Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:06:00 | Win2K-f | 69.46.72.199 (JADEINC.NET): JADE INC, COLUMBUS, OHIO, US. (DSL) |
n/a | :www.maxmind.com :getmyip.co.uk EU:checkip.dyndns.org :www.getmyip.org 108.168.255.243:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
01:12:00 | Win2K-f | 212.0.132.13 (-): ISP COMMUNICATION & COMPUTER, KHARTOUM, AL KHARTUM, SD. (DSL) |
n/a | :www.maxmind.com US:checkip.dyndns.org :getmyip.co.uk :www.getmyip.org 108.168.255.243:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
03:11:00 | Win2K-f | 202.141.240.86 (MULTI.NET.PK): MULTINETBROADBAND, KARACHI, SINDH, PK. (DSL) |
n/a | :www.maxmind.com :www.getmyip.org :getmyip.co.uk US:checkip.dyndns.org 108.168.255.243:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
08:17:00 | WinXP | 46.211.79.25 (-): . |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
17:46:00 | Win2K-f | 181.2.225.204 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 32 of 32 41 of 43 none 38 of 42 2 of 37 none none 3 of 37 none 8 of 38 7 of 37 none none none 39 of 40 none 5 of 37 39 of 41 25 of 25 4 of 37 3 of 37 none 41 of 42 none 40 of 42 none 37 of 43 34 of 34 2 of 37 3 of 37 3 of 37 34 of 41 29 of 29 41 of 43 |
01c4a6b3eb NEW 03f912899b NEW 048b720afe NEW 0c38af69f4 NEW 0d1eb4df79 NEW 223d8089f8 NEW 267b33fd90 NEW 2a22f7c5eb NEW 2daf861bde NEW 3dccf3e786 NEW 4f6b51ea3b NEW 507252387e NEW 5e12c93ecb NEW 5e919067e5 NEW 656ea74fff NEW 70ec5c4b3f NEW 74025075b0 NEW 741c93f3c1 NEW 76d2a5a1ef NEW 7f60162c2c NEW 8ce32ded17 NEW 917c085aca NEW 94227c2434 NEW a4140e4032 NEW b72124df19 NEW bcb3ec60f2 NEW c139a391ff NEW ca3e3b13f3 NEW d20f157117 NEW d60e538e72 NEW d9cb288f31 NEW dc331fb791 NEW deffdf68e8 NEW df17a625ee NEW fb486908b0 NEW |
dd524b0259 [0] none [0] none [none] none [none] none [none] none [3] none [none] none [none] none [3] none [none] none [3] none [3] none [none] none [none] none [none] f697adabdd[0] none [none] none [3] none [none] none [0] none [3] none [3] none [none] none [none] none [none] none [none] none [none] none [none] 738f555183[0] none [3] 45603a001c[0] none [3] 2b011e15ba[0] none [0] none [none] |
ASM:Graph none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none ASM:Graph none:none ASM:Graph none:none ASM:Graph none:none none:none |
PolyEnE| none|none none|none none|none none|none StarForce| none|none none|none Armadillo| none|none MEW| UPX| none|none none|none none|none StarForce| none|none UPX| none|none PolyEnE| Armadillo| Armadillo| none|none none|none none|none none|none none|none none|none PolyEnE| UPX| UPX| UPX| StarForce| ASPack| none|none |
lines=68 lines=64 none none none none none none none none none none none none none none none none none lines=93 embedded dns none none none none none none none none lines=68 none lines=174 embedded dns none lines=3122 embedded dns lines=298 embedded dns none |
trace trace none none none trace none none trace none trace trace none none none trace none trace none trace trace trace none none none none none none trace trace trace trace trace trace none |