Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
02:42:00 | Win2K-f | 114.45.93.19 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:www.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
02:47:00 | Win2K-f | 95.221.96.79 (-): FAIRLIE HOLDING & FINANCE LIMITED, RU. (DSL) |
n/a | EE:www.starman.ee :uvfvtbm.com :gmgmsduglm.info :ebdkozw.info US:ovlff.org US:tuoxiuyygc.biz US:iyzociktybl.biz US:nolceiygysb.biz :lrjabhmovz.info :mcpsksduxpo.com :oxelrnhifu.org :mazaz.org US:xgjrstjjnd.biz :hyyyysidk.org US:znlpkdqk.biz :oyywhe.info :xxnqhrjqod.org :rnhkudmp.com :uysrszscxtt.org US:khveabtxtg.biz :oelntvkfvj.org :muqplvklt.info :txfksc.org :pjxzyzvt.com US:vtgqj.biz :nwcaqb.info :vswdet.com :dyyneniifp.net :agdqiqes.org :qexukrfrxfd.net US:umancqesinn.biz :lwmwwllxn.org :ayfyojyzhj.org :fsqgmylpfi.info :ghhxdg.info US:fhthwwjy.biz :avuyye.org :ubmyocsmhw.com :ttaovbml.com :plfinrfrim.com :zinqukznojc.org :rmbmgzim.net :pudtp.net :nsjljufhkd.com US:enqzusojhvw.biz :hooagpfar.info US:dehglqhdzzu.biz :badvrsgu.net US:csxrhbfsta.biz :fjvvpfpv.net :nrakrqv.org :eeemchdrr.info :ijqxnbpy.com US:himefzhslbf.biz US:ediba.com US:rrfuntwx.biz :vfbrptqq.com :xbmgcgw.com US:cnrtsdoun.biz :yvldvbfb.com US:kltjjjzsosn.biz EE:www.online.if.ee US:149.20.56.32:80 FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
02:58:00 | Win2K-f | 182.52.250.250 (-): . |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:www.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
05:51:00 | Win2K-f | 24.133.64.51 (RIPE.NET): EUROPEAN REGIONAL REGISTRY, UK. (DSL) |
n/a | :www.google.com :txeeg.net :wfbpezej.com US:ltxxrswa.biz US:sazytcgn.biz US:pqjugbhli.biz :qexukrfrxfd.net US:oxxiuzlcsla.biz US:fiztoedl.biz :kzzgxeuo.info US:kltjjjzsosn.biz US:csxrhbfsta.biz US:ertfnhtkgga.biz US:fhthwwjy.biz :badvrsgu.net :qsahcrpancf.org :ibqyxhkbbm.info US:sxdoba.biz :dyyneniifp.net :lrjabhmovz.info :crsqrdwhjc.com :qsbabr.info :dzlewnd.org :gwwomjuods.info US:vpvnoznopr.biz US:dhrye.biz :glkaoakgd.org :fmqiw.com :agdqiqes.org :aqszuewozb.org :ghhxdg.info :jofdbymn.com :lphocxwrt.org :blwsg.org :zinqukznojc.org :bprkfznl.info :ayfyojyzhj.org US:ediba.com :pwyonqqc.org US:himefzhslbf.biz :mcpsksduxpo.com :gsfuxnboh.org :dwgcgvct.com :nrakrqv.org US:mbifd.biz :uysrszscxtt.org :vcytp.com :toulshjr.info :gcoum.org :bfnldfcxve.org :geibbeu.net US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
06:42:00 | Win2K-f | 101.86.162.4 (-): . |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:www.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
08:42:00 | Win2K-f | 190.12.100.101 (COM.AR): CPS, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:www.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 EE:62.65.192.24:80 EE:62.65.192.25:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
08:51:00 | Win2K-f | 72.9.15.156 (METROCAST.NET): METROCAST COMMUNICATIONS, LEXINGTON PARK, MARYLAND, US. (DSL) |
n/a | EE:www.online.if.ee EE:www.starman.ee CA:www.msn.com :vcytp.com :irqupzts.com :covao.com :lphocxwrt.org :ihyvpse.info :qjonvthhngp.net :eeemchdrr.info US:fiztoedl.biz :kvljyrqcn.net :degpn.com US:nltyezrx.biz :ibkpbssw.com :qsahcrpancf.org :xbmgcgw.com US:enqzusojhvw.biz :fjvvpfpv.net :ijqxnbpy.com :fmqiw.com :tcuomdeuwbg.com :gwwomjuods.info FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
09:01:00 | Win2K-f | 89.179.32.42 (CORBINA.RU): INVESTELEKTROSVIAZ LTD, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:www.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
09:11:00 | Win2K-f | 66.6.20.86 (GLOBALMAILER.COM): SOBONITO INVESTMENTS LTD, NEW YORK, NEW YORK, US. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
09:26:00 | Win2K-f | 190.74.93.84 (CANTV.NET): CANTV SERVICIOS VENEZUELA, CARACAS, DISTRITO FEDERAL, VE. (DSL) |
n/a | FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
12:00:00 | Win2K-f | 190.41.77.98 (SPEEDY.NET.PE): TDPERX9-LACNIC, LIMA, LIMA, PE. (DSL) |
n/a | US:www.w3.org :rnhkudmp.com :febdctbktss.org :pjxzyzvt.com :gmgmsduglm.info :vkvvflhgv.net :ayfyojyzhj.org :ibkpbssw.com :nyzlaaou.org :gsfuxnboh.org :abrxys.org :plfinrfrim.com :vdjtkguwc.info :qnwknuh.com :nbzcqqbmfv.info :qexukrfrxfd.net :jpeklwwwmg.org :ktmixaxb.com :muqplvklt.info :thtgmnr.net US:fhthwwjy.biz :fydik.org US:eiktmatsku.biz :qcwjgvh.net :hkrlxwynm.info :ydbfhgahvgw.info :kqbtdrdm.org :xbffi.org US:nltyezrx.biz :wjiodktd.org :xwknl.info :xxnqhrjqod.org US:rrfuntwx.biz :covao.com :wrzwahqt.net :ybenqiyy.net :lphocxwrt.org :jypaa.com :ibwdnqxo.net :txfksc.org :mlnbkuz.net :irqupzts.com :ibqyxhkbbm.info :neljjkwowk.net US:ediba.com :aqszuewozb.org :osokib.org :rsduwz.info :mykhptyp.org :ubmyocsmhw.com :nkcolfrwpe.com :isqfidg.org :ytapyypuv.com :gasplavwwpn.com :yvldvbfb.com :ihyvpse.info :laeuw.net :ppxjzpir.org :uvfvtbm.com US:pqjugbhli.biz US:jmrhiro.biz US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 20 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
12:42:00 | Win2K-f | 79.126.231.151 (MEPSO.COM.MK): ONNET, SKOPJE, KARPOS, MK. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:www.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
16:20:00 | Win2K-f | 177.131.205.9 (-): . |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
16:27:00 | Win2K-f | 87.119.23.232 (NET.PL): COMMERCIAL IP NETWORK MNI TELECOM S.A, WARSAW, WARSZAWA, PL. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
17:44:00 | Win2K-f | 95.0.90.30 (-): TR-TELEKOM, ANKARA, ANKARA, TR. (DSL) |
n/a | :www.maxmind.com :getmyip.co.uk US:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | 223d8089f8 NEW |
none[3] | none:none |
StarForce| | none | trace |
18:09:00 | Win2K-f | 190.203.143.77 (CANTV.NET): CANTV SERVICIOS VENEZUELA, CARACAS, DISTRITO FEDERAL, VE. (DSL) |
n/a | US:www.ask.com US:rdqchnu.biz :vbowgaxcmkk.com :pjwfw.com :mkyoiibm.info :dtzap.com US:xquevystbb.biz US:belalot.biz :myodikkj.net :ymxydww.org :hplfo.info :blfqeeguelu.info :kyrusdgkhw.net :rjmqzyz.net :lerxf.info :wicnjux.info :nxwdozfrsb.com :eyshdmgkqc.net :bhcvxzs.net :jyojn.info :awzcv.com :zlhkv.info US:kqmmswbs.biz :wwkyyl.net :csymxxcoub.org :kebxjcyipwq.net US:wgpkbwvrir.biz :bsxgo.info :qlcsmfwee.com :texbbfrre.net :ccmwbgm.org :oikcgoeqwr.org :ndhvzndaqv.com :wpenlarfbmt.org :nyncehvl.org :nhgckggu.net :nbkimlyqu.com :inlxkb.info :cgmktdar.org :zxeqik.info US:nafkpfmhnpj.biz :blrzevrqal.info :skqkimhtx.com JP:softem.info :xkxnahpjci.info :mancetjaasn.com US:gqhkr.biz US:hmbvpjjjeop.biz :ydxrn.info US:krgzu.biz :lntat.net US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |