Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
03:32:00 | Win2K-f | 122.3.185.15 (PLDT.NET): IPG, CEBU, CEBU CITY, PH. (100Mbps) |
n/a | :www.maxmind.com :getmyip.co.uk :www.getmyip.org EU:checkip.dyndns.org DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
none 40 of 41 41 of 43 none 7 of 37 38 of 42 40 of 41 36 of 43 6 of 37 none 29 of 29 none 41 of 42 2 of 37 none none 42 of 43 40 of 43 41 of 43 3 of 37 none none none none 2 of 37 none 32 of 32 none 7 of 37 none 37 of 40 none none none 39 of 40 none 41 of 43 none 43 of 43 5 of 37 31 of 32 7 of 37 none none 26 of 28 25 of 25 39 of 42 none none 38 of 42 29 of 29 4 of 37 3 of 37 38 of 41 none none 16 of 39 none none 29 of 29 41 of 42 42 of 43 40 of 43 42 of 43 35 of 36 none none 40 of 41 40 of 42 none 37 of 43 34 of 34 30 of 32 none 2 of 37 none 39 of 41 3 of 37 none 3 of 37 41 of 44 none none 40 of 42 34 of 41 29 of 29 41 of 41 41 of 42 none none none none 41 of 43 41 of 42 |
00632e0224 NEW 01c4a6b3eb NEW 048b720afe NEW 085f286a6f NEW 08f384b76a NEW 0d1eb4df79 NEW 1096ba143e NEW 138706aee9 NEW 13e15a653e NEW 1693c68bd5 NEW 1a2c0e6130 NEW 208813189d NEW 22340630ac NEW 223d8089f8 NEW 262edfe111 NEW 267b33fd90 NEW 269ce49eb2 NEW 283970c2d1 NEW 2acefaf1dc NEW 2daf861bde NEW 33a806c2c2 NEW 3679444e79 NEW 37cbbcb33e NEW 3dccf3e786 NEW 409ef22885 NEW 48048cfbf5 NEW 488d27fe97 NEW 4eb2a4de70 NEW 507252387e NEW 51529da007 NEW 5285741560 NEW 56950ee6b1 NEW 59650c92cd NEW 5df33c8d31 NEW 5e8ccc4190 NEW 656ea74fff NEW 67db574df4 NEW 6f97dfe23c NEW 6ffc4847e4 NEW 741c93f3c1 NEW 741e3b03b3 NEW 7587773eea NEW 765c35504c NEW 7cb3a68ab4 NEW 7d99b0e910 NEW 7f60162c2c NEW 8689eac5d3 NEW 8883bbf19e NEW 8a03fb431e NEW 8a2553433c NEW 8ae2cc2e80 NEW 8ce32ded17 NEW 917c085aca NEW 9276456bf8 NEW 94227c2434 NEW 976fe17447 NEW 9a9f93c4d2 NEW 9bd2a2f214 NEW 9ebcc2e373 NEW a12cab51ef NEW a4140e4032 NEW aad01847fa NEW ac1d14519f NEW b269b15ffd NEW b27d73bfcb NEW b76758d4ca NEW b7f91029e4 NEW bb460ddce2 NEW bcb3ec60f2 NEW c139a391ff NEW ca3e3b13f3 NEW d20f157117 NEW d295efe2b8 NEW d5f6c71f19 NEW d60e538e72 NEW d6b1899047 NEW d8040f84d4 NEW d9cb288f31 NEW dbaf3a342e NEW dc331fb791 NEW dd0a92984c NEW dd464e833b NEW dd5e37d9e6 NEW de4624560d NEW deffdf68e8 NEW df17a625ee NEW e92ed9f79c NEW e99261ba46 NEW f046b8c087 NEW f0a0c88348 NEW f3073beb4e NEW f4d9ccf3f8 NEW fb486908b0 NEW ff90c1ff00 NEW |
none[none] dd524b0259[0] none [none] none [none] none [3] none [none] none [none] none [none] none [3] none [none] none [0] none [none] none [none] none [3] none [none] none [none] none [none] none [none] none [none] none [3] none [none] none [none] none [none] none [none] none [3] none [none] none [none] none [none] none [3] none [none] 60590b8b67[0] none [none] none [none] none [none] 8d5f86583f[0] none [none] none [none] none [none] none [none] none [3] none [0] none [3] none [none] none [none] none [0] none [0] none [none] none [none] none [none] none [none] none [0] none [3] none [3] none [none] none [none] none [none] none [3] none [none] none [none] none [0] none [none] none [none] none [none] none [none] 473c6454ce[0] none [none] none [none] none [none] none [none] none [none] none [none] 738f555183[0] none [none] none [none] none [3] none [none] d683995e84[0] 45603a001c[0] none [none] none [3] none [none] none [none] none [none] none [none] 2b011e15ba[0] none [0] none [none] none [none] none [none] none [none] none [none] none [none] none [none] none [none] |
none:none ASM:Graph none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none ASM:Graph none:none none:none none:none ASM:Graph none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none ASM:Graph none:none none:none none:none none:none none:none none:none ASM:Graph none:none none:none none:none none:none ASM:Graph ASM:Graph none:none none:none none:none none:none none:none none:none ASM:Graph none:none none:none none:none none:none none:none none:none none:none none:none none:none |
none|none PolyEnE| none|none none|none MEW| none|none none|none none|none UPX| none|none none|none none|none none|none StarForce| none|none none|none none|none none|none none|none Armadillo| none|none none|none none|none none|none UPX| none|none none|none none|none UPX| none|none none|none none|none none|none none|none PolyEnE| none|none none|none none|none none|none UPX| none|none StarForce| none|none none|none PolyEnE| PolyEnE| none|none none|none none|none none|none PolyEnE| Armadillo| Armadillo| none|none none|none none|none UPX| none|none none|none ASPack| none|none none|none none|none none|none PolyEnE| none|none none|none none|none none|none none|none none|none PolyEnE| none|none none|none UPX| none|none PolyEnE| UPX| none|none UPX| none|none none|none none|none none|none StarForce| ASPack| none|none none|none none|none none|none none|none none|none none|none none|none |
none lines=68 none none none none none none none none lines=60 none none none none none none none none none none none none none none none none none none none lines=59 none none none lines=68 none none none none none lines=61 none none none lines=68 lines=93 embedded dns none none none none lines=68 none none none none none none none none lines=281 embedded dns none none none none lines=68 none none none none none none lines=68 none none none none lines=73 lines=174 embedded dns none none none none none none lines=3122 embedded dns lines=298 embedded dns none none none none none none none none |
none trace none none trace none none none trace none trace none none trace none none none none none trace none none none none trace none none none trace none trace none none none trace none none none none trace trace trace none none trace trace none none none none trace trace trace none none none trace none none trace none none none none trace none none none none none none trace none none trace none trace trace none trace none none none none trace trace none none none none none none none none |
06:19:00 | WinXP | 92.86.40.141 (TELELINK-RO.COM): ARTELECOM, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
06:52:00 | Win2K-f | 210.245.85.39 (FPT-CUSTOMERS.FPT.VN): DAI IP CHO HOSTING GAME, VN. (DSL) |
n/a | :www.maxmind.com :getmyip.co.uk :www.getmyip.org EU:checkip.dyndns.org 174.36.207.186:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
10:01:00 | Win2K-f | 188.132.135.88 (SADECEHOSTING.NET): HOSTING INTERNET HIZMETLERI LTD STI, ISTANBUL, ISTANBUL, TR. (DSL) |
n/a | :www.maxmind.com US:checkip.dyndns.org 174.36.207.186:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
11:37:00 | WinXP | 79.163.23.150 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |