Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
01:18:00 | Win2K-f | 50.83.139.176 (-): . |
n/a | US:www.ask.com :mktwd.net :nrzqhysmwso.com US:sqibnzfy.biz :rficquvbk.info :znrmfkpcf.info :ntyxzupw.info :bpudvom.net US:vqljxybiqdo.biz :bqqll.com :lrfvmaba.com :palaaytgis.net US:yqybezdixk.biz :eyaajnvp.net US:biofn.com :htsgcajoju.org :mtxdw.org :zlqpbzzjmm.com US:gfkghqfm.biz US:ncohpa.biz :czbtynq.net :kkfsxmaphyl.org US:kamuytrqr.biz :sdrekxkef.net :xfqfvst.net US:vzzmgjshvwm.biz US:dbbhn.biz :uxhtro.info :vgfzz.net :edvqkjqevov.info :vbmxc.info :bcgzcd.com :xxnqewmqemy.net :alaruqxf.net :mxagt.info :tqssjzbxonr.net :wsmyq.com :nmbthrdi.org :ggwtqrver.info :dlfakrmkllu.net :sgwbtfpfddt.net :gvwkwjbtyw.info :yhzzddcshfa.org :lavimpwh.org :ujbek.com US:tkzcgdhegin.biz US:kokkunfl.biz :eponeexb.net :wyemi.com :goujq.com :rbrruf.org :pncbxcv.info US:tuofjddwc.biz :lepulgy.com :jkeroratvam.org :kfxtw.org :kwzujpgz.com :mbaaxmbmohm.com :pluvw.net :qjowwb.net US:qaqwjjo.biz US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:02:22:00 | WinXP | 50.81.6.103 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 40 |
474acf88e5 NEW 68f0c14692 NEW |
1f53944b24 [0] ccc1b24d53[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
T:03:51:00 | WinXP | 118.160.37.211 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru US:doasoil.gov.np :earnestbiz.com TR:fotozenistanbul.com :cmyj.co.th TH:chonkanya.ac.th :dinamikdekor.com :aniketkulkarni.in :alabousco.com |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | ff027c230a NEW |
none[none] | none:none |
none|none | none | none |
06:10:00 | Win2K-f | 85.130.11.237 (CABLEBG.NET): CATV POOL FOR SOFIA/BULGARIA, SOFIA, GRAD SOFIYA, BG. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee FI:194.215.38.135:80 EE:62.65.192.24:80 EE:62.65.192.25:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:09:56:00 | WinXP | 79.162.134.51 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru CA:jewellerybazaar.net BR:casaebar.com.br :canossadhule.in :cansesiasknefesi.com DE:how2gethazanat.ho.funpic.de :www.evishop.de :chihuahuaupinghome.com IN:dehaspas.com TR:devdijital.com US:sobrenaturalbr.net BR:direitopublico.com.br |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 9ebcc2e373 NEW |
none[none] | none:none |
none|none | none | none |
T:11:10:00 | Win2K-f | 79.209.109.230 (T-DIALIN.NET): DEUTSCHE TELEKOM AG, REGENSBURG, BAYERN, DE. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee FI:194.215.38.135:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
15:19:00 | Win2K-f | 36.231.174.24 (-): . |
n/a | :www.maxmind.com DE:131.220.6.26:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
22:04:00 | Win2K-f | 111.240.82.78 (-): . |
n/a | US:www.w3.org :hnwuvuegs.net US:iqlomsajrol.biz :byatvdhmc.com US:izpitsb.biz US:hkxkzpohkr.biz :ceuhsgn.info :rsufmzfp.net :crqkqqk.info :itbaguiqv.org US:nvtgfkxsqag.biz :ylkkqc.info US:oqzbhv.biz :hkaioylj.com :onpaepedwhs.org :xtfcaduk.com US:nexdygdw.biz :qzdxhhr.net :kyetif.net :ncvvyejh.net US:bvjivq.biz :fxhsol.info :xbmdtzvhde.info :udxjej.org :tqnwxlu.org US:kkhxsm.biz :zosypfff.org :neuiqa.org US:rlauezos.biz :aggvq.info :nxmkwnbq.info :uytoetti.com :kwajhtpzhzr.net :lrclfw.org :zafozl.org :wvsjmbqg.org :zsnhhbyexk.info :eicfnqdcu.info :qsyozdinhbi.info :mcsayfe.org :lljeax.net US:glotud.biz US:bkybbuac.biz :aqfvicvf.net :comhglok.org :elnqz.org :tzwhduxol.net US:lebduft.biz :gnalhvyta.net US:gbdqp.biz :gyiob.net :skbfifjyd.info :nxzcdraovgb.com :hzxuyvql.net :risquexbzw.net US:iphudnvo.biz :hndtexicvkq.net :cvcakhd.info :ibrkridhf.net :kartfhdtti.net :psrxdjzwere.net :rxlsjulobtc.net US:gfymcwphmf.biz :xmuncizn.org :iafqfyaewi.org :ksxrlqdvavp.info :ifocxjrnejg.info US:pxfotkfd.biz :gihurso.org :ojqlr.net :wvbwnfcot.info US:128.30.52.37:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 9 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:22:28:00 | WinXP | 24.155.194.155 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS CORPUS CHRISTI HUB, CORPUS CHRISTI, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
22:53:00 | Win2K-f | 89.42.87.114 (BIZARTELECOM.RO): SC-BIZAR-GROUP-CONSULTING-TRADE-AND-TRANZACTIONS-SRL, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | US:www.w3.org :jkqawvzyc.net US:kwrnhfj.biz :onpaepedwhs.org :kysvhia.com :rxaisl.org :uplnrfirm.org :ognqpespr.info US:gcagoa.biz US:pxfotkfd.biz :itobseoq.com :rqermi.org US:euqbzo.biz :lxnsaz.com :risquexbzw.net US:udbimfrz.biz US:aepxcipvja.biz :zkddd.info :ktcdrdlq.info :glcgnqzl.org :hnwuvuegs.net :yjxsjsnr.com :ycoudnryo.net :hckecf.org :qdkiztkk.net :sfroyyic.com :iesvttc.com US:ydcyvpbzdc.biz :tdwhpjrx.net :ibrkridhf.net :zubyiabmyan.com :mclwg.com :vuasuhzy.com US:jilicswq.biz :rxlsjulobtc.net :jwdjtgcw.com :dowlqzy.com :ysmjnvqvg.info :gvdhcaw.info :ttzlcqzf.com :ksxrlqdvavp.info :yvnaiagtavb.com :pcrqhip.net :cpouixkm.com :pgugqxpr.org US:glotud.biz :myazdqfdakm.com :zosypfff.org US:gsiqexot.biz :hgnqlws.com :qvemsto.info :ehilksu.info :gpzmpvasvh.net :jzhnbdv.com :fhlbphyjaj.com :jkoupiqlk.com US:oqzbhv.biz :frmzrqzf.net :zsnhhbyexk.info :xbmdtzvhde.info US:dvcojzrpy.biz :qzdxhhr.net :acnssx.com :rveqrnrv.org US:mmtixxct.biz :hmabuqhk.net :cbvkeytto.org :rezpkjhgwmq.com US:ravrdqdded.biz :vndlvv.com :lkaojj.org US:128.30.52.37:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 7 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |