Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
10:04:00 | Win2K-f | 85.237.231.21 (ORANGE.SK): ORANGE-DETRONICS, BRATISLAVA, BRATISLAVA, SK. (DSL) |
n/a | :www.maxmind.com :getmyip.co.uk US:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
15:13:00 | Win2K-f | 103.31.153.7 (-): . |
n/a | :www.maxmind.com :www.getmyip.org US:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 41 of 42 none 26 of 28 none 40 of 41 none 3 of 37 34 of 41 |
01c4a6b3eb NEW 22340630ac NEW 37cbbcb33e NEW 7d99b0e910 NEW 94227c2434 NEW bb460ddce2 NEW d6b1899047 NEW d9cb288f31 NEW deffdf68e8 NEW |
dd524b0259 [0] none [none] none [none] none [0] none [none] none [none] none [none] 45603a001c[0] 2b011e15ba[0] |
ASM:Graph none:none none:none none:none none:none none:none none:none ASM:Graph ASM:Graph |
PolyEnE| none|none none|none PolyEnE| none|none none|none none|none UPX| StarForce| |
lines=68 none none lines=68 none none none lines=174 embedded dns lines=3122 embedded dns |
trace none none trace none none none trace trace |
20:14:00 | Win2K-f | 182.73.236.114 (-): . |
n/a | :www.maxmind.com :getmyip.co.uk :www.getmyip.org EU:checkip.dyndns.org DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |