Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:02:45:00 | WinXP | 159.224.35.248 (TERMBILLING.COM): VARIOUS REGISTRIES, UK. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru :albat.somee.com **:boemaclasic.ro TH:www2.bpp.go.th :caetanojrecruz.adv.br DE:buyukfirsat.bu.funpic.org |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.8 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
T:03:37:00 | Win2K-f | 69.17.112.154 (SPEAKEASY.NET): LAX BRIDGED CIRCUITS, LOS ANGELES, CALIFORNIA, US. (DSL) |
n/a | EE:www.starman.ee FI:194.215.38.135:80 |
139 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:04:20:00 | WinXP | 31.41.235.10 (-): . |
213.155.14.161:80 | DE:citi-bank.ru DK:bem.dk US:banboon.com MY:bdb.com.my TH:baulaung.org IR:bazyar-arya.com :barlikinsaat.com.tr TR:basamakhalisi.com |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | b76758d4ca NEW |
none[none] | none:none |
none|none | none | none |
T:05:36:00 | WinXP | 31.41.235.10 (-): . |
213.155.14.161:80 | DE:citi-bank.ru DK:bem.dk US:banboon.com MY:bdb.com.my TH:baulaung.org IR:bazyar-arya.com :barlikinsaat.com.tr TR:basamakhalisi.com |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | b76758d4ca NEW |
none[none] | none:none |
none|none | none | none |
T:06:59:00 | WinXP | 199.27.98.74 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 0c38af69f4 NEW |
none[none] | none:none |
none|none | none | none |
T:07:17:00 | WinXP | 5.228.62.66 (-): . |
n/a | PT:siliconfireware.ru :wpad RU:www.bbin.ru :www.google-analytics.com :fonts.googleapis.com :themes.googleusercontent.com :html5shiv.googlecode.com RU:binbank.ru RU:counter.yadro.ru RU:mc.yandex.ru CA:www.cwbank.com |
445 | pcap | raw alerts ruleset |
http http http http 377 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee NEW |
none[0] | none:none |
ASPack| | lines=298 embedded dns |
trace |
T:17:19:00 | Win2K-f | 61.221.199.108 (HINET.NET): DATA COMMUNICATION BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (100Mbps) |
n/a | EE:www.starman.ee FI:194.215.38.135:80 EE:62.65.192.25:80 |
135 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
17:37:00 | Win2K-f | 2.93.24.41 (-): . |
n/a | FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:39:00 | Win2K-f | 91.98.122.50 (PARSONLINE.NET): POOL FOR BROADBAND CUSTOMERS, TEHRAN, ESFAHAN, IR. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:www.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 EE:62.65.192.25:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:47:00 | Win2K-f | 190.75.234.156 (MOVILNET.COM.VE): CANTV SERVICIOS VENEZUELA, CARACAS, DISTRITO FEDERAL, VE. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee US:trafficconverter.biz FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 EE:62.65.192.24:80 EE:62.65.192.25:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:57:00 | Win2K-f | 94.52.37.168 (-): NEW COM TELECOMUNICATII SA, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:www.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:28:00 | Win2K-f | 59.124.219.26 (-): HU DONG NET DIGITIZE TECHNOLOGY CO. LTD, TAIPEI, T'AI-PEI, TW. (100Mbps) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |