Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:44:00 | Win2K-f | 190.67.25.75 (TELEFONICA.NET.CO): COLOMBIA TELECOMUNICACIONES S.A. ESP, CALI, VALLE DEL CAUCA, CO. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
02:05:00 | Win2K-f | 91.222.168.205 (NACKSYSTEM.NET): EU-ZZ, UK. (DSL) |
n/a | US:www.yahoo.com US:trafficconverter.biz :axsefjwwaak.org US:khaeaivjz.biz :jzsfcmva.net :xqnogddskhl.net :gwqbmqke.info :jvikavs.net US:ibzazs.biz :mwbsvvwe.net US:rknyk.biz :xjabn.com :eoyjr.org :lvlvucxpvfv.net :jbhnaobz.info :tpbjpir.com :adiillhl.org US:dqwhg.biz US:fuaklhif.biz :oeifsbh.org :onevs.org :uuzkoratscf.net :krmjpqju.info :kenkeehvlkn.com :mppukztpxr.info :ruggdiia.com :rnjpyqvljc.info US:btppjciuj.biz :kxqteqaodw.info :wtmbcnw.org :djciaycxqb.net :prjncyt.info :dxbsurcnkvn.info :uywqdco.org :wyrxlrj.info US:ezryyzafdjc.biz :afwafyee.net :rskwigst.net :bvniqpiloyh.org :jyarenqfo.info :pxwzkpaowf.info US:hjrtxwrfq.biz :voaodxmnqn.net :yfyodehdrdv.com :aadqkwlho.org US:emavycgte.biz :njrqymzdna.org :ssdddrblvp.net :indtpabl.com :faforxm.info US:zdksvvca.biz :mcixcsj.com :ylliznwdgo.net :yasvvgcm.info :mvdltpolx.com :tdfqohyfk.net US:lgbrn.biz :luthhgweej.org :ydyezuvx.com :qvkkt.org :eiygg.org :bqcos.org US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
04:50:00 | Win2K-f | 109.99.195.116 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee FI:194.215.38.135:80 EE:62.65.192.24:80 EE:62.65.192.25:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
04:50:00 | Win2K-f | 89.42.147.55 (-): S.C. EXPERTNET S.R.L, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:06:57:00 | WinXP | 109.102.140.252 (JWS.COM): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru :albat.somee.com **:boemaclasic.ro TH:www2.bpp.go.th :caetanojrecruz.adv.br DE:buyukfirsat.bu.funpic.org GB:www.bsnlondon.co.uk GR:dincermakinasanayi.com.tr |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
08:15:00 | Win2K-f | 61.103.7.10 (-): DREAMX-CATV-WONJUBCSAEROUN, WONJU, KANGWON-DO, KR. (DSL) |
n/a | CN:www.baidu.com US:ubsbvtssgsd.biz :elrzbqcdbc.com :giryoopzjw.info :coewol.net :luthhgweej.org HK:dondup.info :ijkgn.info :qebnwcj.org :qfklm.org :dxsulkzuj.net :aaebrvg.net US:syapue.biz US:zthftdnc.biz :lgimorcz.net US:tmvnzvdsc.biz :hgqhh.org US:ibzazs.biz :eoyuv.org :ppcytwxh.com :mpdntyl.net US:rfbxdpog.biz :hzlzciwk.info :fverqgpm.org US:dqwhg.biz :jqbkpa.com :frwcixqxwt.net :czkqqph.com :uywqdco.org :notihuxxvhj.com :nbepbshm.com :rgqmtv.info :oqwvpwpp.info :djciaycxqb.net :avxamikgbff.net :wijuuke.org :rskwigst.net US:dpflgupi.biz :wynrym.net :goejp.info :prjncyt.info :oeifsbh.org :okrwztoauk.com :confajbnqqp.info US:rgeztatm.biz :glbzmnxn.info :fslaa.org :faforxm.info :eprgdywt.net :wtmbcnw.org US:repio.net :tadupv.com US:fuaklhif.biz US:xetlwdbd.biz :sgqzzbn.info :rkomxgs.org US:bfeojqki.biz :indtpabl.com US:hjrtxwrfq.biz :uuzkoratscf.net :cyomoh.net US:149.20.56.32:80 US:204.152.184.139:80 HK:61.238.149.50:80 |
445 | pcap | raw alerts ruleset |
http 12 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
10:30:00 | Win2K-f | 187.65.33.180 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:www.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
11:20:00 | Win2K-f | 94.137.161.240 (DSL.SANET.GE): SANET-IP-BLOCK, GE. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:www.if.ee :pjrebjahdkw.org US:ocwxqgfmxdl.biz :xkakyxuojuq.info :pdsqsb.info US:btppjciuj.biz :xjmgz.com :meghfcgye.net :prjncyt.info :mkkmbaqvn.net :rqasjeyxqh.info US:repio.net :adiillhl.org :luthhgweej.org :qvkkt.org US:tlthwrnn.biz :jzsfcmva.net US:xetlwdbd.biz :mljenphf.org :jbhnaobz.info :aadqkwlho.org :ubjgjjz.info :eoyuv.org :iwtilpjj.org :iutjsd.net :oeifsbh.org :pxwzkpaowf.info US:emavycgte.biz :lqzovfvc.info US:nqvjmtrnp.biz :dxzgwpzol.net :igwvgklwh.org :yyuad.info :sxdweliy.com :rhsqxkedo.org :xqnogddskhl.net US:zthftdnc.biz :joauewoqzal.com :hdvkq.org US:ezryyzafdjc.biz :czkqqph.com FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 EE:62.65.192.25:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
11:56:00 | Win2K-f | 217.203.25.233 (-): TELECOM ITALIA MOBILE, ROME, LAZIO, IT. (DSL) |
n/a | :www.google.com :tlwvjnfsrt.com :ltryiuw.org US:rgeztatm.biz US:rmgwmhot.biz :wtmbcnw.org US:mgpqjzow.biz :bqcos.org :oevgfzywzv.com US:dbrkj.biz :uywqdco.org :hdvkq.org :zumweo.net :elrzbqcdbc.com :icugiz.info :ospldg.com :owpggad.com US:llxsgut.biz :wemvd.net :qseyyutp.org :rgqmtv.info :pdsqsb.info :zcjvresyt.info :zzfqpujtgvq.com :epiydhxoit.com US:btppjciuj.biz US:dpflgupi.biz :uuzkoratscf.net :vyjlftqmyom.info :njrqymzdna.org :lqzovfvc.info US:wzpwkm.biz :confajbnqqp.info US:ynjao.biz US:urspnxkrjyb.biz :tjnamzevezb.com :ufvmqxqhgmx.com :ylliznwdgo.net :enjkdvth.org :luthhgweej.org :prjncyt.info US:khaeaivjz.biz :yasvvgcm.info :voaodxmnqn.net :joauewoqzal.com :onxczjj.info :rkomxgs.org :yfyodehdrdv.com US:qbrvzfoasu.biz :axsefjwwaak.org :iwtilpjj.org :ipwfpy.com :ygcez.com :rsdhvbyvkzx.info :onevs.org :bpaly.org :xqnogddskhl.net :cpqtu.info :eozmmsca.net :gptyrlekzj.info :fslaa.org US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
14:36:00 | Win2K-f | 109.173.107.205 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee FI:194.215.38.135:80 US:204.152.184.139:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
14:54:00 | Win2K-f | 62.169.119.80 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, LISBON, LISBOA, PT. (DSL) |
n/a | DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
15:47:00 | Win2K-f | 68.159.226.36 (BELLSOUTH.NET): BELLSOUTH.NET INC, ATLANTA, GEORGIA, US. (DSL) |
n/a | :www.maxmind.com EU:checkip.dyndns.org :www.getmyip.org :getmyip.co.uk DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:03:00 | Win2K-f | 210.242.252.183 (-): MEI JIA RECREATION CAREER CO. LTD, KAOHSIUNG, T'AI-WAN, TW. (100Mbps) |
n/a | FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 7 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:43:00 | Win2K-f | 119.42.102.53 (-): 10 FL. 72. CAT TELECOM TOWER BANGRAK BANGKOK THAILAND, BANGKOK, KRUNG THEP, TH. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:47:00 | Win2K-f | 107.7.73.92 (-): . |
n/a | EE:www.starman.ee FI:194.215.38.135:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:50:00 | Win2K-f | 204.116.194.24 (COMPORIUM.NET): SPIRIT TELECOM, COLUMBIA, SOUTH CAROLINA, US. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:18:52:00 | WinXP | 100.42.148.108 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 | ff90c1ff00 NEW |
none[none] | none:none |
none|none | none | none |
18:54:00 | Win2K-f | 189.12.35.87 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, ITAPETINGA, BAHIA, BR. (DSL) |
n/a | EE:www.starman.ee FI:194.215.38.135:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:00:00 | Win2K-f | 203.114.105.211 (TOTBB.NET): TOT PUBLIC COMPANY LIMITED, BANGKOK, KRUNG THEP, TH. (100Mbps) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:09:00 | Win2K-f | 98.112.163.85 (-): LOS TRES HERMANOS RESTAURA, US. (100Mbps) |
n/a | 445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
19:20:00 | Win2K-f | 202.75.52.170 (TM.NET.MY): TELEKOM MALAYSIA BERHAD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 23 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:30:00 | Win2K-f | 173.224.220.179 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:35:00 | Win2K-f | 198.23.150.86 (-): . |
n/a | EE:www.starman.ee FI:www.if.ee FI:194.215.38.135:80 EE:62.65.192.24:80 |
139 | pcap | raw alerts ruleset |
http 5 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:39:00 | Win2K-f | 120.72.84.185 (-): QUANG TRUNG SOFTWARE CITY DEVELOPMENT COMPANY, VN. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:www.if.ee US:trafficconverter.biz FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
21:27:00 | Win2K-f | 46.120.226.27 (-): . |
n/a | :www.ask.com :xlxybshmrpk.com :ghpxvdgf.com :dsnjlbxqzbs.org :wdgndjoqy.info :budajpqrol.com :voakmobbzf.com :qgiskqb.org US:gbrokuii.biz US:nmzrgkj.biz :oshpza.info :cqeankqm.org :iabcgqsjb.info :tozgsccijhp.info US:ozbyissad.biz :ywpointl.org US:rzmzfzz.biz :onqydihfa.org US:uxtibrnz.biz US:sysnorj.biz :hbuukvuc.com :ufuwf.net :hntcczcbeu.com US:xqphxg.biz :swwfirjp.com :mbdvapbg.com :htqevgyhdpa.com :wbaois.info US:rmcxrseudyx.biz :wnham.info :zpcnnkcupne.info :zorhn.com :alxzlrrfh.org :puccbsmwp.com :cyzmpzp.info :ycaurysng.com :vehjuooed.info :mshffc.info :tpyhsyi.org :azcti.net :vlkfjvuwxa.org :dlyddroq.org :abspppyuo.info :sjgrqu.com US:afxhnhzw.biz :qvethwwaat.org :dlljra.org :xvunhonfj.info :fxibxhpe.com :jlcsymwit.info US:kjteajvm.biz :acpmjnav.net :ctihenlzw.com US:yzuqxm.biz :gyelpsrqbr.net :kdqmlvdiens.org US:dxqgeruxtq.biz US:ongajigau.biz :gbwczmbv.net US:akijpbhvd.biz :koaodg.info US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
22:32:00 | Win2K-f | 219.84.236.65 (SO-NET.NET.TW): SONY NETWORK TAIWAN LIMITED, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:www.w3.org :lytyum.net :jlqzdwv.info :acpmjnav.net :budajpqrol.com US:bloynblo.biz :yvito.org :hugxkbhlabs.info :kdqmlvdiens.org :puroizq.info :qwdsnwetzex.info :ppgitdcp.info :cqqjfysvt.info :pobcxs.info :rgaqyvenbxj.info :xpdrmczq.info US:zqasgh.biz :zlsottgtrg.com :uzosqfly.org :hoyvzxl.net :cqeankqm.org :tetqxuyy.net US:akijpbhvd.biz :adpotncfns.net US:afxhnhzw.biz :tswaxsrtvd.net :zgzic.net :htqevgyhdpa.com :xsemj.com US:kkjywousbim.biz :uoucgvkgk.net US:gbrokuii.biz :baxiopg.org :lghywh.com :ufaqyd.com :pmvnpdyk.net :cyzmpzp.info :xvunhonfj.info :rthtrdjedy.com :ppdzcla.org :jqdrnbwg.com US:eebymi.biz :ycaurysng.com :ufuwf.net :obyaevm.net :zfyxvfou.com :cbfopagk.net :rksobfxg.com :gprdwksd.info US:rdhtrlpl.biz :keqknstmnk.net :ywpointl.org :qgiskqb.org :ytmdei.com :xfucaaqyzls.info :iscsorj.net :lbcxooeihl.org :chvtoptwg.org :mshffc.info :zxeckecvgf.org :tozgsccijhp.info US:128.30.52.37:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |