Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
03:46:00 | Win2K-f | 88.87.16.107 (GW3-NAT.TELNET.BG): TELNET-MAN-NET, SOFIA, GRAD SOFIYA, BG. (DSL) |
n/a | :www.maxmind.com DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
10:19:00 | Win2K-f | 196.205.116.32 (LINK.COM.EG): LINK EGYPT, CAIRO, AL QAHIRAH, EG. (DSL) |
n/a | :www.google.com :tpldhmwq.org US:yrrqofgjyr.biz :dsthsv.com :oblxxopbt.net :imchpelpsmv.net US:czshvzznqlo.biz :izwssart.com :ovgwpvf.com :iokmiqzqpw.org :iduoaigw.com :krpxmpqier.info :nmfeocps.org :lpetxbv.net US:zoddsfdm.biz :szopttho.org :bhgacdbxg.com :tmnzkvlamv.com :fliswfw.org :nocyh.net :hhgbpnm.com :ejfburcc.com :olvbrjl.org US:laiifnf.biz :uxkhbofkrq.info :mqmhzseq.info US:hdfgvwwvtl.biz :kzoje.com :kmyoslqi.org US:rpjezkhz.biz :jvwgyvx.net :kvwwujbj.com :usbkrawofp.com US:qgrapvmef.biz :fxesuazfv.info :ptwqhsvmeh.org :ebocahgec.info :sauzqjodp.net US:cxhiajw.biz :vcrpcwtis.com :pucxqriy.com :bmdjz.net US:puncndrdxtk.biz :mzvwbsd.net :ejhsgb.org :itdjmpv.com US:hbqnaohdwp.biz US:mbhildv.biz US:ouxaxxixaq.biz :ivpiinfqh.info US:vgejgv.biz US:149.20.56.32:80 US:149.20.56.34:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:10:21:00 | WinXP | 117.254.217.94 (STERLINGSTUDENTS.NET): NIB (NATIONAL INTERNET BACKBONE), NEW DELHI, DELHI, IN. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru :parex-bank.ru |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:13:42:00 | WinXP | 37.252.73.141 (-): . |
n/a | DE:moscow-advokat.ru :gaspode.zanet.org.za SE:broadway.ny.us.dal.net SE:qis.md.us.dal.net NL:broekhuisjuweliers.nl :caen.fr.eu.undernet.org TH:btech.ac.th SE:viking.dal.net TR:btr.gen.tr :flanders.be.eu.undernet.org :los-angeles.ca.us.undernet.org TR:burakasansor.com NL:london.uk.eu.undernet.org ES:bytegraf.com TH:nt.go.th AT:graz.at.eu.undernet.org :cizreemlak.net :lulea.se.eu.undernet.org SE:coins.dal.net DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 048b720afe NEW |
none[none] | none:none |
none|none | none | none |
T:19:05:00 | WinXP | 178.37.20.121 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | aad01847fa NEW |
none[none] | none:none |
none|none | none | none |
19:56:00 | Win2K-f | 186.112.81.27 (TELEFONICA.NET.CO): COLOMBIA TELECOMUNICACIONES S.A. ESP, CO. (DSL) |
n/a | :elgunmlz.net US:wvjrmzav.biz :rhwtamoxzh.net US:rfjjcjjjmk.biz US:hgxat.com :pkulgdxkerr.com :xmfwr.info :zkeush.info :fsebjpcmwa.net :lkkqmwcghkm.net US:searchezy.com US:clicks.pureleads.com US:149.20.56.32:80 FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Argh : 0.3 profile |
none | summary tarball |
none | 44a12d46c7 NEW |
none[none] | none:none |
none|none | none | none |
23:01:00 | Win2K-f | 1.173.2.202 (-): . |
n/a | US:www.ask.com :tlqos.net US:zqcerpuzpsb.biz :vkjhly.net US:oufzz.biz :tffvxquqh.net :rwyjlzes.net :yqcaj.net :ttyeup.net :stsuxqajff.info US:jfwrcplw.biz :pzhyudmv.info US:nwbmkhoc.biz :bevfxli.info US:ggiukhhmjto.biz :ffyjvny.com :pixcx.com :mafihf.info US:zmsqxfre.biz :fcbwbm.org :wnkjnk.info :zeevoyaw.com US:nxlwgfvqpc.biz US:uazlvzjnt.biz US:gosreoxlrum.biz :dnzll.net :akwfsmlo.net US:egicwy.biz :losztbjc.net :vxgakk.com :xxwybzciahg.org :ccpijy.info :sihkskloeqv.org :vpofmmd.net US:hgxat.com :fztefwwwpab.net :uwlgnr.com :lhncuaxhktr.net :qylyvlhvbn.net :dqgwujeghr.info US:jydpfwzi.biz :vwzedneknyv.org :zkyaxbkb.com :zpitwitkxmp.org US:qfebawfb.biz :fcvkr.info :fjprw.info :mhpmgyvx.info :zlbjavrjq.net :rccxfivthcg.net :ktpcg.net :dggxve.net :rijczpsmq.org :tfqossvlkh.info :sehlofoemki.info :etkzubxcwn.info :zpeqbgdsxe.org :dqydwd.net :eghaysrx.info :inrgugp.net :dihgi.net :bfimicjkh.com :klorvyab.com :egbjlfteic.org :rbbxmgl.com :ezrzj.net :dytlpsof.info :ijhskx.org :swrfkt.info :hagcnbpk.org :jqjyei.org US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |