Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:03:14:00 | WinXP | 5.140.70.175 (-): . |
n/a | DE:moscow-advokat.ru NL:brussels.be.eu.undernet.org :lia.zanet.net SE:vancouver.dal.net CA:jewellerybazaar.net :caen.fr.eu.undernet.org :gaspode.zanet.org.za BR:casaebar.com.br AT:graz.at.eu.undernet.org :canossadhule.in :washington.dc.us.undernet.org :los-angeles.ca.us.undernet.org SE:ced.dal.net :cansesiasknefesi.com DE:how2gethazanat.ho.funpic.de SE:coins.dal.net :www.evishop.de :chihuahuaupinghome.com IN:dehaspas.com TR:devdijital.com :flanders.be.eu.undernet.org US:sobrenaturalbr.net SE:london.uk.eu.undernet.org BR:direitopublico.com.br SE:ozbytes.dal.net SE:broadway.ny.us.dal.net DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 180f0e331e NEW |
none[none] | none:none |
none|none | none | none |
T:06:11:00 | WinXP | 78.9.2.34 (NET.PL): DYNAMIC BROADBAND SERVICES, WROCLAW, DOLNOSLASKIE, PL. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 038c63c8d5 NEW |
none[none] | none:none |
none|none | none | none | |
08:29:00 | Win2K-f | 92.247.223.207 (SPNET.NET): SPNET, BG. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 20 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:09:23:00 | WinXP | 94.52.71.104 (-): NEW COM TELECOMUNICATII SA, BUCHAREST, BUCURESTI, RO. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru :adult-empire.com |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
09:33:00 | Win2K-f | 60.248.166.7 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:09:52:00 | WinXP | 37.114.171.255 (-): . |
213.155.14.161:80 | DE:citi-bank.ru :onuryildiz.net.tr AR:cadenauocraradio.com.ar :tusemiletisim.com US:leobrn.com CA:nicoladiconstruct.ro |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 19045bb749 NEW |
none[none] | none:none |
none|none | none | none |
10:13:00 | Win2K-f | 190.24.216.236 (ETB.NET.CO): ETB - COLOMBIA, SANTAFé DE BOGOTá, DISTRITO ESPECIAL, CO. (DSL) |
n/a | US:www.ask.com :ryyprjchdly.net :xmesryhef.net :oqvpz.net :kefloqvenyw.info US:zeozgcr.biz :hvtomv.org US:odiqy.biz US:bfuoecn.biz :pjdqhymjsom.org :lxxujkcvh.net :kibijewr.net :osjxyoeu.com :uaocqdar.info :mlpfomk.info :vwqpdbr.info US:nsquoqq.biz :acfhizpbq.org :bwtwj.org :pexenpzi.net :iqohcbr.net :tiaysqid.info US:jebxvrdy.biz :vqmjlmw.info :leqbit.info US:sxxwad.biz :ssdwlkr.net :mzddb.org US:cdbfaqkk.biz :tcxsdqv.info US:swlbzxgm.biz :flomsjnpjo.com :nmzrq.net :fpqulaht.com :vwvsoicf.org US:dktglmlcd.biz :bpggxivfhhy.org :odagxeaqs.net :uplfdovbd.com :ogbkidsb.info :wuosgdnjmku.net US:ftolacwfx.biz :ngasnk.net :kxnvcjxra.info US:ucortsmpd.biz :riiqsxk.info :ayyglnauhw.net :dmcefvv.info :wkqpsd.net :olvenyf.org :ficfu.info US:nmtfob.biz US:jjqcuzmnt.biz US:hjwnty.biz US:kkmzzq.biz :czqanplyh.net :rtdhujqgb.org :quyizkmd.com US:vdoomzln.biz :gdxbgkl.org :kjjdvr.org US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:10:31:00 | WinXP | 41.70.188.56 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.8 profile |
none | summary tarball |
41 of 42 | 22340630ac NEW |
none[none] | none:none |
none|none | none | none |
T:11:46:00 | WinXP | 209.87.249.126 (STORM.CA): STORM INTERNET SERVICES, CA. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 154 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
12f8f0ec3a NEW e2864c150c NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:12:12:00 | Win2K-f | 109.87.5.11 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee US:g.0x20.biz :telephone.dd.blueline.be KR:theforums.bbsindex.com :cx10man.weedns.com |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:13:10:00 | WinXP | 92.247.237.218 (SPNET.NET): SPNET, SOFIA, GRAD SOFIYA, BG. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:14:52:00 | WinXP | 37.114.129.100 (-): . |
213.155.14.161:80 | DE:citi-bank.ru :onuryildiz.net.tr AR:cadenauocraradio.com.ar :tusemiletisim.com US:leobrn.com |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 19045bb749 NEW |
none[none] | none:none |
none|none | none | none |
T:15:28:00 | WinXP | 46.119.197.9 (-): . |
n/a | DE:moscow-advokat.ru SE:coins.dal.net :gaspode.zanet.org.za SE:broadway.ny.us.dal.net :lulea.se.eu.undernet.org SE:ced.dal.net **:arqdesigngv.com.br PT:asch-bourj.org US:asli.gencbeta.com :los-angeles.ca.us.undernet.org DE:asmadania.com SE:ozbytes.dal.net :ataguryapi.com :washington.dc.us.undernet.org :lia.zanet.net TR:atra.com.tr SE:qis.md.us.dal.net EU:armagida.net :flanders.be.eu.undernet.org :caen.fr.eu.undernet.org NL:diemen.nl.eu.undernet.org TR:akdenizforeigntrade.com :brussels.be.eu.undernet.org NL:london.uk.eu.undernet.org DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
38 of 43 | af614537c1 NEW |
none[none] | none:none |
none|none | none | none |
16:23:00 | Win2K-f | 171.242.123.161 (BURNERSYSTEMS.COM): VARIOUS REGISTRIES, UK. (DSL) |
n/a | US:www.ask.com US:sxxwad.biz :jgjfurua.info :bhvecyj.org US:llguqnnk.biz :bukrzzbnfcw.com :osjxyoeu.com :ayyglnauhw.net :imbqkbcrn.org :cryusf.com US:audyutc.biz :flomsjnpjo.com :gzhxlbls.net :dkyeoi.org :hmzky.org :vagkmnwjxrm.com :bpggxivfhhy.org :cgawneghw.org :pexenpzi.net :szemuzrd.com :nmzrq.net :jikluiwuew.com :leqbit.info :eqobzzfpsfn.info :ppqorhzes.org :odagxeaqs.net :jhtpaisc.org US:kkmzzq.biz :nsfhoelz.org :esxbb.info :ficfu.info :cmzvusyhvt.org :wfjgmq.org :oxuyoccnf.com :odmiyij.info :vioyjpgk.org :twzquxqt.com :iqohcbr.net US:hjwnty.biz :uplfdovbd.com US:lwvsnjo.biz US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:28:00 | Win2K-f | 113.74.127.100 (JWS.COM): CHINANET GUANGDONG PROVINCE NETWORK, GUANGZHOU, GUANGDONG, CN. (DSL) |
n/a | US:trafficconverter.biz :www.yahoo.com US:dwkinplcl.biz :vgfwu.info US:fnejei.biz US:aylyctzy.biz :vxylnbqnre.com :wzwxbitbdx.info US:vnsfebjz.biz US:tgjvsca.biz :amvwcm.org :pcpsv.info :cducgghwbqi.net US:ftvitvmh.biz US:wrlkexgcd.biz :frqeqyfh.com US:vwtyix.biz :wsmhcqdvy.info :fqbsp.net :lqesfjar.net :iodvye.org US:nnhvvywy.biz :tirylfbyjsj.com :yzgivck.org US:uofilxrdci.biz US:babhflnn.biz US:aflrc.biz :fngbkj.org :bbibla.org :eacbcsv.org :gyvofo.com :narvhlpfh.com :foydrr.net :wdjdzacy.org :irjdslvkmw.org :lvojlaqf.org :gzfdfnrrzwz.com :jtduc.com :yjlyd.org :vcfjoxoln.net :sucqvxrx.com :gzwgdgnpu.com US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
22:34:00 | Win2K-f | 193.226.37.161 (ROEDU.NET): DEPARTMENT OF COMPUTERS UNIVERSITY OF CRAIOVA, RO. (DSL) |
n/a | CN:www.baidu.com :sjuoulmfq.info :mzplvcwt.org :ysqsarxe.info US:hufxnldv.biz :mbzikc.org :jltnkvqf.com US:dwkinplcl.biz :tirylfbyjsj.com :flanagzu.org :biyjwndtbpy.org US:lcoiie.biz :qcfyzorb.org :uybszrzoyv.info :rzshzedq.com :eacbcsv.org US:itmrcbi.biz :plkqt.org :krcbqnaa.com :ojlsjyov.org US:lyduqapppgb.biz US:204.152.184.139:80 CN:220.181.111.147:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |