Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
02:35:00 | Win2K-f | 202.152.30.227 (-): POP SMG, SEMARANG, JAWA TENGAH, ID. (100Mbps) |
n/a | :www.maxmind.com US:checkip.dyndns.org :www.getmyip.org :getmyip.co.uk 108.168.255.243:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
13:41:00 | Win2K-f | 122.169.240.178 (122.AIRTELBROADBAND.IN): ABTS-AP-DSL-HYD, HYDERABAD, ANDHRA PRADESH, IN. (DSL) |
n/a | :www.maxmind.com :getmyip.co.uk US:checkip.dyndns.org :www.getmyip.org IN:122.169.240.178:5794 DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 32 of 32 41 of 43 none none none none 38 of 42 42 of 43 41 of 42 2 of 37 none none 3 of 37 none none 2 of 37 8 of 38 7 of 37 none 37 of 40 none none 43 of 43 39 of 40 5 of 37 31 of 32 39 of 41 none 26 of 28 25 of 25 38 of 42 4 of 37 3 of 37 none 37 of 40 41 of 42 none 39 of 43 40 of 41 none 41 of 42 37 of 43 34 of 34 30 of 32 2 of 37 none 3 of 37 3 of 37 41 of 44 34 of 41 29 of 29 38 of 41 none none 41 of 43 |
01c4a6b3eb NEW 03f912899b NEW 048b720afe NEW 057af4ccd4 NEW 085f286a6f NEW 0961e87d20 NEW 0c38af69f4 NEW 0d1eb4df79 NEW 1511a3f219 NEW 22340630ac NEW 223d8089f8 NEW 262edfe111 NEW 267b33fd90 NEW 2daf861bde NEW 37cbbcb33e NEW 3dccf3e786 NEW 409ef22885 NEW 4f6b51ea3b NEW 507252387e NEW 51529da007 NEW 5285741560 NEW 5e12c93ecb NEW 656ea74fff NEW 6ffc4847e4 NEW 70ec5c4b3f NEW 741c93f3c1 NEW 741e3b03b3 NEW 76d2a5a1ef NEW 7cb3a68ab4 NEW 7d99b0e910 NEW 7f60162c2c NEW 8a2553433c NEW 8ce32ded17 NEW 917c085aca NEW 94227c2434 NEW a09dc0cda1 NEW a4140e4032 NEW b009919adf NEW b7805b2086 NEW bb460ddce2 NEW c139a391ff NEW c73335028d NEW ca3e3b13f3 NEW d20f157117 NEW d295efe2b8 NEW d60e538e72 NEW d6b1899047 NEW d9cb288f31 NEW dc331fb791 NEW dd0a92984c NEW deffdf68e8 NEW df17a625ee NEW ecfbf321d3 NEW ed04b34990 NEW f046b8c087 NEW fb486908b0 NEW |
dd524b0259 [0] none [0] none [none] none [none] none [none] none [none] none [none] none [none] none [none] none [none] none [3] none [none] none [none] none [3] none [none] none [none] none [3] none [3] none [3] none [none] 60590b8b67[0] none [none] none [none] none [none] f697adabdd[0] none [3] none [0] none [none] none [none] none [0] none [0] none [none] none [3] none [3] none [none] none [3] none [none] none [none] none [none] none [none] none [none] none [none] none [none] 738f555183[0] none [none] none [3] none [none] 45603a001c[0] none [3] none [none] 2b011e15ba[0] none [0] none [none] none [none] none [none] none [none] |
ASM:Graph none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none ASM:Graph none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none ASM:Graph none:none none:none none:none ASM:Graph none:none none:none ASM:Graph none:none none:none none:none none:none none:none |
PolyEnE| none|none none|none none|none none|none none|none none|none none|none none|none none|none StarForce| none|none none|none Armadillo| none|none none|none UPX| MEW| UPX| none|none none|none none|none none|none none|none StarForce| UPX| none|none none|none none|none PolyEnE| PolyEnE| none|none Armadillo| Armadillo| none|none StarForce| none|none none|none none|none none|none none|none none|none none|none PolyEnE| none|none UPX| none|none UPX| UPX| none|none StarForce| ASPack| none|none none|none none|none none|none |
lines=68 lines=64 none none none none none none none none none none none none none none none none none none lines=59 none none none none none lines=61 none none lines=68 lines=93 embedded dns none none none none none none none none none none none none lines=68 none none none lines=174 embedded dns none none lines=3122 embedded dns lines=298 embedded dns none none none none |
trace trace none none none none none none none none trace none none trace none none trace trace trace none trace none none none trace trace trace none none trace trace none trace trace none trace none none none none none none none trace none trace none trace trace none trace trace none none none none |
16:55:00 | Win2K-f | 218.201.241.87 (-): CHINA MOBILE COMMUNICATIONS CORPORATION - GUIZHOU, BEIJING, BEIJING, CN. (DSL) |
n/a | :www.maxmind.com :www.getmyip.org US:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |