Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
02:16:00 | Win2K-f | 46.203.129.80 (-): . |
n/a | US:dvpfwaih.biz :ypaaymtbkml.org :acwkaww.net US:gcqaurdawxb.biz :tclyxsmqqhp.info :ljtqqjum.net US:aepspmvk.biz :jfars.net :cgrvfovuf.info :xobxwx.net :nlzyztlljlu.info :ankimls.info US:vtxdlgxex.biz :aorbfspe.info :xntnbiizo.net :zxfoaby.com :vecghd.com US:aewmvhmnaxm.biz :xzpwybkg.org :yeirzvfsaa.info US:otvqt.biz :cbclppjsk.info US:wcihvixbal.biz US:toklm.biz :elpydpknr.net :mffvmfyiuap.org :npcinrpo.info :bzhubkgwtya.net :wpizyxeni.org :wrzrey.org :mkhoydll.org US:anpfflec.biz US:myfywp.biz :acgikhvb.com US:pdwqdprfwcl.biz :ewnycoxqyk.info :dansnvmoo.net :siazluwaac.info :ibcccwt.org :njlinw.info US:qkqsefyx.biz :jfaqx.net :llhlh.com :khpkprymjsw.info :fyyjwknuim.org :jgvdlpsr.info :ysoxr.com :xzzowykrra.com :nzsif.org :zuhaxwo.com US:nzfadfgh.biz US:nrsghnvmrof.biz :tsamal.org US:moajzeaaxaz.biz :njiwt.com :rdzimdga.net :tjbpjcjh.org :pudsvsuqgu.info US:sdsdpbplu.biz :hsjyvpgwshs.org US:204.152.184.139:80 98.138.253.109:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
02:58:00 | Win2K-f | 91.204.84.150 (UKRSD.COM.UA): SYSTEM DESIGN LLC, RIVNE, RIVNENS'KA OBLAST', UA. (DSL) |
n/a | CN:www.baidu.com US:trafficconverter.biz :fyyjwknuim.org US:wcihvixbal.biz :wspub.info US:qyozqywz.biz US:rukjfokskrp.biz :nxvzqixydj.org :llhlh.com :jfaqx.net US:cbxexjig.biz :gxxkavrmeyl.info :ljdpfzad.net US:hmdmsvjj.biz :ewnycoxqyk.info :jbzdkroqxvm.org :vglnlolz.com :njiwt.com US:hxffpcet.biz US:qddfjp.biz :hrvqlv.com :wscxoz.info :ailku.net :kyfatbzs.org :falwjzwp.info :siazluwaac.info :bxjwattdo.info :opqcfxvh.net :dtdmczanfe.com :zlkrlrznvrp.org US:bydjnlxrzzh.biz :ysoxr.com :wxdriixh.info :sbmnjqghpz.com :ubcmxthbwkk.com :hsoyuhqtpj.org US:pdwqdprfwcl.biz :nenwjec.com :nzsif.org US:qkqsefyx.biz :hregyfhie.org :ankimls.info :uodaa.info :psruuiaatlo.com :bzhubkgwtya.net :nlzyztlljlu.info US:aphljsrd.biz US:jmfoigolf.biz US:otvqt.biz :vnftpjlactg.info US:aewmvhmnaxm.biz US:wkkfxbw.biz :krwdkvnwvoy.com :inbzrqfbvwl.org :palaffpmner.com :dansnvmoo.net :bbscnme.info :njlinw.info :thlsjvvqlmd.org :twdqny.org :yeirzvfsaa.info US:vkkudfsr.biz US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 13 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:07:15:00 | WinXP | 184.0.12.0 (EMBARQHSD.NET): EMBARQ CORPORATION, US. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
07:16:00 | Win2K-f | 2.60.82.80 (-): . |
n/a | US:www.w3.org US:trafficconverter.biz US:gcqaurdawxb.biz :psnmxf.net :fuvpfizmjx.net :esgsl.com :nfsiz.info :krwdkvnwvoy.com :eynpbmbxb.net US:libvpaoz.biz :ysoxr.com :gvmhdmzr.net :mdunzi.net :dtdmczanfe.com :qlymtkulnf.net :ypaaymtbkml.org US:mmjlaku.biz :boggwtvli.com US:bydjnlxrzzh.biz US:vtxdlgxex.biz :bvymbjhyj.info US:otvqt.biz :nmnijmri.net US:aphljsrd.biz :micnyd.info :rxuzuswx.net US:aewmvhmnaxm.biz :zxfoaby.com :xhdhxtezm.net :jtjgh.com :zkiztgpmw.org :acwkaww.net :tasvbjtot.info :odppzhqeoeo.org :wtamhzvb.com :xbauqpa.net :exphh.net :siazluwaac.info :pvvvzb.com :nttxiiqk.net :omtfiapead.org :hsghbyle.com US:fjmwx.biz US:yjavngvlxc.biz :zlkrlrznvrp.org :shtbwume.org :mopzftfl.info :shdpilza.com :motmugkyl.org :qjnyzhai.info US:wkkfxbw.biz :ewnycoxqyk.info :ikaxnzkyd.info US:aepspmvk.biz :edmgyaxmf.info :welzgqdc.com :vnftpjlactg.info :vecghd.com US:hecrlbvwpa.biz :uodaa.info :bgfqnkxsj.com :efzrupmmcfb.com :www.maxmind.com US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:08:08:00 | WinXP | 109.229.229.186 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 088838aa27 NEW |
none[none] | none:none |
none|none | none | none |
T:08:13:00 | WinXP | 50.81.6.103 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 40 |
474acf88e5 NEW 68f0c14692 NEW |
1f53944b24 [0] ccc1b24d53[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
08:26:00 | Win2K-f | 186.141.66.110 (-): . |
n/a | :www.yahoo.com US:bydjnlxrzzh.biz :esgsl.com US:aepspmvk.biz :ajtvtzyz.info :aorbfspe.info US:hecrlbvwpa.biz US:gmbvqlqvrng.biz :wrzrey.org :nxvzqixydj.org :cvagb.net :ubcmxthbwkk.com :ooshbdjt.org US:vysgwxsxb.biz :fwktgrai.info :ztnxmji.net US:liwia.biz :jbzdkroqxvm.org :trucmhn.org :oagexil.com :bvymbjhyj.info :corljeqvcj.org :rdxipnd.net :atljm.net :gvmhdmzr.net :hqcldcj.info US:kiuessgmfs.biz :tpmrdetdcc.com :rxuzuswx.net :huhgvm.org US:dvpfwaih.biz US:hxffpcet.biz :cfyij.org :iyjslxh.net :pvvvzb.com :qjnyzhai.info :khpkprymjsw.info :lkbhvmgga.info :llhlh.com US:lbpvci.biz :shtbwume.org US:149.20.56.32:80 US:204.152.184.139:80 98.138.253.109:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:08:55:00 | WinXP | 120.29.75.57 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 | e99261ba46 NEW |
none[none] | none:none |
none|none | none | none |
09:59:00 | Win2K-f | 185.9.158.29 (-): . |
n/a | :www.maxmind.com :www.getmyip.org :getmyip.co.uk US:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | 223d8089f8 NEW |
none[3] | none:none |
StarForce| | none | trace |
T:10:48:00 | WinXP | 109.110.132.155 (JWS.COM): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru :albat.somee.com **:boemaclasic.ro TH:www2.bpp.go.th :caetanojrecruz.adv.br |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
11:09:00 | Win2K-f | 178.234.180.24 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
11:14:00 | Win2K-f | 58.93.26.231 (PLALA.OR.JP): NTT PLALA INC, TOKYO, TOKYO, JP. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee FI:194.215.38.135:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
11:19:00 | Win2K-f | 188.71.100.252 (RIPE.NET): EUROPEAN REGIONAL REGISTRY, UK. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
11:24:00 | Win2K-f | 201.209.216.94 (CANTV.NET): CANTV SERVICIOS VENEZUELA, CARACAS, DISTRITO FEDERAL, VE. (DSL) |
n/a | EE:www.starman.ee | 445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
11:29:00 | Win2K-f | 203.113.159.27 (LOCALHOST): DAI IP CHO VIETEL, HO CHI MINH CITY, HO CHI MINH, VN. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 25 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
11:34:00 | Win2K-f | 213.193.24.83 (LYCOS.DE): LYCOS-DE-NETBLOCK, BERLIN, BERLIN, DE. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee :nlzyztlljlu.info US:vzlrflst.biz :efzrupmmcfb.com :falwjzwp.info :palaffpmner.com :thlsjvvqlmd.org :eynpbmbxb.net :nfsiz.info :ttyjllqop.com :bbscnme.info :opqcfxvh.net :xntnbiizo.net US:devnvs.biz :ajtvtzyz.info :gytyulbn.net :rdtxvrmim.info US:lcwyy.biz US:dvpfwaih.biz :tjehxpuc.com :twdqny.org |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
11:39:00 | Win2K-f | 83.23.74.62 (TPNET.PL): NEOSTRADA PLUS, POZNAN, WIELKOPOLSKIE, PL. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:www.if.ee |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
11:44:00 | Win2K-f | 118.8.54.45 (OCN.NE.JP): OPEN COMPUTER NETWORK, TOKYO, TOKYO, JP. (DSL) |
n/a | EE:www.starman.ee :www.maxmind.com |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
11:49:00 | Win2K-f | 94.54.239.203 (-): TURKSAT UYDU-NET INTERNET, ANKARA, ANKARA, TR. (100Mbps) |
n/a | EE:www.starman.ee FI:www.if.ee EE:www.online.if.ee EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
http 7 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
12:14:00 | Win2K-f | 178.20.227.200 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
12:19:00 | Win2K-f | 186.47.84.20 (-): . |
n/a | EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
12:24:00 | Win2K-f | 78.84.212.57 (-): ADDRESS POOL FOR LTC-HOME CUSTOMERS, RIGA, RIGA, LV. (DSL) |
n/a | EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:12:31:00 | WinXP | 37.252.73.93 (-): . |
n/a | DE:moscow-advokat.ru :los-angeles.ca.us.undernet.org SE:ozbytes.dal.net :washington.dc.us.undernet.org AT:graz.at.eu.undernet.org SE:viking.dal.net NL:broekhuisjuweliers.nl TH:btech.ac.th :flanders.be.eu.undernet.org SE:qis.md.us.dal.net TR:btr.gen.tr SE:vancouver.dal.net TR:burakasansor.com :lia.zanet.net ES:bytegraf.com :gaspode.zanet.org.za :lulea.se.eu.undernet.org SE:broadway.ny.us.dal.net TH:nt.go.th :cizreemlak.net DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |
12:44:00 | Win2K-f | 186.206.19.185 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
12:51:00 | Win2K-f | 31.3.244.91 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
12:57:00 | Win2K-f | 91.82.132.54 (INVITEL.HU): ADSL POOL, HU. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
13:03:00 | Win2K-f | 111.248.3.85 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
13:09:00 | Win2K-f | 178.43.128.152 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
13:26:00 | Win2K-f | 84.0.111.103 (T-ONLINE.HU): DSL DYNAMIC POOL T-ONLINE HUNGARY, BUDAPEST, BUDAPEST, HU. (DSL) |
n/a | CA:www.msn.com :mwmfiufid.net US:aphljsrd.biz US:ynryvgnut.biz :sbmnjqghpz.com :wspub.info :zvynydbyl.info :dtdmczanfe.com :falwjzwp.info :aeonmdkwstd.info :cnoxbq.net :palaffpmner.com US:myfywp.biz :uodaa.info :ttyjllqop.com :bbzlyge.org :ipltqclhlu.info :eokodkspu.org :fimuoikcxk.org :ubcmxthbwkk.com :bbscnme.info US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
15:08:00 | Win2K-f | 185.9.157.206 (-): . |
n/a | :www.maxmind.com US:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | 223d8089f8 NEW |
none[3] | none:none |
StarForce| | none | trace |
15:17:00 | Win2K-f | 109.165.19.93 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
n/a | EU:checkip.dyndns.org | 445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:16:22:00 | WinXP | 186.34.234.56 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
16:58:00 | Win2K-f | 186.95.75.158 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 7 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:17:31:00 | WinXP | 109.52.22.182 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
18:47:00 | Win2K-f | 213.129.117.106 (-): VOTECRETAIL, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:53:00 | Win2K-f | 78.107.142.115 (CORBINA.NET): INVESTELEKTROSVIAZ LTD, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
21:35:00 | Win2K-f | 27.118.20.123 (-): . |
n/a | US:trafficconverter.biz US:www.w3.org US:qaqwjjo.biz :ffyyywnlohw.com :rmkwxrrbym.com :xfqfvst.net US:nqyyiz.biz :eqfknca.net :lavimpwh.org :ociwvh.net :zbxmnclbfbz.info :jkeroratvam.org US:kokkunfl.biz :htbsa.org :gpkakkrp.info :zhycn.org :ddnnjdpk.com :wgquzpp.net :pndhcwrhxfv.org US:vqljxybiqdo.biz US:ivbqrqpfo.biz :fhnnveepduv.info :sgxemr.com :bcgzcd.com :kyomnorrds.org :vztnooue.info :goujq.com :mxagt.info :sdrekxkef.net :kcnqk.org :snogm.org :bzjjyvz.org US:jymxcapayq.biz US:tkzcgdhegin.biz :xczynk.net :yjkvvm.info US:ljupwb.biz :fdjjghwu.com :ilrnz.org :oqcxvrd.net :offpenvldv.net :utwulybtrs.net :sgwbtfpfddt.net :uzblvonu.com :kyysathx.info :edvqkjqevov.info :pvmky.net :ggwtqrver.info :qjpxbqn.net :vatgddb.com :ujqzc.com US:iiarwskx.biz US:vzzmgjshvwm.biz :hdwrlvncr.org :nmbthrdi.org US:akhmvszmwfr.biz US:pbnsgrbpzcm.biz :bqqll.com :bnrtqawd.org :oyxtquaz.net :ghmmkkql.info US:qchfclr.biz US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 20 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
21:53:00 | Win2K-f | 142.4.53.4 (-): DEPARTMENT OF HEALTH (CANADA), CA. (DSL) |
n/a | FI:194.215.38.135:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |