Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:41:00 | Win2K-f | 190.202.118.82 (CANTV.NET): CANTV SERVICIOS VENEZUELA, CARACAS, DISTRITO FEDERAL, VE. (DSL) |
n/a | :uqsdcxjf.com US:myskmgg.biz US:efkpljx.biz US:yqfjhqmbvh.biz :vnjqsgpm.net :hahnhp.org :vgkpsto.info :pbtazjh.net :hkakrnklac.net :fixwyeni.org :wlravwrze.info :bcfnnubq.org US:qccgshw.biz :bkotsppqk.org US:ghwvoaaxs.biz :zgvqnak.org :jqsazpuowxx.com :inovso.info :gbusdjhil.org :jjvyug.info :wgaxanqc.net :fezfqcxncf.info US:nhtbs.biz US:gtiwoprec.biz :vbvvnjpb.net :kczlku.com :otypeqbkuo.com :skuxixqzfyv.org :lrnglq.org :pvmcg.com US:lpqecdhh.biz :bjcojzz.net :gyemnif.org :bmcjzpu.org US:ihdcwgotujg.biz :nkbbnbrabwa.com US:nustyzqc.biz :ocwdbhjxv.org :ttmqybfvmm.com :mjhmdjrx.net :ohoimwper.info :kqpdmjig.com :wrjjbgrqc.net :szyunm.net :qcacoxjepeh.org US:epmis.biz :lnsjtygf.org :iwzojaqblvj.info :hvmyrslcp.net :swnune.com :pmcxgl.org :eygmlq.info :khlmocqh.net :hveifb.info :dojkjtke.info :wjayzfrzpf.com :feujy.com :anzytpipb.org US:wcyfsmfa.biz :cdunbmcz.info US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
02:14:00 | Win2K-f | 216.55.43.166 (XO.NET): XO COMMUNICATIONS, HERNDON, VIRGINIA, US. (DSL) |
n/a | :www.google.com :ckhfkauh.info :xqpnxxun.net :qcacoxjepeh.org :hgdtsxst.net :yeezcmpvoh.org :gnoyg.net :fkkevfkqayx.com :hvmyrslcp.net US:vpilaqjp.biz :jqsazpuowxx.com :kazce.net :sxfybotg.net :xxorsfhqfp.com :fcucwizk.info :kqrnfn.org :bghkj.org :gbusdjhil.org US:rwywndhswul.biz :bcfnnubq.org US:oylzwa.biz :yupdbgceaqq.info :aqelth.com :swnune.com :zzcri.net :kwtwovnpiar.net :kxubvw.info :bmcjzpu.org :vuvbtbhfbpx.com :oukigngvtyo.com :nkbbnbrabwa.com :byzubtrpu.info :cdunbmcz.info :uqobum.com :kqpdmjig.com US:nhtbs.biz :lrcjpixl.org :ryzvcsr.org :onvyasahbs.info :pmcxgl.org :rtmjq.org US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:04:17:00 | WinXP | 79.162.128.89 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru CA:jewellerybazaar.net BR:casaebar.com.br :canossadhule.in :cansesiasknefesi.com DE:how2gethazanat.ho.funpic.de :www.evishop.de :chihuahuaupinghome.com IN:dehaspas.com TR:devdijital.com US:sobrenaturalbr.net BR:direitopublico.com.br :adult-empire.com |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 9ebcc2e373 NEW |
none[none] | none:none |
none|none | none | none |
06:21:00 | Win2K-f | 222.41.170.130 (HERBALQC.COM): CHINA RAILWAY TELECOMMUNICATIONS CENTER, BEIJING, BEIJING, CN. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
06:21:00 | Win2K-f | 93.113.149.35 (-): SC C.O.CO SRL, RO. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
06:27:00 | Win2K-f | 117.193.219.87 (10/24.BSNL.IN): NIB (NATIONAL INTERNET BACKBONE), DELHI, DELHI, IN. (DSL) |
n/a | US:trafficconverter.biz | 445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
06:37:00 | Win2K-f | 94.176.188.97 (INBOXDESIGNDNS.NET): SC INBOX DESIGN SRL, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
06:42:00 | Win2K-f | 187.66.85.67 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee FI:194.215.38.135:80 EE:62.65.192.24:80 EE:62.65.192.25:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
06:50:00 | Win2K-f | 124.123.202.49 (BEAMCABLESYSTEM.IN): INTERNET TELEPHONY SERVICE PROVIDER, HYDERABAD, ANDHRA PRADESH, IN. (DSL) |
n/a | US:www.ask.com :vtbryozbb.com :zgvqnak.org :ckmyqi.org :tnbncyuniy.org :szyunm.net US:nustyzqc.biz :ttmqybfvmm.com :dcfdcqym.com US:wcyfsmfa.biz :oukigngvtyo.com :qrfghpgv.com :dojkjtke.info :gxhzpvgis.info :cabszxgjqqa.org US:ehhrfomhh.biz :mjhmdjrx.net :skuxixqzfyv.org :lrcjpixl.org :kfbqssokyj.net US:msadcoeubm.biz US:lngrpnaj.biz :zhntghfw.info :wqpqkj.info US:ihdcwgotujg.biz :hdufhbfr.com US:tmswoa.biz :xucmakr.info :bjyms.net :pbtazjh.net US:tyovcn.biz :hkakrnklac.net :khfam.net US:myskmgg.biz :aqnph.net :lrbjxoim.com US:ximlhciu.biz :kazce.net :memeeoiiye.net :uhxshcr.info :pzduprjn.com :moexs.org :iqikp.net :bkotsppqk.org :kgikbbvajd.net US:htzjd.biz :lrnglq.org :oithk.info :rtmjq.org :zyzqzjyi.com :fezfqcxncf.info :kxubvw.info US:ghwvoaaxs.biz :fqtdlfzl.com US:kgcmr.biz :gbusdjhil.org :zfsdjk.info :nzyugnje.net :sxfybotg.net :ijjfjs.net :wfingry.net :votvkxti.net :oenlheds.net US:yqfjhqmbvh.biz :bghkj.org US:vpilaqjp.biz :xvakywpljp.org :vnjqsgpm.net US:qccgshw.biz US:oylzwa.biz :nipsjotphmo.info EE:www.starman.ee EE:www.online.if.ee FI:www.if.ee US:149.20.56.32:80 US:149.20.56.34:80 FI:194.215.38.135:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:10:26:00 | WinXP | 177.35.143.126 (-): . |
213.155.14.161:80 | DE:citi-bank.ru DE:www.kelesoglugroup.com :bleublanc.net TH:kabinburi.ac.th :bilimegitim.org :juvenopolis.org.br PT:buyukkarapinar.com EU:karenoil.com US:cajovnanazemi.cz **:beautiful-shop.rv.ua :cannabisverificationcenter.com US:clinicadematematica.com.br |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 42 | 0d1eb4df79 NEW |
none[none] | none:none |
none|none | none | none |
T:11:13:00 | WinXP | 46.40.34.32 (-): . |
213.155.14.161:80 | DE:citi-bank.ru CA:jewellerybazaar.net BR:casaebar.com.br :canossadhule.in :cansesiasknefesi.com DE:how2gethazanat.ho.funpic.de :www.evishop.de :chihuahuaupinghome.com IN:dehaspas.com TR:devdijital.com US:sobrenaturalbr.net BR:direitopublico.com.br |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 9276456bf8 NEW |
none[none] | none:none |
none|none | none | none |
T:11:34:00 | WinXP | 109.191.67.156 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru CA:jewellerybazaar.net BR:casaebar.com.br :canossadhule.in :cansesiasknefesi.com DE:how2gethazanat.ho.funpic.de :www.evishop.de :chihuahuaupinghome.com IN:dehaspas.com TR:devdijital.com US:sobrenaturalbr.net BR:direitopublico.com.br |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 42 | 8689eac5d3 NEW |
none[none] | none:none |
none|none | none | none |
12:41:00 | Win2K-f | 174.36.209.242 (SOFTLAYER.COM): SOFTLAYER TECHNOLOGIES INC, DALLAS, TEXAS, US. (DSL) |
n/a | FI:194.215.38.135:80 US:204.152.184.139:80 EE:62.65.192.25:80 |
445 | pcap | raw alerts ruleset |
http 17 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
15:01:00 | Win2K-f | 111.253.246.89 (-): . |
n/a | FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.25:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
16:05:00 | Win2K-f | 204.97.99.10 (ISMNET.COM): I-2000 INC, METUCHEN, NEW JERSEY, US. (DSL) |
n/a | :www.google.com :inovso.info :xqpnxxun.net :qxgpzpdsr.org US:tyovcn.biz :ifbfcu.org :emujhp.com :jeojuxim.com :hfrbgxib.net :mirdufqqw.info :zgymkdjc.org :uqsdcxjf.com :jhjiaea.info :shhqdegdgqc.info :nipsjotphmo.info US:lngrpnaj.biz :ejkxpye.com :hzddewh.com :vuvbtbhfbpx.com US:fkokc.biz :oldeumlnii.com :zyzqzjyi.com :swnune.com US:gtiwoprec.biz :gsljseoa.org :ckmyqi.org US:efkpljx.biz :iyvbuq.com :pjfop.com :qjnowmap.info :hgdtsxst.net :pzduprjn.com :ycvlcpdeza.net :bcfnnubq.org US:iowsnx.biz :stbbzv.info :pmcxgl.org US:kgcmr.biz :rpwvdncd.net US:hgkjcrhqtl.biz :aqelth.com :ibhjrmvofl.org :votvkxti.net :lrbjxoim.com :pvmcg.com :iqdeqfnevu.com :kqpdmjig.com US:jmupgdkz.biz US:bbkasvombq.biz :otrmemrcvkw.org :liqstpzzek.info :kgntq.com US:yvantzgzgdq.biz :vnjqsgpm.net :hqhciy.org :bghkj.org :cclioo.org :nzyugnje.net :khfam.net US:wkzlqpmrkkh.biz :nbnfqvfns.net US:trafficconverter.biz :xhvveaioas.net US:msadcoeubm.biz :byzubtrpu.info :khlmocqh.net US:ximlhciu.biz :szyunm.net :vkrsorgi.org :wrjjbgrqc.net :zfsdjk.info :kgikbbvajd.net US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:16:26:00 | WinXP | 93.157.157.142 (HISPEED.PL): USLUGI INTERNETOWE MAJESTIC, PL. (DSL) |
n/a | DE:citi-bank.ru CA:jewellerybazaar.net BR:casaebar.com.br :canossadhule.in :cansesiasknefesi.com DE:how2gethazanat.ho.funpic.de :www.evishop.de :chihuahuaupinghome.com IN:dehaspas.com TR:devdijital.com US:sobrenaturalbr.net BR:direitopublico.com.br DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
37 of 43 | ca3e3b13f3 NEW |
none[none] | none:none |
none|none | none | none |
16:27:00 | Win2K-f | 180.199.108.32 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 15 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:17:46:00 | WinXP | 123.220.43.80 (OCN.NE.JP): OPEN COMPUTER NETWORK, YOKOHAMA, KANAGAWA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
22:14:00 | Win2K-f | 189.104.59.166 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, SALVADOR, BAHIA, BR. (DSL) |
n/a | CN:www.baidu.com :erfdbtyh.org :ktstwsjteoe.com :vokbxz.info US:bsxow.biz US:udhbjyfevs.biz :qvxncveh.net :gcbxox.com :eneupuezgc.org :gprknxnt.org :froeem.net :errhuarg.com :tudakkse.com US:lnqylhteme.biz :xhmew.info :dmmlkjkb.net :ztvwjm.net :ojsii.org :gusblfwy.info :adxoumlq.com :vdkkmmjy.org :elpesczdl.info :gloitmcpbn.org :hdgdtq.net US:qiombpfqwkk.biz US:ghkffb.biz :qfxnsbizr.net :zurbtis.org :eebtina.com :iaihn.com :bxggfla.net :nwswyrtibdp.info US:nacsdxddw.biz :bxtsig.com :gwqdb.info :oswue.info :bkoqridk.info :voqxkuqm.com :jpbhjkwc.org US:geusy.biz :qsmwdjq.com :wajanvnz.org :fgkyrimwk.net :gjrsso.org :wtajbvdlb.com :tpqenineluh.org :iwxenq.org :oedzstz.com :tdihnziwilc.net US:klejejlimrt.biz :qqnkwz.org :ascgkbkowm.com :tihtzisx.info US:ljxmvlq.biz :pxasw.info :zlaykxxqrm.org :jmohdxvkxaz.info :rvybwkob.com :blywuusmpsr.org :pfutzlcuizp.org :vzoau.info :fdylqijpsa.org :fydkzjclzm.com :cvqvlvvz.info :gnpyzwzlksj.com :yoldpjykzjh.info :tedlkv.com US:xkejmtdbci.biz :flvjzqugxs.net US:pdyfhrugf.biz :gegkwwb.org US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 10 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |