :myrbfsamgg.net :gaypwoeufs.info US:idrdflfi.biz :nzyaslr.org :ujrrbg.com :cjpuh.info :ctuenpco.net :mrejxy.info :tdhdcwdtgur.com :zymwrlcoevx.com :shhtcwvia.org US:jhkcygjucl.biz :culskvbj.info :ifbrdzbbl.com :xmcyb.info US:exsntmhedn.biz US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
09:32:00 | Win2K-f | 193.27.215.118 (ISINET.RU): NETWORK FEDERAL AGENCY ON EDUCATION, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | :www.google.com US:meptr.biz :nxrdcoagox.com :otgbim.info :ishbehdns.info :njdvgcgeiq.org :tdhdcwdtgur.com :ozgdtuipme.net :hpufsx.org :glscnhwp.info :gafzr.info :zcogddnxo.info :dfruo.com :heenapatai.net :vbuvhsnj.org :yyacecdf.org :gubgednqkp.org :vreosbfb.org :hxoygv.com :bdcro.com :wuwcc.info US:bivgdn.biz US:sxdkj.biz :gmbwoqeuh.org US:dtsgyeawkd.biz :zlgycewl.net :qfuzs.com US:sawhun.biz :wqzmytq.com :chuuufzzckt.org US:lcookgba.biz US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:10:07:00 | Win2K-f | 95.37.133.76 (MTS-NN.RU): NETWORK FOR PPPOE CLIENTS TERMINATIONS IN, NIZHNIY NOVGOROD, NIZHEGOROD, RU. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee |
445 | pcap | raw alerts ruleset |
irc 4 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:10:15:00 | Win2K-f | 2.95.76.115 (-): . |
n/a | EE:www.starman.ee FI:www.if.ee FI:194.215.38.135:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
irc 5 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:10:38:00 | WinXP | 92.36.23.174 (SKYLINK.RU): MOSCOW CELLULAR COMMUNICATIONS, RU. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:12:31:00 | WinXP | 186.34.234.56 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
12:36:00 | Win2K-f | 200.29.239.74 (CONSULNETWORKS.COM.CO): CONSULNETWORK LTDA, CALI, VALLE DEL CAUCA, CO. (DSL) |
n/a | :www.ask.com :kjglr.info :lktyrrcekgr.info :dxsugno.info :vxkejecp.org :wuwcc.info :wswqzqywpwj.org US:jxgvrb.biz :xurcbghdzr.info :yjnnsdvblvs.info US:evrxeodocu.biz :jtobsbarnw.net :ikcjdkocgg.net :dmxpsfksre.com :njetvbjaga.info US:xwzsxwva.biz :eukbrhzhm.net :tdhdcwdtgur.com :emfmraj.org :jttohmnjq.net :irqtasoer.com :czadknumbs.info :rrlmwwunitt.com :engfdhco.com :xmcyb.info :pkdumejhv.org US:ghiyzb.biz :gafzr.info :fbsmwq.net :njmfw.info :jpgarn.net US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:13:11:00 | WinXP | 91.64.46.166 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BERLIN, BERLIN, DE. (DSL) |
n/a | DE:moscow-advokat.ru :london.uk.eu.undernet.org NL:brussels.be.eu.undernet.org :caen.fr.eu.undernet.org SE:qis.md.us.dal.net SE:broadway.ny.us.dal.net :washington.dc.us.undernet.org SE:vancouver.dal.net NL:diemen.nl.eu.undernet.org :lia.zanet.net SE:ozbytes.dal.net :lulea.se.eu.undernet.org SE:viking.dal.net SE:coins.dal.net :gaspode.zanet.org.za DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 1511a3f219 NEW |
none[none] | none:none |
none|none | none | none |
15:09:00 | Win2K-f | 79.175.160.126 (-): AFRANET DATACENTER SERVICES, IR. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
15:15:00 | Win2K-f | 79.44.198.33 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA NET, MACERATA, MARCHE, IT. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
15:21:00 | Win2K-f | 190.209.73.149 (-): TELMEX CHILE S.A HFC, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:17:06:00 | WinXP | 177.143.165.205 (-): . |
n/a | DE:citi-bank.ru :www.kelesoglugroup.com :bleublanc.net TH:kabinburi.ac.th :bilimegitim.org |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
38 of 42 | 0d1eb4df79 NEW |
none[none] | none:none |
none|none | none | none |
18:47:00 | Win2K-f | 178.75.246.95 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | :www.google.com :xgggyhgbpuk.info :btufvxtnxo.org :szemuzrd.com :axbaf.net :buyeautin.org :quyizkmd.com :vnzaulia.net :rjjilpgv.net :uuqliedhn.info US:iobvgswmux.biz US:mkmkxbnyc.biz :oyeslywgx.com US:yqpirrohi.biz :mlaasmeb.com :vwbtkhfim.info :zetkrk.net :agzvpl.com :xrytaask.net :ydfnnse.net :tkjyeeip.org :jikluiwuew.com :wjajeetloj.net US:bhgwzfwfukx.biz :ccumkoqtlki.net :khiec.org :czqanplyh.net :twzquxqt.com US:nmtfob.biz :ryyprjchdly.net :gzhxlbls.net :ysxqbjt.net :adubgubby.info :boomdrhaup.org :tcxsdqv.info :oqvpz.net :bukrzzbnfcw.com :tiaysqid.info :vzgkmik.net US:audyutc.biz :yekmra.info :mpahsj.net :wuosgdnjmku.net :leqbit.info :acqmamzezj.info US:ftolacwfx.biz US:fnlpnybtvj.biz :ihcthuogcm.info :vagkmnwjxrm.com :bwtwj.org :esxbb.info :cryusf.com :gdddfd.net US:vdoomzln.biz :ogtalvxs.org :etkerc.com :ngasnk.net :bkwskvksva.net :ovrtbv.info :cmzvusyhvt.org :fxtyzo.net US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:22:54:00 | WinXP | 46.162.196.51 (-): . |
n/a | DE:moscow-advokat.ru SE:coins.dal.net :flanders.be.eu.undernet.org SE:ced.dal.net NL:diemen.nl.eu.undernet.org SE:ozbytes.dal.net NL:broekhuisjuweliers.nl :caen.fr.eu.undernet.org TH:btech.ac.th SE:brussels.be.eu.undernet.org TR:btr.gen.tr :london.uk.eu.undernet.org TR:burakasansor.com ES:bytegraf.com SE:vancouver.dal.net TH:nt.go.th SE:qis.md.us.dal.net :cizreemlak.net DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |