Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:28:00 | Win2K-f | 176.53.44.154 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
05:52:00 | Win2K-f | 95.72.4.80 (-): ZHUKOVSKY FLATE RATE POOL, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
12:40:00 | Win2K-f | 197.28.19.135 (-): . |
n/a | EE:www.starman.ee FI:www.if.ee EE:www.online.if.ee US:trafficconverter.biz FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
16:17:00 | Win2K-f | 111.242.157.146 (-): . |
n/a | US:www.ask.com :vpkgxhl.net :xpajyxzx.info :movrxau.info :otyvsgbc.org :bdwqume.org US:eomqzrqe.biz :wglfbz.org :ojxdwh.org :tpfluzq.com :lzrffm.com :kcaafdf.com :egzrrugfij.net :tufvmo.org :swwuasn.org :ccdtjc.info US:ukcpf.biz US:oqqosy.biz :yhutow.com :jiewx.com :fknsdeufodp.org :pugckcdbp.com :ockelylle.info :rdfvunbh.com US:sdnsxqbk.biz :dfsqwvfms.info :idyrtrxspue.info :hokgygvy.net :mhiit.net :iiqduudl.net :mjchkvly.org US:ljsfnz.biz :udqtndhutd.com :ijkbcwzr.org :ykkjg.com :isuckxq.org :ngtflvhoyeg.com :junyuj.org :tnvzojdd.com :bgirpgxdlq.org US:nddrryhl.biz :iioslpl.com :bzrmpf.org US:erxnfr.biz :xyxree.com :ntxwutze.com :hlbhdjk.info :kdpsbvpti.info :uscxryzq.com US:vkxzcvq.biz :wnmtm.info :wsdsz.net :ozzifnqr.net :fmvfcaebgf.info :arqmwiq.info :ycjbhpr.net :ukzoliu.org US:wfpgovcchul.biz US:mvafepoco.biz :yirol.com :rygwkvbw.info :dgksfzdknmm.net :fbuurx.net :qvkirpzt.net :fhsqqcc.com :amcohofm.org :sjtltx.org :swymhgzyf.net US:kxtgrlbq.biz US:hfqhswsd.biz :sdvjaerm.net US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |