Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:37:00 | Win2K-f | 189.14.174.61 (PLUGIN.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
01:28:00 | Win2K-f | 103.6.238.125 (-): . |
n/a | :www.maxmind.com :getmyip.co.uk :www.getmyip.org EU:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | 917c085aca NEW |
none[3] | none:none |
Armadillo| | none | trace |
01:52:00 | Win2K-f | 78.63.64.135 (ZEBRA.LT): LIETUVOS-TELEKOMAS, VILNIUS, VILNIAUS APSKRITIS, LT. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
04:02:00 | Win2K-f | 187.79.243.21 (CAMPUSEAI.ORG): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | :www.ask.com :iadvu.info :aobqx.org :gfrapfhx.org :mfgvi.com :jhkrkfwi.info :gzzpfy.org :mhsyzhx.com US:vjggzy.biz :qkntki.org US:fflplwt.biz :tjtoh.com :ddjawyvhln.org :xouabsky.info :khbfz.net :tmuoaxpmdo.com :nwnazcl.org :kthlnqyy.org US:wqyzw.biz US:pnpfzfue.biz US:iktdr.biz :mtdqlz.info :cmdmamacvdh.org :muducxgt.com :lrwks.net :mhtgjqfaqg.com :dlbladah.org :vmjwimwy.com US:yfovkvhvkju.biz :locpiizrah.net :noxbrwzlwu.info :jsoidtw.org :rtkhwrjhq.net :oifiio.org :cjpukmro.org :rhnccqcm.net :dwuaxk.net :vxqsrx.net :kdrqwj.org :mnpdfwvmk.info :lgftmr.com :qpkjh.net US:cwgpqqndxm.biz US:lxhchrr.biz :gegbavxhk.info :lxismq.net :njzwheafj.net :gpfawifazii.org :yuzxyc.net :teyrptjhc.org US:ozilxzdi.biz :cwficrgia.org :hdypwy.com :xurfxcnr.org :cxhdpukm.net :mblyier.com :bjivw.com :aihyyvx.info US:guajclww.biz :ocjxqjhxd.net :jzbxh.net US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:05:37:00 | WinXP | 122.26.179.218 (OCN.NE.JP): OPEN COMPUTER NETWORK, YOKOHAMA, KANAGAWA, JP. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 0ab0d85629 NEW |
none[none] | none:none |
none|none | none | none |
T:06:14:00 | WinXP | 95.84.207.229 (OSTROV.NET): NATIONAL CABLE NETWORKS, RU. (DSL) |
n/a | PT:siliconfireware.ru :wpad :www.proxy-socks.net PT:195.22.26.236:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee NEW |
none[0] | none:none |
ASPack| | lines=298 embedded dns |
trace |
07:07:00 | Win2K-f | 92.36.221.152 (NET.BA): BH TELECOM D.D. SARAJEVO, SARAJEVO, FEDERATION OF BOSNIA AND HERZEGOVINA, BA. (DSL) |
n/a | US:www.yahoo.com :yeyljrd.com :xzhggp.net :ndvljz.net :ppbadcbm.net :jhcwfwdo.org :rtkhwrjhq.net :csfzhln.info US:mtvrxumb.biz :dwnprenl.net :cmaop.net :zysey.info :jvzuiza.net :cjuam.info :qvovttc.com :xurfxcnr.org :aihyyvx.info :mtdqlz.info :wzucthqgjdh.com US:vjggzy.biz :irljrwiko.info :www.maxmind.com EU:checkip.dyndns.org US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:09:39:00 | WinXP | 95.84.207.229 (OSTROV.NET): NATIONAL CABLE NETWORKS, RU. (DSL) |
n/a | PT:siliconfireware.ru :wpad EU:new.egg.com EU:www.egg.com :metrics.ybs.co.uk PT:195.22.26.236:80 |
445 | pcap | raw alerts ruleset |
http http 32 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee NEW |
none[0] | none:none |
ASPack| | lines=298 embedded dns |
trace |
10:28:00 | Win2K-f | 78.8.206.177 (NET.PL): DIALOG, WROCLAW, DOLNOSLASKIE, PL. (DSL) |
n/a | :www.maxmind.com US:checkip.dyndns.org DE:131.220.6.26:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:13:36:00 | WinXP | 70.60.132.174 (RR.COM): ROAD RUNNER HOLDCO LLC, COLUMBUS, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:13:36:00 | WinXP | 181.16.32.128 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
14:29:00 | Win2K-f | 181.16.32.128 (-): . |
n/a | :www.maxmind.com :www.getmyip.org :getmyip.co.uk US:checkip.dyndns.org DE:131.220.6.26:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:15:55:00 | WinXP | 181.16.32.128 (-): . |
213.155.14.161:80 | DE:citi-bank.ru US:kidos-bank.ru |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:18:02:00 | WinXP | 221.121.241.136 (CCNW.NE.JP): CHUBU CABLE NETWORK COMPANY INCORPORATED, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 88 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 none |
53bfe15e91 NEW c5f5a81c60 NEW |
1473091351 [0] none [none] |
ASM:Graph none:none |
tElock| none|none |
lines=75 embedded dns none |
trace none |
18:38:00 | Win2K-f | 117.211.14.56 (10/24.BSNL.IN): NIB (NATIONAL INTERNET BACKBONE), NEW DELHI, DELHI, IN. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:45:00 | Win2K-f | 178.20.225.38 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:52:00 | Win2K-f | 79.44.199.10 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA NET, MACERATA, MARCHE, IT. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 23 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:00:00 | Win2K-f | 217.21.220.77 (-): PRMSTR-NET, MOSCOW, MOSCOW CITY, RU. (100Mbps) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 23 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:07:00 | Win2K-f | 187.39.87.77 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:14:00 | Win2K-f | 82.198.111.107 (CLIENTE-82824.IBERBANDA.ES): IBERBANDA-MERCURIO, CADIZ, ANDALUCIA, ES. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:22:00 | Win2K-f | 201.53.250.163 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:30:00 | Win2K-f | 114.41.101.38 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:44:00 | Win2K-f | 72.87.174.108 (VERIZON.NET): VERIZON INTERNET SERVICES INC, ONTARIO, CALIFORNIA, US. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:52:00 | Win2K-f | 80.93.210.47 (-): MURAT AVCI, ISTANBUL, ISTANBUL, TR. (100Mbps) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 23 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:58:00 | Win2K-f | 118.166.121.229 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:06:00 | Win2K-f | 182.52.48.105 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:13:00 | Win2K-f | 85.255.175.3 (-): SATNET-NETWORK, SOFIA, GRAD SOFIYA, BG. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:21:00 | Win2K-f | 31.184.173.90 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 23 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:29:00 | Win2K-f | 114.45.46.197 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 23 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
21:14:00 | Win2K-f | 142.4.53.7 (-): DEPARTMENT OF HEALTH (CANADA), CA. (DSL) |
n/a | :www.google.com :apwqmuafevz.net US:mdlpmpce.biz US:hpfzuena.biz :ilfdnbk.net :fxcnfpzdlvd.com :bqgpqce.org :bhkptqqz.net :rixpjopw.info :psacljod.info :xgzskybm.com :zzgbsube.info :igbtn.info :qzkhwpu.org :mtvscsbn.info :pfosw.net :xctljjjutss.com :hhagn.info :zrpmtfalsiy.net :kfeaijxwjz.net US:ehudner.biz US:snilwlqjzj.biz :elmundmod.org :gyrxeern.com US:rfqgbjhve.biz :gmrpcpf.org :gxwjmsoiw.com US:jfgnx.biz US:devhtlsta.biz US:hnyfgfacyk.biz :drxwsrqb.com US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |