Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
10:01:00 | Win2K-f | 180.148.210.59 (-): . |
n/a | :www.maxmind.com :getmyip.co.uk :www.getmyip.org US:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
17:52:00 | Win2K-f | 115.186.133.196 (115-186-128-10.NAYATEL.PK): MICRONET BROADBAND (PVT) LTD, ISLAMABAD, ISLAMABAD, PK. (DSL) |
n/a | :www.maxmind.com :getmyip.co.uk US:checkip.dyndns.org 115.186.133.196:6332 DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
none 41 of 43 none 7 of 37 none none none 29 of 29 36 of 43 none none 28 of 41 none 41 of 42 2 of 37 none none none 41 of 43 3 of 37 none none none none 38 of 41 2 of 37 none none 22 of 41 7 of 37 37 of 40 none none none 39 of 40 none none none none none 43 of 43 none 5 of 37 31 of 32 7 of 37 none 39 of 41 none none 26 of 28 none 36 of 41 39 of 42 none 38 of 42 none none 4 of 37 38 of 41 none none none none 29 of 29 42 of 43 40 of 43 38 of 43 none 42 of 43 none none 39 of 43 none 28 of 41 40 of 41 40 of 42 39 of 42 none none 37 of 43 none 34 of 34 30 of 32 none none 2 of 37 none none 39 of 41 3 of 37 36 of 42 3 of 37 41 of 44 none 29 of 29 41 of 41 41 of 42 37 of 43 none none none none none 6 of 37 |
00632e0224 NEW 048b720afe NEW 085f286a6f NEW 08f384b76a NEW 0961e87d20 NEW 0a8dfdef4e NEW 0c38af69f4 NEW 0cfab99612 NEW 138706aee9 NEW 1693c68bd5 NEW 17eecab10b NEW 1bb4b25c0e NEW 1ef46e2863 NEW 22340630ac NEW 223d8089f8 NEW 22b21ba08d NEW 267b33fd90 NEW 2a22f7c5eb NEW 2acefaf1dc NEW 2daf861bde NEW 33a806c2c2 NEW 35fba96133 NEW 3679444e79 NEW 3dccf3e786 NEW 3e30dc90de NEW 409ef22885 NEW 48048cfbf5 NEW 4eb2a4de70 NEW 5069160ffe NEW 507252387e NEW 5285741560 NEW 56ebfb0d0c NEW 59650c92cd NEW 5df33c8d31 NEW 5e8ccc4190 NEW 5e919067e5 NEW 656ea74fff NEW 6bf9b1dc21 NEW 6cae055435 NEW 6f97dfe23c NEW 6ffc4847e4 NEW 74025075b0 NEW 741c93f3c1 NEW 741e3b03b3 NEW 7587773eea NEW 768b456645 NEW 76d2a5a1ef NEW 78df593585 NEW 7cb3a68ab4 NEW 7d99b0e910 NEW 8061e5f689 NEW 83f6cb959d NEW 8689eac5d3 NEW 8a03fb431e NEW 8a2553433c NEW 8c0ddcf6d5 NEW 8c282472f0 NEW 8ce32ded17 NEW 9276456bf8 NEW 94227c2434 NEW 9bd2a2f214 NEW 9c831d56a8 NEW 9ebcc2e373 NEW a12cab51ef NEW aad01847fa NEW ac1d14519f NEW af614537c1 NEW b009919adf NEW b269b15ffd NEW b72124df19 NEW b76758d4ca NEW b7805b2086 NEW b7f91029e4 NEW b8076e37ae NEW bb460ddce2 NEW bcb3ec60f2 NEW c6a04373ec NEW c7fd060c28 NEW c8ae5d88cf NEW ca3e3b13f3 NEW cd76e32816 NEW d20f157117 NEW d295efe2b8 NEW d3c12859c0 NEW d5f6c71f19 NEW d60e538e72 NEW d6b1899047 NEW d6b571e247 NEW d8040f84d4 NEW d9cb288f31 NEW db3cc73e21 NEW dc331fb791 NEW dd0a92984c NEW dd5e37d9e6 NEW df17a625ee NEW e92ed9f79c NEW e99261ba46 NEW ecc07df4ad NEW ed86cec415 NEW f046b8c087 NEW f0a0c88348 NEW f6c2bea069 NEW fca087c49d NEW fcb1f9cdfa NEW |
none[none] none [none] none [none] none [3] none [none] none [none] none [none] none [0] none [none] none [none] none [none] 9293a2c3db[0] none [none] none [none] none [3] none [none] none [none] none [none] none [none] none [3] none [none] none [none] none [none] none [none] d5e7d16040[0] none [3] none [none] none [none] 65a33ca939[0] none [3] 60590b8b67[0] none [none] none [none] none [none] 8d5f86583f[0] none [none] none [none] none [none] none [none] none [none] none [none] none [none] none [3] none [0] none [3] none [none] none [none] none [none] none [none] none [0] none [none] 445f56b6dd[0] none [none] none [none] none [none] none [none] none [none] none [3] none [none] none [none] none [none] none [none] none [none] none [0] none [none] none [none] none [none] none [none] none [none] none [none] none [none] none [none] none [none] 52953fed05[0] none [none] none [none] none [none] none [none] none [none] none [none] none [none] 738f555183[0] none [none] none [none] none [none] none [3] none [none] none [none] d683995e84[0] 45603a001c[0] none [none] none [3] none [none] none [none] none [0] none [none] none [none] none [none] none [none] none [none] none [none] none [none] none [none] none [3] |
none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none ASM:Graph none:none none:none none:none ASM:Graph none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none ASM:Graph none:none none:none none:none none:none none:none none:none ASM:Graph ASM:Graph none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none |
none|none none|none none|none MEW| none|none none|none none|none PolyEnE| none|none none|none none|none StarForce| none|none none|none StarForce| none|none none|none none|none none|none Armadillo| none|none none|none none|none none|none StarForce| UPX| none|none none|none StarForce| UPX| none|none none|none none|none none|none PolyEnE| none|none none|none none|none none|none none|none none|none none|none UPX| none|none StarForce| none|none none|none none|none none|none PolyEnE| none|none StarForce| none|none none|none none|none none|none none|none Armadillo| none|none none|none none|none none|none none|none ASPack| none|none none|none none|none none|none none|none none|none none|none none|none none|none StarForce| none|none none|none none|none none|none none|none none|none none|none PolyEnE| none|none none|none none|none UPX| none|none none|none PolyEnE| UPX| none|none UPX| none|none none|none ASPack| none|none none|none none|none none|none none|none none|none none|none none|none UPX| |
none none none none none none none lines=68 none none none none none none none none none none none none none none none none none none none none none none lines=59 none none none lines=68 none none none none none none none none lines=61 none none none none none lines=68 none none none none none none none none none none none none none lines=281 embedded dns none none none none none none none none none none none none none none none none none lines=68 none none none none none none lines=73 lines=174 embedded dns none none none none lines=298 embedded dns none none none none none none none none none |
none none none trace none none none trace none none none trace none none trace none none none none trace none none none none trace trace none none trace trace trace none none none trace none none none none none none none trace trace trace none none none none trace none trace none none none none none trace none none none none none trace none none none none none none none none none trace none none none none none none none trace none none none trace none none trace trace none trace none none trace none none none none none none none none trace |