Time
|
Victim OS
|
Infection Source
|
C&C Server
|
DNS Lookups & Failed Connects
|
Infection Port
|
Packet Trace
|
Detection Signatures
|
Infection Chatter
|
BotHunter Analysis
|
Behavioral Cluster
|
Forensic Logs
|
Antivirus Labels
|
Packed Malware_Binary
|
Unpacked egg.exe
|
Unpacked egg.asm
|
Packer PEID
|
Data Strings
|
Syscall Trace
|
T:09:35:00
|
WinXP
|
5.248.249.0 (-): .
|
n/a
|
DE:citi-bank.ru
|
445
|
pcap
|
raw alerts ruleset
|
http 1 line
|
Yeah : 0.8
profile
|
none
|
summary tarball
|
41 of 43 7 of 37 41 of 42 5 of 37 26 of 28 none 40 of 43 none 3 of 37 29 of 29 |
048b720afe NEW 08f384b76a NEW 22340630ac NEW 741c93f3c1 NEW 7d99b0e910 NEW 94227c2434 NEW ac1d14519f NEW b76758d4ca NEW d9cb288f31 NEW df17a625ee NEW
|
none[none] none [3] none [none] none [3] none [0] none [none] none [none] none [none] 45603a001c[0] none [0]
|
none:none none:none none:none none:none none:none none:none none:none none:none ASM:Graph none:none
|
none|none MEW| none|none UPX| PolyEnE| none|none none|none none|none UPX| ASPack|
|
none none none none lines=68 none none none lines=174 embedded dns lines=298 embedded dns
|
none trace none trace trace none none none trace trace
|
T:09:59:00
|
WinXP
|
128.143.35.227 (VIRGINIA.EDU): UNIVERSITY OF VIRGINIA, CHARLOTTESVILLE, VIRGINIA, US. (100Mbps)
|
n/a
|
|
445
|
pcap
|
raw alerts ruleset
|
other 3 lines
|
Yeah : 0.8
profile
|
none
|
summary tarball
|
41 of 43 7 of 37 5 of 37 26 of 28 none 40 of 43 none 3 of 37 29 of 29 |
048b720afe NEW 08f384b76a NEW 741c93f3c1 NEW 7d99b0e910 NEW 94227c2434 NEW ac1d14519f NEW b76758d4ca NEW d9cb288f31 NEW df17a625ee NEW
|
none[none] none [3] none [3] none [0] none [none] none [none] none [none] 45603a001c[0] none [0]
|
none:none none:none none:none none:none none:none none:none none:none ASM:Graph none:none
|
none|none MEW| UPX| PolyEnE| none|none none|none none|none UPX| ASPack|
|
none none none lines=68 none none none lines=174 embedded dns lines=298 embedded dns
|
none trace trace trace none none none trace trace
|
13:50:00
|
Win2K-f
|
80.93.212.202 (-): NET-BIZIM, ISTANBUL, ISTANBUL, TR. (100Mbps)
|
n/a
|
:www.maxmind.com :getmyip.co.uk US:checkip.dyndns.org DE:131.220.6.26:80
|
445
|
pcap
|
raw alerts ruleset
|
lanman http 31 lines
|
Yeah : 0.8
profile
|
none
|
summary tarball
|
41 of 43 7 of 37 5 of 37 none 40 of 43 3 of 37 29 of 29 |
048b720afe NEW 08f384b76a NEW 741c93f3c1 NEW 94227c2434 NEW ac1d14519f NEW d9cb288f31 NEW df17a625ee NEW
|
none[none] none [3] none [3] none [none] none [none] 45603a001c[0] none [0]
|
none:none none:none none:none none:none none:none ASM:Graph none:none
|
none|none MEW| UPX| none|none none|none UPX| ASPack|
|
none none none none none lines=174 embedded dns lines=298 embedded dns
|
none trace trace none none trace trace
|
T:14:16:00
|
Win2K-f
|
80.93.212.202 (-): NET-BIZIM, ISTANBUL, ISTANBUL, TR. (100Mbps)
|
n/a
|
:www.maxmind.com US:checkip.dyndns.org DE:131.220.6.26:80 174.36.207.186:80
|
445
|
pcap
|
raw alerts ruleset
|
http 4 lines
|
Yeah : 0.8
profile
|
none
|
summary tarball
|
41 of 43 7 of 37 41 of 42 5 of 37 26 of 28 none 40 of 43 none 3 of 37 29 of 29 |
048b720afe NEW 08f384b76a NEW 22340630ac NEW 741c93f3c1 NEW 7d99b0e910 NEW 94227c2434 NEW ac1d14519f NEW b76758d4ca NEW d9cb288f31 NEW df17a625ee NEW
|
none[none] none [3] none [none] none [3] none [0] none [none] none [none] none [none] 45603a001c[0] none [0]
|
none:none none:none none:none none:none none:none none:none none:none none:none ASM:Graph none:none
|
none|none MEW| none|none UPX| PolyEnE| none|none none|none none|none UPX| ASPack|
|
none none none none lines=68 none none none lines=174 embedded dns lines=298 embedded dns
|
none trace none trace trace none none none trace trace
|
15:40:00
|
Win2K-f
|
186.110.239.61 (-): .
|
n/a
|
:www.maxmind.com US:checkip.dyndns.org :www.getmyip.org :getmyip.co.uk DE:131.220.6.26:80 EU:91.198.22.70:80
|
445
|
pcap
|
raw alerts ruleset
|
http 4 lines
|
Yeah : 0.8
profile
|
none
|
summary tarball
|
41 of 43 7 of 37 5 of 37 none 40 of 43 3 of 37 29 of 29 |
048b720afe NEW 08f384b76a NEW 741c93f3c1 NEW 94227c2434 NEW ac1d14519f NEW d9cb288f31 NEW df17a625ee NEW
|
none[none] none [3] none [3] none [none] none [none] 45603a001c[0] none [0]
|
none:none none:none none:none none:none none:none ASM:Graph none:none
|
none|none MEW| UPX| none|none none|none UPX| ASPack|
|
none none none none none lines=174 embedded dns lines=298 embedded dns
|
none trace trace none none trace trace
|
17:41:00
|
Win2K-f
|
186.120.116.90 (-): .
|
n/a
|
:www.maxmind.com :www.getmyip.org US:checkip.dyndns.org :getmyip.co.uk 174.36.207.186:80 EU:91.198.22.70:80
|
445
|
pcap
|
raw alerts ruleset
|
http 1 line
|
Yeah : 0.8
profile
|
none
|
summary tarball
|
41 of 43 7 of 37 5 of 37 none 40 of 43 3 of 37 29 of 29 |
048b720afe NEW 08f384b76a NEW 741c93f3c1 NEW 94227c2434 NEW ac1d14519f NEW d9cb288f31 NEW df17a625ee NEW
|
none[none] none [3] none [3] none [none] none [none] 45603a001c[0] none [0]
|
none:none none:none none:none none:none none:none ASM:Graph none:none
|
none|none MEW| UPX| none|none none|none UPX| ASPack|
|
none none none none none lines=174 embedded dns lines=298 embedded dns
|
none trace trace none none trace trace
|
T:19:19:00
|
WinXP
|
119.15.233.46 (TCOL.COM.TW): E-MAX NETWORK CORP, TAIPEI, T'AI-PEI, TW. (DSL)
|
n/a
|
DE:citi-bank.ru
|
445
|
pcap
|
raw alerts ruleset
|
http 1 line
|
Yeah : 0.8
profile
|
none
|
summary tarball
|
41 of 43 7 of 37 5 of 37 26 of 28 none 40 of 43 none 3 of 37 29 of 29 |
048b720afe NEW 08f384b76a NEW 741c93f3c1 NEW 7d99b0e910 NEW 94227c2434 NEW ac1d14519f NEW b76758d4ca NEW d9cb288f31 NEW df17a625ee NEW
|
none[none] none [3] none [3] none [0] none [none] none [none] none [none] 45603a001c[0] none [0]
|
none:none none:none none:none none:none none:none none:none none:none ASM:Graph none:none
|
none|none MEW| UPX| PolyEnE| none|none none|none none|none UPX| ASPack|
|
none none none lines=68 none none none lines=174 embedded dns lines=298 embedded dns
|
none trace trace trace none none none trace trace
|
T:22:05:00
|
WinXP
|
114.45.37.18 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL)
|
n/a
|
DE:citi-bank.ru DE:213.155.14.161:80
|
445
|
pcap
|
raw alerts ruleset
|
http 1 line
|
Yeah : 0.8
profile
|
none
|
summary tarball
|
41 of 43 7 of 37 5 of 37 none 40 of 43 none 3 of 37 29 of 29 |
048b720afe NEW 08f384b76a NEW 741c93f3c1 NEW 94227c2434 NEW ac1d14519f NEW b76758d4ca NEW d9cb288f31 NEW df17a625ee NEW
|
none[none] none [3] none [3] none [none] none [none] none [none] 45603a001c[0] none [0]
|
none:none none:none none:none none:none none:none none:none ASM:Graph none:none
|
none|none MEW| UPX| none|none none|none none|none UPX| ASPack|
|
none none none none none none lines=174 embedded dns lines=298 embedded dns
|
none trace trace none none none trace trace
|