Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:59:00 | Win2K-f | 1.187.179.204 (-): . |
n/a | EE:www.starman.ee FI:www.if.ee FI:194.215.38.135:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
02:23:00 | Win2K-f | 113.16.98.129 (163DATA.COM.CN): CHINANET GUANGXI PROVINCE NETWORK, NANNING, GUANGXI, CN. (DSL) |
n/a | CA:www.msn.com :errhuarg.com :czoebcwrqj.info :nzhotgtqzi.com :ddqsoic.net :ojsii.org :kkwlmzgy.org US:xkejmtdbci.biz :yogaouul.org :weisd.info :ckoityotv.com :qqnkwz.org :ytvqmwztm.net :gikwja.com :wporh.net :fyskqurkio.com US:aznakixcwg.biz US:dvnquvfyq.biz :bmtphwdw.net :temzpiikay.org :ovsmfi.org :wajanvnz.org :bjhpuj.com US:naaxpss.biz :gusblfwy.info :vmjszgz.com :phohfvwrjsi.net :cvipq.com :jphtq.info US:zevduxvuhc.biz US:nacsdxddw.biz :mbqxhljoe.org US:jdxjmidr.biz :bxtsig.com :bnkszwjz.net :flvjzqugxs.net US:bsxow.biz :kivhpypyj.org :mzzdovzevyh.org :tpocpmyb.com :xxmulgve.com :hbnzv.net :pxasw.info :cbwjxhr.org US:krdqpfthnm.biz :msubbxfa.net :utjfjj.com :ojdrgq.org :yoldpjykzjh.info US:quwskpdz.biz :gloitmcpbn.org US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:02:25:00 | WinXP | 109.161.60.39 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru US:kidos-bank.ru |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | 269ce49eb2 NEW |
none[none] | none:none |
none|none | none | none |
02:34:00 | Win2K-f | 189.203.203.22 (NIC-R2-R1-MTY.NIC.MX): NETWORK INFORMATION CENTER MEXICO, MX. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
03:45:00 | Win2K-f | 92.247.254.248 (92-247-240-10.SPECTRUMNET.BG): SPNET-PPPOE-POOLS, VARNA, VARNA, BG. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
03:46:00 | Win2K-f | 88.132.60.37 (PRTELECOM.HU): PRTELECOM-CP, NAGYKOROS, PEST, HU. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
03:52:00 | Win2K-f | 88.147.238.106 (SAN.RU): NETWORK OF SARATOV BRANCH OF OJSC VOLGATELECOM, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
03:56:00 | Win2K-f | 182.68.155.117 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
04:06:00 | Win2K-f | 123.16.26.100 (LOCALHOST): VIETNAM POSTS AND TELECOMMUNICATIONS(VNPT), VN. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
04:11:00 | Win2K-f | 178.211.52.170 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
04:16:00 | Win2K-f | 95.140.207.3 (CUSTOMERS.ADC.AM): ARMENIAN DATACOM COMPANY, YEREVAN, YEREVAN, AM. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
04:21:00 | Win2K-f | 81.190.44.148 (MM.PL): MULTIMEDIA POLSKA S. A, LODZ, LODZKIE, PL. (DSL) |
n/a | FI:194.215.38.135:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
04:26:00 | Win2K-f | 151.64.193.82 (51-151.NET24.IT): IUNET-BNET, BASSANO DEL GRAPPA, VENETO, IT. (DSL) |
n/a | :suyslg.net :ufhygdboi.net :tdihnziwilc.net :sktvr.org :blywuusmpsr.org :yoldpjykzjh.info :bkoqridk.info :xhmew.info :kahumgh.com :inzstbxl.org US:dgfqrvwf.biz US:vxmnw.biz US:xkejmtdbci.biz :vimwbbtttv.com US:lnqylhteme.biz :utjfjj.com :uhmful.com US:bphwlmbos.biz :gjrsso.org :ledvnuhodob.org US:owcsfdnk.biz :fuhyzbxsvzm.org :qoyfag.org :ddqsoic.net :jszzjkbr.net :ixikgt.com :temzpiikay.org :btwlblua.net :ikhrvasv.net :isoum.com :waxttve.info US:ljxmvlq.biz US:pdyfhrugf.biz US:krdqpfthnm.biz :phohfvwrjsi.net :uffzywjxf.net :ztvwjm.net US:qiombpfqwkk.biz :xqtpmlvdiog.org :fgkyrimwk.net US:149.20.56.32:80 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
06:36:00 | Win2K-f | 114.44.221.191 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | FI:194.215.38.135:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
06:56:00 | Win2K-f | 71.173.36.140 (VERIZON.NET): VERIZON INTERNET SERVICES INC, WILKES BARRE, PENNSYLVANIA, US. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:www.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
06:59:00 | Win2K-f | 41.56.90.180 (-): . |
n/a | EE:www.starman.ee FI:194.215.38.135:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
07:14:00 | Win2K-f | 46.107.115.28 (-): . |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
07:19:00 | Win2K-f | 96.244.154.74 (VERIZON.NET): VERIZON INTERNET SERVICES INC, US. (DSL) |
n/a | EE:www.starman.ee :www.maxmind.com FI:194.215.38.135:80 EE:62.65.192.24:80 EE:62.65.192.25:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
07:24:00 | Win2K-f | 126.45.120.81 (BBTEC.NET): JAPAN NATION-WIDE NETWORK OF SOFTBANK BB CORP, TOKYO, TOKYO, JP. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee CA:www.msn.com :blywuusmpsr.org :eeumekpl.info :mmkdbze.info :zcqyyijw.com :eqgaq.org :nqhfdnoqt.com :iwxenq.org :bfxbcgummlf.info US:nacsdxddw.biz US:qjtffmpz.biz US:shszzhzezsh.biz :ssrgntixfk.com US:naaxpss.biz :cewzy.com :gmtwnifoq.org :lypfju.info US:dvnquvfyq.biz US:kljmbcfhnfr.biz :vzoau.info US:xpoopopmq.biz FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
07:32:00 | Win2K-f | 201.187.92.28 (-): . |
n/a | :www.maxmind.com :getmyip.co.uk :www.getmyip.org US:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | 917c085aca NEW |
none[3] | none:none |
Armadillo| | none | trace |
07:44:00 | Win2K-f | 177.64.91.93 (-): . |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
07:54:00 | Win2K-f | 61.41.1.40 (CHODANG.COM): DACOM CORP, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
08:27:00 | Win2K-f | 109.184.68.98 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:10:34:00 | WinXP | 93.157.157.142 (HISPEED.PL): USLUGI INTERNETOWE MAJESTIC, PL. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru CA:jewellerybazaar.net BR:casaebar.com.br :canossadhule.in :cansesiasknefesi.com DE:how2gethazanat.ho.funpic.de |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 43 | ca3e3b13f3 NEW |
none[none] | none:none |
none|none | none | none |
11:01:00 | Win2K-f | 188.168.109.15 (-): CLOSED JOINT STOCK COMPANY TRANSTELECOM, RU. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee US:www.w3.org :gprknxnt.org :fhjzkekuca.org :gwqdb.info :oiwxcfkya.org :wporh.net US:owcsfdnk.biz :fdylqijpsa.org :nwswyrtibdp.info :qfxnsbizr.net :sktvr.org US:xpoopopmq.biz :vglnnpor.com :gycylqnt.net :ftcihcad.info US:tbnvwqscitd.biz US:rkdkbiv.biz :zoqsmtrfeui.info :kahumgh.com US:naaxpss.biz :hiazedx.com FI:194.215.38.135:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
11:20:00 | Win2K-f | 118.160.92.135 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | EE:www.starman.ee FI:194.215.38.135:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
13:56:00 | Win2K-f | 176.100.148.159 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 15 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
14:06:00 | Win2K-f | 187.34.92.59 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | CN:www.baidu.com US:shszzhzezsh.biz :lcvrxl.com :gprknxnt.org :gcbxox.com :dhqnlm.com US:ahdfdwahz.biz :grjmpevtrqs.com :xxujdpfvpo.net US:nacsdxddw.biz :bfexx.com :ojdrgq.org :yjioxpaf.org :uzipa.net US:sbuza.biz :hbnzv.net US:gnnuedniy.biz US:siioqj.biz :ovsmfi.org :weisd.info :ftcihcad.info :gusblfwy.info :fyskqurkio.com :oorqqldx.org :qxkeadzw.info US:xpoopopmq.biz :stcpsn.com :rcdgcsfscky.info :qxetwf.com :dmmlkjkb.net US:quwskpdz.biz :zurbtis.org US:kscqct.biz :eljtbodo.com :ytvqmwztm.net :hiazedx.com :ckoityotv.com :ufhygdboi.net US:udhbjyfevs.biz :eeumekpl.info :gmmbmfywesg.net :cvipq.com :sktvr.org :zhjvjeckquw.info :tpocpmyb.com :pyaysxat.org US:vxmnw.biz :cbwjxhr.org :zskinvj.org :gnpyzwzlksj.com :ahoem.com US:149.20.56.32:80 184.105.203.8:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 12 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
16:42:00 | Win2K-f | 186.116.9.20 (-): . |
n/a | US:www.w3.org :sidsnf.info :vfecx.info :ruuqg.net :zltdheux.info :xocpf.org US:hhdboqazof.biz :djqlilurl.com :rghzh.info :rtlyxghrxbw.org :fdyffktpjc.info :dmzgkmk.org :vzcsipta.net US:amqps.biz :veuccbjt.info :hnbgvpy.org :sdbywf.org :xhgeu.com :sbsoaqshpv.net :joyuomtzmq.com :ubwraaoipii.net :nyrwclwqegh.net :qaeydizzgzb.net :mljsscsg.org :irdlqkb.info :qdxpxx.info :ztneste.info US:pmqimwtlu.biz :hfrbstnlcp.org :odeglkpzrhg.net :hdzjgebejfr.org :owhdj.net :awryj.com :jddtypsa.org RU:ecmos.net :phfbcikgu.org :ioxyfabz.org :kkkcs.org US:twpxivnqv.biz US:npsips.biz :vyjxlznet.org :eepprwzumb.org :ntwodpqa.info :pjltkwspenm.info :htywezxoabg.com :mzwvdxl.com :pffxhammuv.net :qnujcnr.info :fopjtuig.net :aeyaorzev.org :nbdxahby.org :etkjp.org :sthmrfnt.org US:ayawlfcv.biz :xbmjwejn.org :bsmpnmpl.com :midlpovj.info :likoqmcbaba.com US:pzyidhx.biz :ctdqtchdgi.org :csqskkrp.net US:rhwye.biz US:bicax.biz :xxmtjh.info :dezzgy.org :sbknnfqd.info :qbyqtfbg.net US:rxlyr.biz US:cwatiruro.biz :brjid.org :ciluuffp.info US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 20 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
17:26:00 | Win2K-f | 114.25.57.67 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | EE:195.50.195.10:443 EE:62.65.192.25:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
17:31:00 | Win2K-f | 108.131.103.242 (-): . |
n/a | FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 8 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
17:36:00 | Win2K-f | 190.174.247.183 (COM.AR): TELEFONICA DE ARGENTINA, AR. (DSL) |
n/a | FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.25:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
17:45:00 | Win2K-f | 123.27.108.220 (LOCALHOST): VIETNAM POSTS AND TELECOMMUNICATIONS(VNPT), HO CHI MINH CITY, HO CHI MINH, VN. (DSL) |
n/a | US:kxdcadveu.biz :pjltkwspenm.info :eepprwzumb.org :etkjp.org :awryj.com US:hvhamet.biz :whvcwnm.org :veuccbjt.info :nyrwclwqegh.net :otpzofvkqx.info :qdxpxx.info :vxbgypyn.org US:smsodd.biz :slckngmjta.org :pkidtkkhjgh.net :joyuomtzmq.com :lfyevuu.info US:bilaae.biz US:amqps.biz :txxbqdsgbt.info :lgeljlorj.net :ycghjnoyksi.com :ugfxrdcl.com :xjpddd.org :orvjmpeiykp.com :mzwvdxl.com :zmdrxanxwmp.net :dzuonaojl.org :kuefzk.info :jddtypsa.org :rtlyxghrxbw.org US:ayawlfcv.biz US:zffoukedtr.biz :rqzqa.info :itfnms.org :hdzjgebejfr.org :hlbkeqzs.org :jnpsuf.org US:pzyidhx.biz :ctdqtchdgi.org :eiyjd.org :djqlilurl.com US:jrijirc.biz :gzawmfdg.org :cdksgnrns.info :pmdec.info :xmgehd.org :ujzxia.com US:npsips.biz :fawfsyh.net :cmxnt.info :gexxuddpn.net :eddviemlnr.org :bewaifhh.com :fopjtuig.net :wlcqbkkc.com :kzdtvmci.com :sirrrecvv.info US:lzsmeiowm.biz :vfecx.info :www.maxmind.com US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:46:00 | Win2K-f | 180.222.216.203 (-): . |
n/a | :getmyip.co.uk US:checkip.dyndns.org :www.getmyip.org EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
23:53:00 | Win2K-f | 201.43.20.227 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | :www.google.com :bsmpnmpl.com :yauqxa.net :xbmjwejn.org :fdyffktpjc.info :kgpueagnayd.org :estjncfo.com :ueskptiy.net :hfrbstnlcp.org :jwtnqqcz.org :gmvntgw.info :vzcsipta.net :edxogmdqr.info :mhpkc.net :fuhjxcn.org :ezmeiyzu.org :jnpsuf.org :xpuelehkbd.com US:tqykynlorg.biz :mjcvxswj.com :bdnfeyawyl.net :cmlxtqs.info :ixfihej.org US:myniuwvss.biz :obocty.net :lqzsrqd.org :ctdqtchdgi.org :zwdbxj.net :aovyn.net :xjpddd.org :rpmgphcp.net :eiyjd.org US:hhdboqazof.biz :lgeljlorj.net :ilczlhan.net :midlpovj.info :kghjwxhy.org :suholdbu.com US:iaxbrcdbcqq.biz :txxbqdsgbt.info :ubwraaoipii.net :irdlqkb.info :gzawmfdg.org :xmgehd.org :eddviemlnr.org :nrapnhmh.net :vumdoeri.org :pnuaooxmn.net :xrbdlh.net :rqrketx.com :pcnak.org :uxxoklcqww.com :jbyswxwkxa.org :knjrlakczs.com :xhqwgukcw.info :kuefzk.info US:jzjewvewbta.biz US:rhwye.biz :nudbnl.info US:pmqimwtlu.biz :ayvswjtduh.net US:149.20.56.34:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |