Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
09:10:00 | Win2K-f | 66.19.68.58 (MCLEODUSA.NET): PAETEC COMMUNICATIONS INC, NASHVILLE, TENNESSEE, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 133 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
21:06:00 | WinXP | 203.81.115.197 (KBN.NE.JP): KAGAWA T.V BROADCAST NETWORK CO .LTD, TOKYO, TOKYO, JP. (DSL) |
213.155.14.161:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |