Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
02:10:00 | Win2K-f | 85.122.43.171 (-): SC AMBAVI TELECOM SRL, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | US:www.w3.org :zqkivb.info US:ytoupasu.biz :kwpplfvycm.com :jzvnr.info :nutxyrdr.org :lmvngms.com :kopblpfv.info US:ohegg.biz :pmjan.org :addbpzm.net :khxstokfyuk.org :ezanbox.org :gwrhzwhimsx.com :ipqiqdtzl.net :aomcpwy.net :qvluumqfvdu.org US:dpijevzc.biz :xzwqxfar.net :fpthqtdjavj.info :bzwizjysv.com US:cohwuuvgipu.biz :wpmyzxge.info :gkone.com :znglaq.info :athorgyn.org :wifpc.info US:mvromizf.biz US:zoapidx.biz :pzfrfei.org :mdkwmvmkxz.info :yjhlbnnv.org US:nwjevqbnnkt.biz :zgnztevlt.info :dlaee.net :bjmtvxvfeoe.net :zexiz.info :jhextbt.org :imzbihuvnf.com US:heuuk.biz :yhlrplmgtg.info :usgzmvz.info US:xyuzsdpc.biz :xtouuxhrrq.com :gmyvquuxvvx.net :okbwkf.info US:fncrwctn.biz :iyfhjuq.com :dwomyc.info US:ognsyqxeva.biz :ofibkyjzlp.net :ayrrttlh.com :imfaqv.org :lzufvbaipme.com US:almtrucy.biz :kceldwwwb.info :zfhtyzoynyf.info US:oemjznv.biz US:ntlmugr.biz :mbqvzbe.org US:vcsisdrulj.biz US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 19 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
05:15:00 | Win2K-f | 94.61.243.94 (ROSITEHOST101.COM): S.C. ROSITE EQUIPMENT SRL, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | US:www.yahoo.com US:eflliyesnvw.biz :febnnrccdef.net US:mtrgbr.biz :vbaiulgl.net :aqqdjaiv.com :kxqilvdj.com :onfyzkjj.com :xtonvwgl.com US:ntlmugr.biz :huyzhobiaj.org :mqkgpfrw.com :lwiurlmi.org :lzufvbaipme.com :imehidk.net :yadhrd.net US:dpijevzc.biz :kuixzl.net :dijswm.org :hzflidm.net US:mvromizf.biz :qrxywbeo.net :tvswqwhboy.info :kexawtn.org :uhbcvpx.org :athorgyn.org :mdkwmvmkxz.info :janadsoswgg.com US:nwjevqbnnkt.biz :ilvlkbat.info US:nlbmiytm.biz :gljqohgc.info :jrsbnxaen.com :pmjan.org :yzetdwhqct.net US:rilfftma.biz :yhlrplmgtg.info US:erjzxgkz.biz :dczehsd.net :wpmyzxge.info :qbfgakvigo.net :cubket.com :zoxoughk.net :xwvamgwhg.com :hbxgv.com :khxstokfyuk.org :ohade.com :jkblspdq.com US:vbnmfobr.biz :twgtcpq.org :prsnstxc.org :odrgm.info :xtouuxhrrq.com :fvcvucsf.com :pxehjngvb.info :rjwfpbsbc.info :dwomyc.info :iyfhjuq.com :youulhj.info :whvwcieg.org :xxiqm.org US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:06:36:00 | WinXP | 177.35.135.210 (-): . |
213.155.14.161:80 | DE:citi-bank.ru DE:www.kelesoglugroup.com :bleublanc.net TH:kabinburi.ac.th :bilimegitim.org |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 42 | 0d1eb4df79 NEW |
none[none] | none:none |
none|none | none | none |
06:37:00 | WinXP | 201.11.154.84 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | FI:www.if.ee EE:www.starman.ee FI:194.215.38.135:80 EE:62.65.192.24:80 EE:62.65.192.25:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:06:50:00 | WinXP | 5.248.21.54 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 | 22340630ac NEW |
none[none] | none:none |
none|none | none | none |
T:07:09:00 | WinXP | 92.36.95.96 (SKYLINK.RU): MOSCOW CELLULAR COMMUNICATIONS, RU. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 1096ba143e NEW |
none[none] | none:none |
none|none | none | none |
07:13:00 | Win2K-f | 84.40.126.110 (NACKSYSTEM.NET): EU-ZZ, UK. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 15 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:07:36:00 | WinXP | 37.252.68.65 (-): . |
n/a | DE:moscow-advokat.ru :lia.zanet.net SE:vancouver.dal.net :los-angeles.ca.us.undernet.org SE:viking.dal.net NL:broekhuisjuweliers.nl :london.uk.eu.undernet.org TH:btech.ac.th :lulea.se.eu.undernet.org TR:btr.gen.tr :flanders.be.eu.undernet.org :gaspode.zanet.org.za SE:broadway.ny.us.dal.net TR:burakasansor.com AT:graz.at.eu.undernet.org DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |
08:20:00 | Win2K-f | 182.7.48.215 (-): . |
n/a | US:www.yahoo.com :xvsxjiny.net :ipqiqdtzl.net :rmvhgahdej.net US:slsex.com :jhextbt.org :bhwfzkjs.com :imehidk.net :znglaq.info US:xyuzsdpc.biz :mbqvzbe.org US:searchezy.com :tpgdvklu.net :agzvdhmok.org US:potxf.biz :vxvzfdt.org :fgoldmsyo.org US:axydefs.biz US:tstpqd.biz :zexiz.info :txgosb.org :lblxgvhpd.net US:tpwftplp.biz US:gggmsc.biz :qfkkjugklaf.net :bejislwjwh.net :vemgwwcomos.com :kceldwwwb.info US:qycxhfwv.biz US:ognsyqxeva.biz :zigbwwmnj.org :hwhcrzdpkj.info :zqkivb.info :guaijc.info :ufast.org :qrxywbeo.net :kswghlu.org :gezfuxsvvz.com :kopblpfv.info US:odankjaixg.biz :mfkss.net :tfkpeekeuei.net :xtouuxhrrq.com :aomcpwy.net US:dtagswwn.biz :odrgm.info :addbpzm.net :sgxct.com :dczehsd.net :ktrwxzsumf.com :xwvamgwhg.com :ojszjvovqgy.info :uoona.net :xocoqyb.net :uhbcvpx.org :rjwfpbsbc.info :xbwal.info :czngfegxwr.com :yhlrplmgtg.info :cyiupoodzh.com US:voizttjso.biz :wukulsca.org US:149.20.56.32:80 US:204.152.184.139:80 98.138.253.109:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:08:24:00 | WinXP | 37.252.67.81 (-): . |
n/a | DE:moscow-advokat.ru SE:broadway.ny.us.dal.net SE:coins.dal.net NL:brussels.be.eu.undernet.org NL:broekhuisjuweliers.nl :los-angeles.ca.us.undernet.org TH:btech.ac.th :gaspode.zanet.org.za SE:viking.dal.net TR:btr.gen.tr NL:diemen.nl.eu.undernet.org TR:burakasansor.com SE:ced.dal.net ES:bytegraf.com TH:nt.go.th SE:london.uk.eu.undernet.org :cizreemlak.net SE:qis.md.us.dal.net DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |
14:30:00 | Win2K-f | 195.188.250.96 (BARNSLEY.GOV.UK): BARNSLEY_MBC, LONDON, ENGLAND, UK. (100Mbps) |
n/a | US:www.w3.org US:vksiwkdj.biz :ioegztujhk.com US:okpgvdhpv.biz :bejislwjwh.net :lmvngms.com :wpmyzxge.info :ipqiqdtzl.net :qstrv.net :bzwizjysv.com :uoona.net :kxqilvdj.com :uhbcvpx.org :yctwqq.org :gkone.com :nutxyrdr.org :xredvmzck.com :bgxqmxph.com :xtonvwgl.com :royteetwr.info :okbwkf.info US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 20 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:15:38:00 | Win2K-f | 69.57.115.155 (NEFCOM.NET): NEFCOM INTERNET, DOUGLASVILLE, GEORGIA, US. (DSL) |
n/a | EE:www.starman.ee FI:194.215.38.135:80 EE:62.65.192.24:80 |
135 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:18:00:00 | WinXP | 66.234.200.72 (ASTOUND.NET): ASTOUND BROADBAND, WALNUT CREEK, CALIFORNIA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 | bcb3ec60f2 NEW |
none[none] | none:none |
none|none | none | none |
T:18:45:00 | Win2K-f | 79.228.104.76 (T-DIALIN.NET): DEUTSCHE TELEKOM AG, BERLIN, BERLIN, DE. (DSL) |
n/a | EE:www.starman.ee US:microsoft.com FI:194.215.38.135:80 EE:62.65.192.24:80 |
135 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
22:36:00 | Win2K-f | 36.224.180.96 (-): . |
n/a | :www.maxmind.com :www.getmyip.org US:checkip.dyndns.org 174.36.207.186:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:22:47:00 | WinXP | 93.157.157.142 (HISPEED.PL): USLUGI INTERNETOWE MAJESTIC, PL. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru CA:jewellerybazaar.net BR:casaebar.com.br :canossadhule.in :cansesiasknefesi.com DE:how2gethazanat.ho.funpic.de |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 43 | ca3e3b13f3 NEW |
none[none] | none:none |
none|none | none | none |