Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
11:12:00 | Win2K-f | 79.124.82.237 (PC010093.AIRBITES.BG): AIR BITES BULGARIA, SOFIA, GRAD SOFIYA, BG. (DSL) |
n/a | EE:www.online.if.ee EE:www.starman.ee FI:www.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
12:18:00 | Win2K-f | 187.143.109.22 (PROD-INFINITUM.COM.MX): UNINET S.A. DE C.V, MX. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
12:28:00 | Win2K-f | 114.42.220.8 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
12:38:00 | Win2K-f | 81.9.21.34 (NOVLINE.NET): NOVLINE LTD. ISP IN NOVGOROD RUSSIA, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
12:48:00 | Win2K-f | 192.30.139.67 (SPEAKEASY.NET): US. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
12:58:00 | Win2K-f | 89.121.212.85 (ROMTELECOM.NET): ROMTELECOM DATA NETWORK, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
13:08:00 | Win2K-f | 95.85.146.119 (STCABLE.NET): DHCP POOL FOR BROADBAND CABLE MODEM CUSTOMERS, RS. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee US:trafficconverter.biz EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
13:18:00 | Win2K-f | 46.49.22.111 (-): . |
n/a | EE:www.starman.ee EE:www.online.if.ee EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
http lanman 28 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
13:28:00 | Win2K-f | 78.84.180.143 (-): ADDRESS POOL FOR LTC-HOME CUSTOMERS, RIGA, RIGA, LV. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
13:38:00 | Win2K-f | 86.106.81.205 (ROMEXNET.RO): SC ROMEX NETWORK SRL, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
13:48:00 | Win2K-f | 202.78.227.40 (MAIL.TRIENMINH.VN): IP RANGE ALLOCATE FOR DEDICATE SERVER SERVICE OF QTSC, HO CHI MINH CITY, HO CHI MINH, VN. (100Mbps) |
n/a | 445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
13:58:00 | Win2K-f | 93.113.132.95 (-): SC EL NICO SRL, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | :wofuywyt.info :ysfbocj.net US:wslnumw.biz :qmvllcm.org :lxznmjuebzj.org :qlukhgmtajy.info :smalwsrooer.info :rxatmc.net :duhcgpphu.org :qesaschyloy.net :gqekxdqi.org :agxibquh.info US:soykkjl.biz US:ovziqyzs.biz :uhsntu.com :xathlec.com :ezgzxs.org US:jknfjytu.biz :xvnyc.info :vgmrauzorml.org :vqllx.com :iemdef.org :eandvgfi.org :patkfnd.info US:jeocnlbi.biz :ctoeioqy.info :twxxqlkdme.net :vflixbgdud.net :avydorphaiz.info :ojrih.org |
445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
14:08:00 | Win2K-f | 176.240.126.238 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 25 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
14:18:00 | Win2K-f | 207.182.143.62 (XLHOST.COM): ENET INC, COLUMBUS, OHIO, US. (100Mbps) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
16:12:00 | Win2K-f | 193.93.160.118 (ONET.NET.UA): ISP ONET, KIEV, KYYIV, UA. (DSL) |
n/a | US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:03:00 | Win2K-f | 46.72.235.29 (-): . |
n/a | US:www.ask.com :ksryuqlq.org :wpmdvblngzc.org :rdvqhy.com :luuzbs.org :djqhutpmvd.com :fyhwyiv.info :hbtkhxsdt.com :dhkhnqmo.info :fxopycwilqq.org :jpahhvck.info :rouaeanh.org US:lpzocszhbj.biz :ryhzcxdon.com :bccgyysvv.net :igijoshnx.info US:voqmyzca.biz :ejhdqzexji.com :jjggvbvizk.com :vxafxusanev.org :dujvfmes.org :vkgplxlz.net :ywukyiax.info :xkchgisk.org US:gvilxoxe.biz :iguzipfi.com :aocdh.org :hcbgetd.net US:ytrolcrjnd.biz :ynfyemc.info :aliveyq.net :bdkomoq.com :agkurwyg.net :zwkhclqlvv.org :frvjust.org US:ghwofijf.biz :zmncaft.info :cxficwbm.com :dyhxgwzj.net :rovndt.com :gdkjegis.com :nsafnnvibfg.net :kfdys.net :dypcucjc.info :ozkbosqz.org :rwtfgc.org US:kbiwcdnv.biz :unnqhyjf.com :unlrrbhot.com :duhdfmup.net :ombspy.com :kewpcxnp.com :zqntjuw.com :bjagjlex.info :avrwtrzhlw.info :bcjsh.org :zvpiagwnuu.info US:djitrag.biz :idhyaifpk.net US:lwquqs.biz :cwwalsbrmiq.net US:spirhdli.biz :msaxebajy.info :besacbnpn.net :fltoroh.info :gdopsgvdhai.com :xkzfigbxnz.org :jyzngxeeyc.org :ubhhlztnj.com :exnkbpk.org :getpr.org US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:55:00 | Win2K-f | 201.53.20.212 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
21:05:00 | Win2K-f | 59.95.165.160 (10/25.BSNL.IN): NIB (NATIONAL INTERNET BACKBONE), JAIPUR, RAJASTHAN, IN. (DSL) |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
21:15:00 | Win2K-f | 31.3.249.24 (-): . |
n/a | EE:www.starman.ee EE:www.online.if.ee FI:194.215.38.135:80 EE:195.50.195.10:443 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
21:40:00 | Win2K-f | 114.24.55.30 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | FI:194.215.38.135:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |