Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
02:20:00 | Win2K-f | 188.209.227.160 (TIM.RO): JUMP NETWORK SERVICES S.R.L, RO. (DSL) |
n/a | US:www.ask.com :fjqlerguki.info US:itnimcr.biz US:vwlafbxdv.biz :ruxycmrt.org :yndgsqra.org :ggkyybi.com :vpnctjqknk.net US:scnehqius.biz US:gcrtifef.biz US:nckmtszbjlw.biz US:fuvsx.biz :rlvajqg.net :opmfqwlj.org :pwqscpxwih.com :voqeoouf.info :vaunn.net US:ztfcqbkvw.biz :biuobhmqp.info :tsmnxxax.net :mkmyjg.com US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:02:36:00 | WinXP | 42.70.197.71 (-): . |
213.155.14.161:80 | DE:citi-bank.ru US:kidos-bank.ru |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
05:12:00 | Win2K-f | 179.235.3.33 (-): . |
n/a | EE:www.starman.ee FI:www.if.ee EE:www.online.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.25:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
05:32:00 | Win2K-f | 117.239.50.211 (10/24.BSNL.IN): NIB (NATIONAL INTERNET BACKBONE), NEW DELHI, DELHI, IN. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 EE:62.65.192.25:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
05:37:00 | Win2K-f | 80.230.113.151 (INTER.NET.IL): SMILE INTERNET GOLD, TEL AVIV, TEL AVIV, IL. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee FI:194.215.38.135:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
05:42:00 | Win2K-f | 95.155.60.157 (CRNAGORA.NET): INTERNET CRNA GORA D.O.O, ME. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
05:47:00 | Win2K-f | 95.26.99.49 (CORBINA.NET): INVESTELEKTROSVIAZ LTD, RU. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee FI:194.215.38.135:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
05:52:00 | Win2K-f | 85.121.148.62 (SKYCONNECT.RO): SC SKY NET COMPUTERS SRL, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:07:28:00 | WinXP | 79.121.70.109 (SUPRAKTV.HU): SUPRA KABELTELEVIZIOS KERESKEDELMI ES SZOLGALTATO KFT, BUDAPEST, BUDAPEST, HU. (DSL) |
n/a | DE:citi-bank.ru CA:jewellerybazaar.net BR:casaebar.com.br :canossadhule.in :cansesiasknefesi.com DE:how2gethazanat.ho.funpic.de :www.evishop.de :chihuahuaupinghome.com IN:dehaspas.com DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | bb460ddce2 NEW |
none[none] | none:none |
none|none | none | none |
10:27:00 | Win2K-f | 190.72.183.132 (CANTV.NET): CANTV SERVICIOS VENEZUELA, CARACAS, DISTRITO FEDERAL, VE. (DSL) |
n/a | FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:11:24:00 | WinXP | 65.25.61.94 (RR.COM): ROAD RUNNER HOLDCO LLC, CANTON, OHIO, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:51:00 | WinXP | 109.110.132.155 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
14:02:00 | Win2K-f | 125.64.17.43 (163DATA.COM.CN): CHINANET SICHUAN PROVINCE NETWORK, CHENGDU, SICHUAN, CN. (DSL) |
n/a | :www.google.com :fyehdvdc.net :yndgsqra.org :mxvliqpaz.info :ypajjal.com :kujvkzimg.org :ktakmyxvkl.com :rzzdkm.info :mmuufquqpi.net US:madajznjyj.biz :cjgadhn.org :otlldudmzs.net :udrkri.info :nzlqhu.net US:moyizcxsc.biz US:tyhuqscorz.biz :ajclsdhnd.org :vzppo.com US:jpdvitnd.biz US:tgupf.biz :ewsnc.net :lilocxmgb.net US:gtlkign.biz :rqsexdjcudz.info :fxbjr.info :vixukxxl.info US:wruefacbw.biz :wnkmoy.com :nbhgqqwj.org :vigxco.com US:qtyzfqrc.biz :fqzkzqlt.info :ipwugp.org :jrtpvlleio.com :jwbwujkcru.net :pgutmnbbz.org :xayouyg.com :therjfkjsdo.net :culhbjlko.org :yferivqeqxr.info :bpsfgpttigw.org :dygkgnnskp.info :zbxrzcvvkt.com :fhlidammv.net :ulvwoevgm.net US:gofhng.biz :egygtdvmk.info US:fuvsx.biz :nutsbp.info :wgigmyhr.info :xhuabkxkge.net :lvpqeopdjx.org US:pmufgap.biz :vwbvqq.com :yvikgkyir.org US:aryzwqbf.biz :gqovaeynamp.info :itpdtcpy.com :vaunn.net :usvwucxycwc.net US:vkvnryneta.biz US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:14:15:00 | WinXP | 93.157.157.142 (HISPEED.PL): USLUGI INTERNETOWE MAJESTIC, PL. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru CA:jewellerybazaar.net BR:casaebar.com.br |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 43 | ca3e3b13f3 NEW |
none[none] | none:none |
none|none | none | none |
15:02:00 | Win2K-f | 61.42.76.38 (BORA.NET): DACOM CORP, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:17:23:00 | WinXP | 109.110.132.155 (JWS.COM): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru :albat.somee.com **:boemaclasic.ro TH:www2.bpp.go.th :caetanojrecruz.adv.br DE:buyukfirsat.bu.funpic.org GB:www.bsnlondon.co.uk GR:dincermakinasanayi.com.tr |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
T:17:57:00 | WinXP | 173.23.226.45 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
20:50:00 | Win2K-f | 31.23.156.157 (-): . |
n/a | US:www.ask.com :fzpsxhcvmg.org :zyweda.net :lxvevwpf.info :ehnjryqg.net :jlveig.info :veztptgdt.org :dbotgiz.net :nidkqs.org :vllbfkb.net :uzfapx.com :fqosvywt.org :biivupeq.com :hyesyoaigil.net :lxjhfpsbt.info US:respeizqt.biz :oxboacw.org :knvexbrjs.info :oolfed.info :bdykqu.net :krcnffb.com :xcyqw.org :vyuqfmlwaqg.net :jdkpgzfknc.net :busguwjuh.com :qreitpwemr.org :atfqgsik.org :vdedrids.org :ssovx.net :juqdlghhcn.org US:uqabsumj.biz :qlpdculird.com :xjwybp.com US:enqnvcf.biz US:ethblgi.biz US:osgap.biz :hyhmvsqafaz.org :ceosjc.net US:tnjxysjnodo.biz US:hjtxsua.biz :pjymeo.com :uvqxons.info US:rrvtiiuing.biz :aanmtl.com :djgrt.com :gzruaqm.info :hbiwbdmd.info :jjudhibx.com :ipfjjxucjo.com :nootzfkfj.info :otcsk.info :bfwukqvv.com :bejwtnduypl.org :hxwureqe.com :npoxkft.com :thfadlut.net :upevwmrg.info :ipfpjlwgevu.info :actraemnc.com :esflwmofcoy.org :eopibpewf.com US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |