Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
01:13:00 | Win2K-f | 27.73.57.197 (-): . |
n/a | :www.maxmind.com :getmyip.co.uk :www.getmyip.org EU:checkip.dyndns.org 174.36.207.186:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:02:37:00 | WinXP | 37.5.158.32 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
04:08:00 | Win2K-f | 121.65.232.163 (-): BORANET, KR. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:04:19:00 | WinXP | 2.195.165.129 (-): . |
213.155.14.161:80 | DE:citi-bank.ru :www.kelesoglugroup.com :bleublanc.net TH:kabinburi.ac.th :bilimegitim.org :juvenopolis.org.br PT:buyukkarapinar.com EU:karenoil.com US:cajovnanazemi.cz **:beautiful-shop.rv.ua :cannabisverificationcenter.com US:clinicadematematica.com.br US:construindia.com |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.8 profile |
none | summary tarball |
none | fca087c49d NEW |
none[none] | none:none |
none|none | none | none |
07:53:00 | Win2K-f | 212.5.134.96 (-): ET UNACS - IURI JORDANOV BOURGAS, BURGAS, BURGAS, BG. (DSL) |
n/a | US:www.ask.com :vffismiqtg.info :yjlyd.org :wvtxq.org :dnlllmujy.com US:ueeiykzyt.biz :fjoklawb.com :ktbhuca.org :sblub.info :cducgghwbqi.net :xfvnifizu.org :lkiev.com :rnskk.org :tponztmngs.net :znkgrblysw.com :tuauivryrt.info :edybhz.org :bbibla.org US:uttdbtyjro.biz US:opxbemyw.biz US:tcaxezad.biz US:vnsfebjz.biz :uffhyheegt.net :qqpnefjc.net :pcsyha.info :vxylnbqnre.com :gzfdfnrrzwz.com :viwwabszzu.info :cetzbmbgc.org :pdxjvp.com :edxmrqmwhbb.com US:hufxnldv.biz :wkfieyi.org :ljgbte.com :ydgevojfelq.com US:aflrc.biz :fmyxwd.com US:xzdjsxfv.biz US:magrszum.biz :irjdslvkmw.org :amvwcm.org :ntvfio.org :fngbkj.org :krcbqnaa.com :ibhprjohnq.com :czqdl.net :ipnvzjbz.info US:hpjpkoytq.biz US:wrlkexgcd.biz :dtvkpoxw.org :ohirufmba.org US:itmrcbi.biz US:lyduqapppgb.biz US:wfyaj.biz US:pqkep.biz :onjvuxmh.info PT:pynxd.info US:lcoiie.biz :wpqpy.org :ydcfesbutuc.org :yvyxf.com US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:08:59:00 | WinXP | 117.254.82.230 (STERLINGSTUDENTS.NET): NIB (NATIONAL INTERNET BACKBONE), NEW DELHI, DELHI, IN. (DSL) |
n/a | DE:citi-bank.ru :albat.somee.com **:boemaclasic.ro TH:www2.bpp.go.th :caetanojrecruz.adv.br DE:buyukfirsat.bu.funpic.org GB:www.bsnlondon.co.uk GR:dincermakinasanayi.com.tr :adult-empire.com DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
T:10:50:00 | WinXP | 93.157.153.1 (HISPEED.PL): USLUGI INTERNETOWE MAJESTIC, WARSAW, WARSZAWA, PL. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
14:04:00 | Win2K-f | 222.36.58.54 (HERBALQC.COM): CHINA RAILWAY TELECOMMUNICATIONS CENTER, BEIJING, BEIJING, CN. (DSL) |
n/a | US:www.yahoo.com :cducgghwbqi.net :ohirufmba.org US:babhflnn.biz :jwlijycb.net :viwwabszzu.info :wkwkrwdxzym.com :pcpsv.info :nhdcgzrmyap.info US:uofilxrdci.biz :narvhlpfh.com :vuvzeckamz.com US:uttdbtyjro.biz :dnlllmujy.com :frqeqyfh.com :kgmbjieizdh.org :mfuipq.info US:hpjpkoytq.biz :ugogkoppuex.net :kteixhxrfnv.com :zlcydrep.net :firyceyx.org :fjoklawb.com :edxmrqmwhbb.com US:wgiixqnv.biz :ddppldpa.org :nwrsfplorn.org :azpiwvkhlq.info :bktzxtdq.org :vaebwhof.org US:wrlkexgcd.biz :myrhzu.com :yjlyd.org :mkrzbhplv.com :exmsttodx.org :lkiev.com US:pmgfezcl.biz :amvwcm.org US:fnejei.biz :ojlsjyov.org :vgfwu.info :irqcbycg.net :kfyndnghsg.org :ysqsarxe.info :qbhxeuuqzt.org :wpkmr.info :sucqvxrx.com US:ukahawt.biz :gprbwovnxq.org US:aylyctzy.biz :iedtdgm.info US:vnsfebjz.biz :sgaticzoenr.org :fqbsp.net :cgwxmngcmo.org US:yigvelye.biz :uqpwawrp.com :bgxjophnzjk.net :yzgivck.org :ksyjvyq.info :ugoitn.com US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
17:09:00 | Win2K-f | 87.107.121.156 (AZARABENERGY.COM): SOROUSH AUDIO VISUAL COMPANY, IR. (DSL) |
n/a | US:www.yahoo.com :bdlhfl.com :bhduonr.org :qxmugdcxr.net :dojforvurgv.com :bshwbrr.org US:xzzbmqrflvy.biz :dtrqg.net :wvdbsdrjt.com :powlop.net :cczers.com US:rncxk.biz US:rsfbqwugp.biz :urwcbfd.org :kxmwmodg.net :xbjsuozs.com US:ybtkmhnemu.biz :pjdqaehbkfl.org :rhvud.net US:tuqmtm.biz :iyknoogun.info :cnjbviie.info :xgvyxbyi.info :huuzdgoru.org :mhthmuhx.info :bkuytfxf.info :jforropolrm.com :gaedentq.com :omwjojuz.net :aunzuigq.org :fhxkyr.net US:dqmgxavtf.biz :apynnvcrulf.com :aayriepb.net :opohhgyoabd.com :kasdnu.info :mvbxkxqij.net US:leiondwq.biz :fapgdhjey.info :uchqotcewro.net :gzlspr.org :wwnwa.info US:snojxd.biz :stktd.info US:fclizxruj.biz US:nbypp.biz :rvsjnoqoy.net US:lcdvnha.biz US:jmfgzn.biz US:qkkosshg.biz :wgfieg.net US:bxhsijmtr.biz :hvwkzex.com :blqgklupa.org :yhmzaxlbp.com US:padnehimiak.biz :pjodfphrr.info :dlsfi.com US:fuahxgxx.biz US:rumfft.biz :jvxqitlrz.info US:204.152.184.139:80 98.138.253.109:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
17:36:00 | Win2K-f | 41.72.37.245 (-): . |
n/a | :www.maxmind.com EU:checkip.dyndns.org 174.36.207.186:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:21:09:00 | WinXP | 42.74.186.243 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
22:21:00 | Win2K-f | 115.119.126.110 (VSNL.NET.IN): INTERNET SERVICE PROVIDER, IN. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 11 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:22:22:00 | WinXP | 66.234.192.8 (ASTOUND.NET): ASTOUND BROADBAND, WALNUT CREEK, CALIFORNIA, US. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 | bcb3ec60f2 NEW |
none[none] | none:none |
none|none | none | none |
22:27:00 | Win2K-f | 185.9.157.81 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |