Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
04:24:00 | Win2K-f | 210.245.83.152 (FPT-CUSTOMERS.FPT.VN): DAI IP CHO HOSTING GAME, HANOI, DAC LAC, VN. (DSL) |
n/a | :www.maxmind.com US:checkip.dyndns.org :www.getmyip.org :getmyip.co.uk 108.168.255.243:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
05:47:00 | Win2K-f | 210.86.239.72 (CI239-10.NETNAM.VN): IP RANGE ASSIGNED FOR SERVER IN HCMC, VN. (DSL) |
n/a | :www.maxmind.com US:checkip.dyndns.org :www.getmyip.org :getmyip.co.uk 108.168.255.243:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
14:43:00 | Win2K-f | 185.12.111.245 (-): . |
n/a | :www.maxmind.com US:checkip.dyndns.org :getmyip.co.uk :www.getmyip.org DE:131.220.6.26:80 US:216.146.38.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 none 38 of 42 2 of 37 none 39 of 40 3 of 37 41 of 42 37 of 43 34 of 34 3 of 37 3 of 37 29 of 29 41 of 43 |
048b720afe NEW 0c38af69f4 NEW 0d1eb4df79 NEW 223d8089f8 NEW 3dccf3e786 NEW 70ec5c4b3f NEW 917c085aca NEW a4140e4032 NEW ca3e3b13f3 NEW d20f157117 NEW d9cb288f31 NEW dc331fb791 NEW df17a625ee NEW fb486908b0 NEW |
none[none] none [none] none [none] none [3] none [none] f697adabdd[0] none [3] none [none] none [none] 738f555183[0] 45603a001c[0] none [3] none [0] none [none] |
none:none none:none none:none none:none none:none none:none none:none none:none none:none ASM:Graph ASM:Graph none:none none:none none:none |
none|none none|none none|none StarForce| none|none StarForce| Armadillo| none|none none|none PolyEnE| UPX| UPX| ASPack| none|none |
none none none none none none none none none lines=68 lines=174 embedded dns none lines=298 embedded dns none |
none none none trace none trace trace none none trace trace trace trace none |