Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
02:43:00 | Win2K-f | 115.127.28.122 (CORPORATE-ACCESS.COM): ISP IN BANGLADESH, BD. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:www.if.ee US:trafficconverter.biz FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
10:41:00 | Win2K-f | 109.200.4.124 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
n/a | EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
12:38:00 | Win2K-f | 187.10.51.130 (TELESP.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | US:www.w3.org :dgwcfe.net :gwtelzjf.info :pytgycnjkwv.info US:snnysoz.biz :yeoypjnq.net US:gqhkr.biz :umqzk.org :ccmwbgm.org :nkwnomybm.org US:ckgbmr.biz US:ouibs.biz :bpbxjacp.com :oikcgoeqwr.org :hgdtrxocn.info US:hmbvpjjjeop.biz :mancetjaasn.com US:ywgtmnbpr.biz :uilyrvlqnqz.org :ruxfrnbosg.net US:vwzljl.biz :awzcv.com US:belalot.biz :emepihdi.info :rjmqzyz.net :ymxydww.org US:gmtqddorqa.biz :ijpsvkqunuk.net :stxnfeseem.org US:rajjeyytf.biz :ezqvmskx.net :haqaks.net US:imnhrfuoms.biz :vrutmquaul.net :mgsxqigr.com :jrynwugm.org US:cibovf.biz :skqkimhtx.com :usnvtjlp.com :vqgrwqlrf.net :fyjuwju.info JP:softem.info :kydxmxrqa.net :admloczows.info :yxdwxi.info :hcfwr.org :zxeqik.info US:vkhoniey.biz US:gdmxit.biz :hzypp.com :sbvbuob.com :zjxcv.org :wicnjux.info :vpggea.com :xbhnmz.info :cvdghs.com US:rdqchnu.biz :ugvuhdnlpnv.org :lkssozioy.com :anwdpspa.org :grirhtat.com :pjwfw.com :ukfdisp.info :ndhvzndaqv.com US:bpqwqzh.biz :hplfo.info US:oxhwoy.biz :dbsbdl.org :bhcvxzs.net :yjgmrhfcv.net :rxchetrpw.info US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 20 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
22:43:00 | Win2K-f | 195.140.154.212 (KOPNET.PL): KOPNET-NET-PL, WARSAW, WARSZAWA, PL. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:www.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |