Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:43:00 | WinXP | 118.1.216.136 (OCN.NE.JP): OPEN COMPUTER NETWORK, YOKOHAMA, KANAGAWA, JP. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | 0ab0d85629 NEW |
none[none] | none:none |
none|none | none | none |
T:06:43:00 | WinXP | 37.252.74.60 (-): . |
n/a | DE:moscow-advokat.ru NL:diemen.nl.eu.undernet.org :washington.dc.us.undernet.org SE:brussels.be.eu.undernet.org SE:broadway.ny.us.dal.net AT:graz.at.eu.undernet.org NL:broekhuisjuweliers.nl :los-angeles.ca.us.undernet.org :caen.fr.eu.undernet.org :flanders.be.eu.undernet.org :lia.zanet.net SE:coins.dal.net TH:btech.ac.th :london.uk.eu.undernet.org TR:btr.gen.tr SE:ced.dal.net TR:burakasansor.com SE:ozbytes.dal.net ES:bytegraf.com TH:nt.go.th :cizreemlak.net DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |
T:08:31:00 | WinXP | 70.45.69.176 (ONELINKPR.NET): SAN JUAN CABLE LLC, TOA BAJA, PUERTO RICO, PR. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 0c38af69f4 NEW |
none[none] | none:none |
none|none | none | none |
10:31:00 | Win2K-f | 171.252.239.212 (BURNERSYSTEMS.COM): VARIOUS REGISTRIES, UK. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 22 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:10:35:00 | WinXP | 37.252.74.60 (-): . |
213.155.14.161:80 | DE:citi-bank.ru US:kidos-bank.ru |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 | a4140e4032 NEW |
none[none] | none:none |
none|none | none | none |
T:11:02:00 | WinXP | 109.229.229.186 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 088838aa27 NEW |
none[none] | none:none |
none|none | none | none |
13:55:00 | Win2K-f | 49.145.1.211 (-): . |
n/a | US:qhzhqidysa.biz :ccpxwii.com :magnlsu.info US:btxlgtqkciz.biz :bnsmbwk.com :onapyplmtw.info :wzqiccd.net :lmawac.org :bfqmc.info :xaotmxcw.com US:pozimktnia.biz :akjicykh.org US:aalnxr.biz :grgzetd.info :dbdbrkfg.net :rstiw.com :ummbyuifq.com US:xscftxgpq.biz :ofegbkycz.info :jmavgm.info :nuwpirfre.net :nutjmrlf.org :isgclzdboss.net US:hipizpumvwt.biz US:scgahjzlh.biz :yrsct.com :oiqeaoav.info :yunjrvicndo.org :mcsiqqgyfdk.net :jprekpsa.com :tjscp.info :mvjtdhxpbp.org :blvvkiq.net :ihhxeqntw.net :kiutcddl.net US:spsewd.biz :qclplsfc.org US:vumjat.biz :uivrhfox.org :aiyriq.info :jxfvrfr.info :eavvkl.com US:zcnzk.biz :gpjoio.com :lnhmfcr.info :wplrpbqpjlv.net :blavp.org :nhpkyfth.org :cmarjdqe.info :orpnnela.org US:ztqnxalui.biz :iomimy.net :nmylkfiqb.org :wtrdxcfiwt.org :fkaroppqsle.com :ihmhwoo.org US:iprozqrfucl.biz :rvjttexcgw.org :mrtjhoox.com :tpxfqsn.com US:tyvudcism.biz :dqhojnl.net :chwhbza.info :dqrmvvu.info :fuoqpw.org :hocnurjhc.org :kgifabmul.net :hisdhrx.org :fljgkw.net :jqvqngkdkwi.info :qhwegs.info US:quvyzrtk.biz :eqpqkj.com :hjatgc.org :luxwto.net :ifefr.org :lvczlnuaij.org :wxurgoecbx.info :hgmoddjoy.org US:miknbdks.biz US:204.152.184.139:80 74.125.224.112:80 |
445 | pcap | raw alerts ruleset |
http 7 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:14:30:00 | WinXP | 100.42.148.108 (-): . |
n/a | DE:citi-bank.ru :adult-empire.com DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | ff90c1ff00 NEW |
none[none] | none:none |
none|none | none | none |
T:14:32:00 | WinXP | 94.240.175.43 (FLAGMAN.ZP.UA): UA-FLAGMAN, KIEV, KYYIV, UA. (DSL) |
n/a | DE:citi-bank.ru :albat.somee.com **:boemaclasic.ro TH:www2.bpp.go.th :caetanojrecruz.adv.br DE:buyukfirsat.bu.funpic.org GB:www.bsnlondon.co.uk :dincermakinasanayi.com.tr :adult-empire.com DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
15:25:00 | Win2K-f | 180.73.144.173 (-): . |
n/a | :www.google.com :gifkzjgzu.net :lmawac.org :fljgkw.net :yvdymijdb.com :ejewatc.net :hfybwzqh.com :gpjoio.com :mklqrkfbkh.info US:ziovoa.biz :hocnurjhc.org :meidmgemt.org :pfrfw.info :mcsiqqgyfdk.net :ccpxwii.com :lelkcc.com :gqxyoocj.info :fhvxls.net :fcorvqcp.net :kiutcddl.net :xezemzfu.info :ijxihkbh.info :swwqxfkt.info :guemiiviv.info :svrmv.info :lgkilcgigsn.org :qdvbjd.net :tpxfqsn.com :usakqqqu.org :wpgtcgy.com US:aalnxr.biz :luxwto.net :gfsiwzesi.net :jxfvrfr.info :qckidwyra.org :hgzjtzip.info :wizlnzvylgd.com :ovutefeuz.org :qgjpdmjrin.org :eptrfnqibhk.com US:yxqpaedl.biz US:mhibyxej.biz :hgmoddjoy.org US:zcnzk.biz :grgzetd.info :vmrsn.org US:strdqjkbas.biz US:scgahjzlh.biz :vierczykj.info :knklmjpfag.net :qjphowgvd.org :blavp.org US:xscftxgpq.biz :dbdbrkfg.net :bncgfbvv.net US:nbtyqlblerr.biz :nuwpirfre.net :cafmivk.org :hisdhrx.org :eulofbjr.info :bnsmbwk.com US:ajsnl.biz :wrxbnypfq.net :kwdagek.net :gtpifxg.info :otvfbgoeive.org :myeivtx.net US:iprozqrfucl.biz :yjrto.com :qrwkscef.org :ncloxxz.com US:204.152.184.139:80 74.125.224.112:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:16:47:00 | WinXP | 109.110.132.155 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru :albat.somee.com **:boemaclasic.ro TH:www2.bpp.go.th :caetanojrecruz.adv.br DE:buyukfirsat.bu.funpic.org GB:www.bsnlondon.co.uk :dincermakinasanayi.com.tr DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
17:56:00 | Win2K-f | 186.58.210.150 (COM.AR): TELEFONICA DE ARGENTINA, AR. (DSL) |
n/a | :www.maxmind.com DE:131.220.6.26:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:05:00 | Win2K-f | 190.196.2.74 (GTDINTERNET.COM): SERVICIOS ADSL GTD INTERNET, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
n/a | US:www.yahoo.com :hgdtsxst.net :yeezcmpvoh.org :ibhjrmvofl.org :iqdeqfnevu.com :anuzjjrwsdj.net :uqobum.com US:ehhrfomhh.biz US:lpqecdhh.biz :ohoimwper.info :mtytumgjztj.org :cjnps.org :wlravwrze.info :ttmqybfvmm.com :rhnqyj.org US:oztozhf.biz :fezfqcxncf.info US:aetfzh.biz :hfrbgxib.net :fkkevfkqayx.com :xxeqnyssjv.net :weadj.info :gbusdjhil.org :moexs.org :qxcxi.org US:rplshocz.biz :memeeoiiye.net :vnjqsgpm.net :qqwktyzodu.info US:ximlhciu.biz :kfvtiafh.info :bjyms.net :votvkxti.net :uczmqvmaqyn.net :vkrsorgi.org US:eyozzzpzme.biz US:oylzwa.biz :qjnowmap.info :aqelth.com :fqtdlfzl.com :azkeaf.net :hwoli.com :uqsdcxjf.com :rxinuyuv.org :zhntghfw.info :lrbjxoim.com :avclathz.net :pzduprjn.com :oithk.info US:fsztivpj.biz :pzbbkgdgm.org US:lngrpnaj.biz :ijjfjs.net :qcacoxjepeh.org :bokyujlp.info :zzcri.net :hhkaeltys.com US:cckofw.biz :brixah.net :ocwdbhjxv.org :pwqgfjmd.net :elzdckwri.com :rpwvdncd.net :shhqdegdgqc.info :mirdufqqw.info :dymcpppzyaz.net :fqnuju.org :pvmcg.com :otrmemrcvkw.org :gsljseoa.org :jhjiaea.info US:204.152.184.139:80 98.138.253.109:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:22:37:00 | WinXP | 89.145.131.32 (-): HOME ETHERNET NETWORK, RU. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru :albat.somee.com **:boemaclasic.ro TH:www2.bpp.go.th :caetanojrecruz.adv.br DE:buyukfirsat.bu.funpic.org GB:www.bsnlondon.co.uk :dincermakinasanayi.com.tr |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
T:23:34:00 | WinXP | 109.191.67.156 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru CA:jewellerybazaar.net BR:casaebar.com.br :canossadhule.in :cansesiasknefesi.com DE:how2gethazanat.ho.funpic.de :www.evishop.de :chihuahuaupinghome.com IN:dehaspas.com |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 42 | 8689eac5d3 NEW |
none[none] | none:none |
none|none | none | none |