Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:55:00 | WinXP | 109.162.123.224 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru :albat.somee.com **:boemaclasic.ro TH:www2.bpp.go.th |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 8c282472f0 NEW |
none[none] | none:none |
none|none | none | none |
T:03:18:00 | WinXP | 109.162.123.224 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru :albat.somee.com **:boemaclasic.ro TH:www2.bpp.go.th :caetanojrecruz.adv.br DE:buyukfirsat.bu.funpic.org GB:www.bsnlondon.co.uk GR:dincermakinasanayi.com.tr |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 8c282472f0 NEW |
none[none] | none:none |
none|none | none | none |
06:07:00 | Win2K-f | 89.149.103.69 (10-91-149-89.GLOBNET.MD): JV SUN COMMUNICATIONS S.R.L, CHISINAU, CHISINAU, MD. (DSL) |
n/a | US:www.ask.com :cprbnadi.com :tmaghrr.org US:teuzjcf.biz :lxalqpkh.com :xupdke.com :uiooar.com :zutdklmtjok.org :ibaqhnny.info :broeeeows.org :savmvopo.info :udaohhkwas.net :nadsgqfbd.net US:qvqzd.biz :lhruergt.org :finiozpzb.com :emfrsa.info :enhcbaooyn.com :hwntmhqad.org :vittjbk.org US:jqewftnuwhx.biz :yhhtglclfol.info :kpewro.org US:enwufplj.biz :qqkvfebll.org :zydbs.net :mgumvw.net :ggnzi.info US:bzmwfwx.biz :uhmer.net :qqvfv.org US:trafficconverter.biz :vokzddqg.info US:gxvppmmkzc.biz :gluimlcht.org :oghnzckqb.com :tzibmpiun.com US:tnpczb.biz :oommmnr.com :lngpkggw.info :okyfq.info :zoirreupxx.net :gvmrjfnjfwg.info :ebkhfjbr.com US:plpxcfmx.biz :bablirlytk.com :ulhehxomu.com :clypk.net :ozgfduyned.com :xkmxxu.info :xpuhasi.org :ztrecpepag.info :aopalprg.net :gbmoh.com US:olgogqk.biz :insamh.com US:omlwsydr.biz :gruiek.info :hsmski.org :vhviunnudq.info :cdduytsuwih.com :bhohtf.info US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
07:41:00 | Win2K-f | 93.178.35.35 (-): INTERNATIONAL COMPUTER COMPANY LTD, JEDDAH, MAKKAH, SA. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
08:17:00 | Win2K-f | 109.238.111.144 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
n/a | FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
10:32:00 | Win2K-f | 186.89.11.91 (-): . |
n/a | EE:www.starman.ee FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
12:48:00 | Win2K-f | 185.12.111.228 (-): . |
n/a | :www.maxmind.com :www.getmyip.org :getmyip.co.uk US:checkip.dyndns.org DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
14:20:00 | Win2K-f | 94.55.55.55 (-): TURKSAT UYDU-NET INTERNET, ANKARA, ANKARA, TR. (100Mbps) |
n/a | CA:www.msn.com :nmtvmdw.org US:emyncvddpk.biz :yhhtglclfol.info :vknow.biz :ibaqhnny.info :lbaznrllmti.net :ytwxuflzoh.net US:wbgekd.biz :hrivjre.info US:klgroycsej.biz :lgtoem.info :jawatazqf.info :aekkqhydckk.info US:ccpmsvdic.biz :cpqtkord.net :bhohtf.info :uguqyclr.info :mehjpfi.net :nqhqtti.org :mdeiofi.com US:vnilmnze.biz :mwpfblpr.org :flpkxkae.org US:xztsbe.biz :emfrsa.info US:ecdpivm.biz US:xpefrq.biz US:torqa.biz :gbmoh.com :lduuptk.com US:invtl.biz :vgkwz.net :aopalprg.net :tpmyfow.net :pisjzxec.com :hfndvfngxt.com US:enwufplj.biz :sxjaho.info :tyywoioldqp.info :ossxx.org :broeeeows.org :lngpkggw.info :itkpcxvhsv.net :vhviunnudq.info US:teuzjcf.biz :glzifxzlj.info :syekq.org :lhruergt.org US:fezfyns.biz :zmhehcorxq.com :pcedhjpckq.info :hwntmhqad.org :livpujoj.org :cdduytsuwih.com :cuuhkvvu.info :tuvqfssg.com US:vnyjiude.biz US:wqoillqkzla.biz US:wjlteehu.biz :qqvfv.org US:149.20.56.32:80 FI:194.215.38.135:80 US:204.152.184.139:80 EE:62.65.192.25:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:47:00 | Win2K-f | 186.110.117.7 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
20:19:00 | Win2K-f | 27.69.23.235 (-): . |
n/a | DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:30:00 | Win2K-f | 186.207.216.180 (-): . |
n/a | US:www.w3.org US:repio.net :epiydhxoit.com :mpdntyl.net :goejp.info :eiygg.org :wemvd.net :pdzeqruty.org :gptyrlekzj.info :sxdweliy.com :ljqplyjj.com :krmjpqju.info US:nxmotrefi.biz :pxwzkpaowf.info :coewol.net :rwcfikjk.org US:anlbmbdtg.biz US:beeivasxcg.biz :ppkqsjc.info :oevgfzywzv.com :bpaly.org :yxfalezf.com :pjrebjahdkw.org :jztqk.org :aaebrvg.net US:llxsgut.biz :rzhlvutq.info :sgqzzbn.info US:fczafqg.biz HK:dondup.info US:fuaklhif.biz :kodtvposa.org :cyomoh.net US:rfbxdpog.biz :ijkgn.info :owpggad.com :tlwvjnfsrt.com :eoyjr.org :cpqtu.info :cyewygo.net :ospldg.com :mkkmbaqvn.net :xqnogddskhl.net :ssdddrblvp.net :jvikavs.net :uqffhrvq.org :voovajxgfoa.net :fembqroghg.com :diqfanpdrve.net :axsefjwwaak.org US:zthftdnc.biz US:bfeojqki.biz US:ritrknjhwp.biz US:folzeagqwtx.biz US:lgbrn.biz :tpbjpir.com :jqbkpa.com :hvzktounab.net US:tlthwrnn.biz :rnjpyqvljc.info :zdqoqymi.info US:128.30.52.37:80 FI:194.215.38.135:80 US:204.152.184.139:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:22:12:00 | WinXP | 36.224.176.86 (-): . |
213.155.14.161:80 | DE:citi-bank.ru DK:bem.dk US:banboon.com MY:bdb.com.my TH:baulaung.org IR:bazyar-arya.com :barlikinsaat.com.tr TR:basamakhalisi.com |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 43 | bbafbfe1df NEW |
none[none] | none:none |
none|none | none | none |
T:22:57:00 | WinXP | 223.191.200.75 (-): . |
213.155.14.161:80 | DE:citi-bank.ru :albat.somee.com **:boemaclasic.ro TH:www2.bpp.go.th :caetanojrecruz.adv.br DE:buyukfirsat.bu.funpic.org GB:www.bsnlondon.co.uk GR:dincermakinasanayi.com.tr |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |