Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
06:42:00 | Win2K-f | 2.90.136.234 (-): . |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:www.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
08:47:00 | Win2K-f | 95.49.36.58 (TPNET.PL): NEOSTRADA-ADSL, WARSAW, WARSZAWA, PL. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee EE:www.online.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
08:57:00 | Win2K-f | 95.42.252.49 (95-42-224-10.BTC-NET.BG): BULGARIAN TELECOMMUNICATIONS COMPANY PLC, SLIVEN, SLIVEN, BG. (DSL) |
n/a | US:trafficconverter.biz EE:www.starman.ee FI:www.if.ee EE:www.online.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
09:07:00 | Win2K-f | 188.229.3.119 (RIPE.NET): EUROPEAN REGIONAL REGISTRY, UK. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee EE:www.online.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
09:17:00 | Win2K-f | 89.47.240.226 (PANEVO.RO): SC PAN ELECTRO SRL, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
14:27:00 | Win2K-f | 41.232.138.242 (NILE-ONLINE.NET): AFRINIC, CAIRO, AL QAHIRAH, EG. (DSL) |
n/a | US:www.yahoo.com :dcllv.info :gpenfp.net :hrppxved.org :qrpilfcyy.net :ayzmtscomc.info :kfrygpbcziz.org :metyhjyn.com :cvllc.com :muxxjip.net US:bxzoenn.biz US:cjwdin.biz :eqdfg.org :izmiy.net US:vmdoiubnf.biz :uucalpte.com :tivtzpl.net :chkufedifet.net :jxgayiotym.net :nchgjqrno.net :suhkfeksx.info :pjmgguvs.org US:jouldvcb.biz :omunbkwkgse.com :vttwdmqddbk.com US:xulbo.biz :puooa.net :mybdgms.com :fjonbrymod.net :tyywwm.org :sdrlwoav.com :tempmmhn.info :avekuc.org :sibjqnvweez.org US:gavwrpdf.biz :vsvkyvrsj.info US:jibxgpzehh.biz US:fqwhaewx.biz :ueoxrb.org :qikeygrpt.org :iqlgfnqlks.info :qxcwouzpe.net :ydzgndsxw.org :xyqemgiyvwl.info :ryqhuoml.net :swuukpjx.net :oeofk.org :dvkbehfw.info US:tdshp.biz US:morxyqta.biz US:duifssie.biz :xajptowp.org :jvpouzvhxmp.info :vecwjd.org :oyfzoyjx.info :lyytmrvpwq.com :mkttpbtqdvd.org :csmwlr.info :dxvyy.info :libfuqgw.com :cmgqmifgz.com US:wwhwfivkg.biz US:yjmxuyzbsd.biz :ycqztaebib.org :xjrgom.com :xytxuqg.net :vegijyzvqh.com :zjvuyzevee.net US:jrerjebci.biz :gjvmbg.info :zysvscicl.info US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | dce58ec963 NEW |
none[none] | none:none |
none|none | none | none |
17:32:00 | Win2K-f | 204.111.65.42 (SHENTEL.NET): SHENTEL SERVICE COMPANY, WOODSTOCK, VIRGINIA, US. (DSL) |
n/a | US:ujlbyhw.biz US:sazytcgn.biz :cqfpcyd.info :ecsfx.net :bqbffk.org :ydbfhgahvgw.info :guserswjgn.info :gcoum.org :qexukrfrxfd.net :rsduwz.info US:149.20.56.32:80 FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 11 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:18:00 | Win2K-f | 218.173.28.149 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 23 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:28:00 | Win2K-f | 94.102.75.67 (DORUK.NET.TR): DORUKNET XDSL CUSTOMER BLOCK, ISTANBUL, ISTANBUL, TR. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:38:00 | Win2K-f | 203.189.143.140 (ONLINE.COM.KH): COGETEL ONLINE, KH. (DSL) |
n/a | :qsbabr.info :bfnldfcxve.org :mgyzquhyr.info :muqplvklt.info :avuyye.org :vkvvflhgv.net US:umancqesinn.biz :vfbrptqq.com :hyyyysidk.org US:icsefqgq.biz US:pqjugbhli.biz :rdedsu.org :kslbhedqp.com :dwgcgvct.com :ncbevezqpp.info :covao.com :degpn.com :upcatqubfia.com US:kavwf.biz :blwsg.org :mpwkhnjfyyt.net US:kltjjjzsosn.biz :fpszd.net US:dehglqhdzzu.biz :jeposvtk.org US:tuoxiuyygc.biz :hkrlxwynm.info :gmgmsduglm.info :zepvkewnz.com US:khveabtxtg.biz :ugzzztlnrky.net :pwlht.org :laeuw.net :dwqpmkomw.net :sdfaxnka.com :mazaz.org :bflbt.net :ybenqiyy.net :cnecrhij.info :rmbmgzim.net US:kkwcilnwhu.biz :nbzcqqbmfv.info :lphocxwrt.org US:cnrtsdoun.biz :xwknl.info :febdctbktss.org :bbsvay.info :bihtvglw.com :txeeg.net :thtgmnr.net :qnxsqwcuntq.info US:csxrhbfsta.biz :doikzgsgylr.com US:mbifd.biz :kzzgxeuo.info :ibqyxhkbbm.info :prlgcvikk.org :txfksc.org :oelntvkfvj.org :zydef.org EE:www.starman.ee EE:www.online.if.ee FI:www.if.ee US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:48:00 | Win2K-f | 77.65.26.213 (ICPNET.PL): ICP NETWORK, POZNAN, WIELKOPOLSKIE, PL. (DSL) |
n/a | EE:www.online.if.ee EE:www.starman.ee FI:www.if.ee EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:58:00 | Win2K-f | 177.69.135.82 (-): . |
n/a | EE:www.online.if.ee EE:www.starman.ee FI:www.if.ee |
445 | pcap | raw alerts ruleset |
http 16 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
21:18:00 | Win2K-f | 27.78.68.193 (-): . |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:www.if.ee EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
http 10 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
21:28:00 | Win2K-f | 122.183.102.226 (122.AIRTELBROADBAND.IN): BHARTI AIRTEL LTD. TELEMEDIA SERVICES, NEW DELHI, DELHI, IN. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:www.if.ee EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
http 8 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
21:38:00 | Win2K-f | 186.244.27.50 (-): . |
n/a | EE:www.starman.ee EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
http 8 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
21:48:00 | Win2K-f | 1.172.169.28 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 24 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
21:58:00 | Win2K-f | 31.23.134.236 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 20 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
22:08:00 | Win2K-f | 186.46.129.170 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
22:42:00 | Win2K-f | 203.187.195.234 (YOUTELE.COM): IQARA TELECOM INDIA PVT LTD, VADODARA, GUJARAT, IN. (DSL) |
n/a | EE:www.online.if.ee FI:www.if.ee EE:www.starman.ee FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |