Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:10:00 | Win2K-f | 42.112.16.58 (-): . |
n/a | :www.maxmind.com :www.getmyip.org EU:checkip.dyndns.org :getmyip.co.uk DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
5 of 37 | 741c93f3c1 NEW |
none[3] | none:none |
UPX| | none | trace |
T:01:21:00 | Win2K-f | 14.139.85.117 (-): . |
n/a | EE:www.starman.ee FI:www.if.ee FI:194.215.38.135:80 EE:62.65.192.24:80 |
139 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
01:47:00 | Win2K-f | 93.81.63.135 (CORBINA.RU): BROADBAND CUSTOMERS IN ST. PETERSBURG, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | US:trafficconverter.biz CA:www.msn.com :hsdaf.com :czhoka.org :zajcgjzo.com :vmuxxmsm.net US:kidqr.biz :kmfdvwydgq.net US:ffthuiez.biz :vgfdvjgewjz.com :dhhonqwwijm.com US:rguaugwh.biz :stopnote.vhostgo.com :qezlq.com :rkuvkkuj.com :hzibgl.com :jbaung.com US:obyehxntkyf.biz :ntiytgav.org US:wzltgndh.biz :fmtqq.org :akvwy.net :bdkdslykfw.net :sxzmtrnz.com :bbiuxr.com :dmidism.com :zpqrc.info :bqzjdbhfyz.info :vmsgxmvryfo.org :tduqdkpf.info :slkwjv.com US:zlqpitif.biz US:gfwyxcwq.biz US:149.20.56.32:80 US:149.20.56.34:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:02:09:00 | WinXP | 46.40.34.32 (-): . |
n/a | DE:citi-bank.ru CA:jewellerybazaar.net BR:casaebar.com.br :canossadhule.in DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 9276456bf8 NEW |
none[none] | none:none |
none|none | none | none |
T:02:31:00 | WinXP | 109.191.91.243 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru CA:jewellerybazaar.net BR:casaebar.com.br :canossadhule.in :cansesiasknefesi.com DE:how2gethazanat.ho.funpic.de :www.evishop.de :chihuahuaupinghome.com IN:dehaspas.com TR:devdijital.com US:sobrenaturalbr.net BR:direitopublico.com.br :parex-bank.ru |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 42 | 8689eac5d3 NEW |
none[none] | none:none |
none|none | none | none |
02:39:00 | Win2K-f | 62.225.185.170 (MOEBEL-BRUCKER.DE): MOEBELHAUS BRUCKER GMBH, AACHEN, NORDRHEIN-WESTFALEN, DE. (100Mbps) |
n/a | FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
07:56:00 | Win2K-f | 82.211.172.233 (PLANETSKY.COM): PROVIDER LOCAL REGISTRY, CY. (DSL) |
n/a | US:www.ask.com US:snakjrtui.biz US:jvhqta.biz :xdvlctrj.info :qhyifepi.org :nuyqgbnicto.net US:djkxdib.biz :zkyekt.org :ilxosomb.net US:wzltgndh.biz :vgmji.org :nkeqhof.info :qxcfjopu.net :cwebeizt.info :qedlxw.org US:fgvowjv.biz :dwpoap.org :mffoarff.net :enfzbpzf.info :fnflazez.org :hntyqushpaw.info :sdyamloy.net US:zwsimeipu.biz :wtqvuqrpja.net :babkuao.net US:hxphgfpzbg.biz :mamxuh.info :jnkdiwjuzsi.com :ganfxdz.net US:jpqpmr.biz :fybsapzhfq.com US:149.20.56.32:80 US:149.20.56.34:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
09:04:00 | Win2K-f | 113.254.15.96 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | :ilxosomb.net :nedjg.com :lsjxbozd.info US:dgtxbo.biz US:aatwc.biz :mersk.net US:nxprayho.biz :ganfxdz.net :hntyqushpaw.info :mffoarff.net :gpwlehpkmze.org :wpxoxrldm.info :jdpoggg.info :wfepqq.net :irirahaef.net US:espzaauho.biz :tsqvnpap.info :nnwvhqlevq.org :hxvofbqw.info :qhyifepi.org :mcnhjs.net :znipl.com :mwfgvq.com :qqbskobh.net :pjfatn.org :hbkfwyvm.info :wierbbz.net :qbply.net :ixbipwvap.org :tgtmhpmcxjw.com US:sitght.biz :cupvqm.com :xdvlctrj.info :ebdezxxlxu.org :vuknfwulhq.net :hckpk.org :kfxlteqrka.com :hgavs.org US:ffthuiez.biz :irdibv.info :jzxykp.com :spbxxkfoiap.net :bxmkwub.org :ootwabx.org :fwstlg.info :pmdjetqa.net US:crxaarbk.biz :nuyqgbnicto.net :yjdswhojpwp.com :bbiuxr.com US:hxphgfpzbg.biz :bqzjdbhfyz.info :jyjvhkd.com :rgywadotr.info :jnkdiwjuzsi.com :vmuxxmsm.net :niquadtfw.info :qqxfhctivoj.org :hzdhr.info :lgzoj.info US:149.20.56.34:80 FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:10:07:00 | WinXP | 184.0.12.0 (EMBARQHSD.NET): EMBARQ CORPORATION, US. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:10:49:00 | WinXP | 217.245.186.186 (T-IPCONNECT.DE): DEUTSCHE TELEKOM AG, LEIPZIG, SACHSEN, DE. (DIAL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | a0139d7ad8 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:11:00:00 | WinXP | 70.60.132.174 (RR.COM): ROAD RUNNER HOLDCO LLC, COLUMBUS, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:31:00 | WinXP | 186.34.234.56 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | d0886c89bf NEW |
none[none] | none:none |
none|none | none | none | |
T:12:13:00 | WinXP | 46.162.234.76 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 | a4140e4032 NEW |
none[none] | none:none |
none|none | none | none |
15:28:00 | Win2K-f | 189.47.155.177 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, SãO PAULO, SAO PAULO, BR. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
16:04:00 | Win2K-f | 212.17.3.115 (SIBERIA.NET): MAGISTRAL TELECOM, NOVOSIBIRSK, NOVGOROD, RU. (DSL) |
n/a | EE:www.online.if.ee EE:www.starman.ee FI:www.if.ee EE:195.50.195.10:443 US:204.152.184.139:80 EE:62.65.192.24:80 |
139 | pcap | raw alerts ruleset |
http 7 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
16:09:00 | Win2K-f | 92.87.64.191 (-): TRANSCABLU, TULCEA, TULCEA, RO. (DSL) |
n/a | FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
16:14:00 | Win2K-f | 189.78.85.151 (TELESP.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, SãO PAULO, SAO PAULO, BR. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
16:24:00 | Win2K-f | 85.112.6.118 (-): AMERICATEL2-NET, MADRID, MADRID, ES. (100Mbps) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 7 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
16:34:00 | Win2K-f | 74.100.159.52 (VERIZON.NET): VERIZON INTERNET SERVICES INC, US. (100Mbps) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:16:44:00 | WinXP | 93.157.157.142 (HISPEED.PL): USLUGI INTERNETOWE MAJESTIC, PL. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
37 of 43 | ca3e3b13f3 NEW |
none[none] | none:none |
none|none | none | none |
16:44:00 | Win2K-f | 94.37.105.180 (CUST-ADSL.TISCALI.IT): TISCALINET, ROME, LAZIO, IT. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
16:54:00 | Win2K-f | 62.141.250.83 (MM.PL): MULTIMEDIA POLSKA S. A, TOMASZOW MAZOWIECKI, LODZKIE, PL. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 7 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
17:04:00 | Win2K-f | 2.94.191.198 (-): . |
n/a | EE:195.50.195.10:443 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:04:00 | Win2K-f | 58.71.8.244 (PLDT.NET): IPG, MANILA, MANILA, PH. (100Mbps) |
n/a | EE:www.online.if.ee EE:www.starman.ee FI:www.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:18:30:00 | WinXP | 122.121.7.66 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:moscow-advokat.ru :washington.dc.us.undernet.org SE:ced.dal.net SE:vancouver.dal.net :gaspode.zanet.org.za :lia.zanet.net AT:graz.at.eu.undernet.org :jsthomes.com TR:adiyamanlicigkoftecim.com **:akordketrzyn.ugu.pl TR:akcainsaat.com :lulea.se.eu.undernet.org SE:viking.dal.net US:akdari.com US:alsharqpaper.net DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 079642b8c1 NEW |
none[none] | none:none |
none|none | none | none |
T:21:16:00 | Win2K-f | 101.111.204.92 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
21:23:00 | Win2K-f | 123.79.50.138 (JWS.COM): CHINA TIETONG TELECOMMUNICATIONS CORPORATION, BEIJING, BEIJING, CN. (DSL) |
n/a | US:www.yahoo.com :sptijoidgz.org :attzpnf.com :lzlryd.info :plptylp.info :etfwhohv.info :qgmhmg.com :pusfkprsdwi.com :lgzrzjijw.com :wykglukbn.org :ylgvdtgboiz.info :tkxthitp.com :vntdeuouv.net :zryviojfxi.com :myata.net :erwaigxts.com US:lnwuvq.biz :hzmrhaxcme.org :bbnwjsof.org :ecabuwmgg.com :yjsgpsna.com :pkjtdcqjhr.com :ailwzfah.org :vhuzmrzfs.info US:viknhggebpi.biz :tpemxqyfja.info :actugfp.com :uxyrssv.org US:ugutjes.biz :muqrpbseu.com :cqpyczbq.net :aoihldhv.org US:sfnsv.biz :yhwootum.net :ywmjlk.org :qvjjjgobfgt.org :morztzod.org US:kgmgjemov.biz :huhfzneew.org US:iedyesleslr.biz :ytjvfpvzcq.com US:ygyou.biz US:hxpak.biz :kbjbi.org :rkaunrzeq.net US:bvohugck.biz US:jlworqitvri.biz :gzdivfdmzvp.net :rpqybsdpgm.org US:fgiwokmgs.biz :juzswop.org :vhsyzihsg.info :bkqjoieecc.org :hdgbmehf.info :fgkygbw.net :bymrrahmhph.org US:kzaihvrb.biz :wlotbq.net US:ozcrx.biz :rqzbv.net :dplzpsxdv.info :qxtrdyaqp.org :hslqxmypa.org :koqfmfzksb.info :mqjnf.net :oycyqqkp.com :sajikgyzv.com :fzmvhsmmye.net :glhtsho.net :ghorebhafl.org US:tgtolxi.biz US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |