Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
05:35:00 | Win2K-f | 212.2.222.74 (TTNET.NET.TR): PROVIDER LOCAL REGISTRY, ANTALYA, ANTALYA, TR. (DSL) |
n/a | :www.maxmind.com :www.getmyip.org US:checkip.dyndns.org 108.168.255.243:80 DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
07:49:00 | WinXP | 46.202.60.135 (-): . |
n/a | DE:citi-bank.ru DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
09:59:00 | Win2K-f | 202.152.30.227 (-): POP SMG, SEMARANG, JAWA TENGAH, ID. (100Mbps) |
n/a | :www.maxmind.com US:checkip.dyndns.org :getmyip.co.uk :www.getmyip.org 108.168.255.243:80 ID:202.152.30.227:6731 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none 40 of 41 41 of 43 none none none none none none 29 of 29 38 of 42 none none 36 of 43 42 of 43 none 29 of 29 none none 2 of 37 41 of 42 2 of 37 none 42 of 43 none none none none 2 of 37 none 7 of 37 none 37 of 40 none none 39 of 40 none none 41 of 43 42 of 43 43 of 43 none 5 of 37 31 of 32 39 of 41 none 26 of 28 none 36 of 41 38 of 42 29 of 29 4 of 37 3 of 37 none none 37 of 40 41 of 42 none none none 39 of 43 40 of 41 40 of 42 none 26 of 38 37 of 43 34 of 34 30 of 32 2 of 37 none 3 of 37 3 of 37 41 of 44 34 of 41 29 of 29 none 41 of 41 41 of 42 38 of 41 none 41 of 43 |
00632e0224 NEW 01c4a6b3eb NEW 048b720afe NEW 057af4ccd4 NEW 085f286a6f NEW 0961e87d20 NEW 0a8dfdef4e NEW 0c118085f0 NEW 0c38af69f4 NEW 0cfab99612 NEW 0d1eb4df79 NEW 11dc631514 NEW 124bd705ec NEW 138706aee9 NEW 1511a3f219 NEW 17eecab10b NEW 1a2c0e6130 NEW 1bfb4f2148 NEW 1dda300310 NEW 216ec67841 NEW 22340630ac NEW 223d8089f8 NEW 267b33fd90 NEW 269ce49eb2 NEW 3679444e79 NEW 37cbbcb33e NEW 3c861e793c NEW 3dccf3e786 NEW 409ef22885 NEW 4eb2a4de70 NEW 507252387e NEW 51529da007 NEW 5285741560 NEW 5df33c8d31 NEW 5e12c93ecb NEW 5e8ccc4190 NEW 5e919067e5 NEW 656ea74fff NEW 67db574df4 NEW 6ce2f9af19 NEW 6ffc4847e4 NEW 74025075b0 NEW 741c93f3c1 NEW 741e3b03b3 NEW 76d2a5a1ef NEW 7cb3a68ab4 NEW 7d99b0e910 NEW 8061e5f689 NEW 83f6cb959d NEW 8a2553433c NEW 8ae2cc2e80 NEW 8ce32ded17 NEW 917c085aca NEW 94227c2434 NEW 99e375f06c NEW a09dc0cda1 NEW a4140e4032 NEW b009919adf NEW b72124df19 NEW b76758d4ca NEW b7805b2086 NEW bb460ddce2 NEW bcb3ec60f2 NEW c139a391ff NEW c645a73bd2 NEW ca3e3b13f3 NEW d20f157117 NEW d295efe2b8 NEW d60e538e72 NEW d8157df044 NEW d9cb288f31 NEW dc331fb791 NEW dd0a92984c NEW deffdf68e8 NEW df17a625ee NEW e4e9908e5c NEW e92ed9f79c NEW e99261ba46 NEW ecfbf321d3 NEW ed04b34990 NEW fb486908b0 NEW |
none[none] dd524b0259[0] none [none] none [none] none [none] none [none] none [none] none [none] none [none] none [0] none [none] none [none] none [none] none [none] none [none] none [none] none [0] none [none] none [none] none [3] none [none] none [3] none [none] none [none] none [none] none [none] none [none] none [none] none [3] none [none] none [3] none [none] 60590b8b67[0] none [none] none [none] 8d5f86583f[0] none [none] none [none] none [none] none [none] none [none] none [none] none [3] none [0] none [none] none [none] none [0] none [none] 445f56b6dd[0] none [none] none [0] none [3] none [3] none [none] none [none] none [3] none [none] none [none] none [none] none [none] none [none] none [none] none [none] none [none] none [3] none [none] 738f555183[0] none [none] none [3] none [none] 45603a001c[0] none [3] none [none] 2b011e15ba[0] none [0] none [none] none [none] none [none] none [none] none [none] none [none] |
none:none ASM:Graph none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none ASM:Graph none:none none:none ASM:Graph none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none ASM:Graph none:none none:none none:none ASM:Graph none:none none:none ASM:Graph none:none none:none none:none none:none none:none none:none none:none |
none|none PolyEnE| none|none none|none none|none none|none none|none none|none none|none PolyEnE| none|none none|none none|none none|none none|none none|none none|none none|none none|none StarForce| none|none StarForce| none|none none|none none|none none|none none|none none|none UPX| none|none UPX| none|none none|none none|none none|none PolyEnE| none|none none|none none|none none|none none|none none|none UPX| none|none none|none none|none PolyEnE| none|none StarForce| none|none PolyEnE| Armadillo| Armadillo| none|none none|none StarForce| none|none none|none none|none none|none none|none none|none none|none none|none tElock| none|none PolyEnE| none|none UPX| none|none UPX| UPX| none|none StarForce| ASPack| none|none none|none none|none none|none none|none none|none |
none lines=68 none none none none none none none lines=68 none none none none none none lines=60 none none none none none none none none none none none none none none none lines=59 none none lines=68 none none none none none none none lines=61 none none lines=68 none none none lines=68 none none none none none none none none none none none none none none none lines=68 none none none lines=174 embedded dns none none lines=3122 embedded dns lines=298 embedded dns none none none none none none |
none trace none none none none none none none trace none none none none none none trace none none trace none trace none none none none none none trace none trace none trace none none trace none none none none none none trace trace none none trace none trace none trace trace trace none none trace none none none none none none none none trace none trace none trace none trace trace none trace trace none none none none none none |
17:11:00 | Win2K-f | 188.72.5.2 (-): CELLNET LTD, IQ. (DSL) |
n/a | :www.maxmind.com US:checkip.dyndns.org :www.getmyip.org :getmyip.co.uk 108.168.255.243:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none 40 of 41 32 of 32 41 of 43 none none 7 of 37 none none none none 29 of 29 38 of 42 none none 36 of 43 42 of 43 none none 29 of 29 none none none 2 of 37 41 of 42 2 of 37 none none 42 of 43 none 3 of 37 none none 7 of 37 none none none 2 of 37 none 8 of 38 7 of 37 none 37 of 40 none none 39 of 40 none none 41 of 43 42 of 43 43 of 43 39 of 40 none 5 of 37 31 of 32 39 of 41 none 26 of 28 25 of 25 none 36 of 41 39 of 42 38 of 42 29 of 29 4 of 37 3 of 37 38 of 41 none none 37 of 40 29 of 29 41 of 42 none none none 39 of 43 28 of 41 40 of 41 40 of 42 none 26 of 38 41 of 42 37 of 43 34 of 34 30 of 32 2 of 37 none 39 of 41 none 3 of 37 3 of 37 41 of 44 34 of 41 29 of 29 none 41 of 41 41 of 42 38 of 41 none none 41 of 43 |
00632e0224 NEW 01c4a6b3eb NEW 03f912899b NEW 048b720afe NEW 057af4ccd4 NEW 085f286a6f NEW 08f384b76a NEW 0961e87d20 NEW 0a8dfdef4e NEW 0c118085f0 NEW 0c38af69f4 NEW 0cfab99612 NEW 0d1eb4df79 NEW 11dc631514 NEW 124bd705ec NEW 138706aee9 NEW 1511a3f219 NEW 166fb604f1 NEW 17eecab10b NEW 1a2c0e6130 NEW 1bfb4f2148 NEW 1dda300310 NEW 1ef46e2863 NEW 216ec67841 NEW 22340630ac NEW 223d8089f8 NEW 262edfe111 NEW 267b33fd90 NEW 269ce49eb2 NEW 2a22f7c5eb NEW 2daf861bde NEW 3679444e79 NEW 37cbbcb33e NEW 3862324588 NEW 3c861e793c NEW 3dccf3e786 NEW 3e043d1918 NEW 409ef22885 NEW 4eb2a4de70 NEW 4f6b51ea3b NEW 507252387e NEW 51529da007 NEW 5285741560 NEW 5df33c8d31 NEW 5e12c93ecb NEW 5e8ccc4190 NEW 5e919067e5 NEW 656ea74fff NEW 67db574df4 NEW 6ce2f9af19 NEW 6ffc4847e4 NEW 70ec5c4b3f NEW 74025075b0 NEW 741c93f3c1 NEW 741e3b03b3 NEW 76d2a5a1ef NEW 7cb3a68ab4 NEW 7d99b0e910 NEW 7f60162c2c NEW 8061e5f689 NEW 83f6cb959d NEW 8689eac5d3 NEW 8a2553433c NEW 8ae2cc2e80 NEW 8ce32ded17 NEW 917c085aca NEW 9276456bf8 NEW 94227c2434 NEW 99e375f06c NEW a09dc0cda1 NEW a12cab51ef NEW a4140e4032 NEW b009919adf NEW b72124df19 NEW b76758d4ca NEW b7805b2086 NEW b8076e37ae NEW bb460ddce2 NEW bcb3ec60f2 NEW c139a391ff NEW c645a73bd2 NEW c73335028d NEW ca3e3b13f3 NEW d20f157117 NEW d295efe2b8 NEW d60e538e72 NEW d6b1899047 NEW d8040f84d4 NEW d8157df044 NEW d9cb288f31 NEW dc331fb791 NEW dd0a92984c NEW deffdf68e8 NEW df17a625ee NEW e4e9908e5c NEW e92ed9f79c NEW e99261ba46 NEW ecfbf321d3 NEW ed04b34990 NEW f046b8c087 NEW fb486908b0 NEW |
none[none] dd524b0259[0] none [0] none [none] none [none] none [none] none [3] none [none] none [none] none [none] none [none] none [0] none [none] none [none] none [none] none [none] none [none] none [none] none [none] none [0] none [none] none [none] none [none] none [3] none [none] none [3] none [none] none [none] none [none] none [none] none [3] none [none] none [none] none [3] none [none] none [none] none [none] none [3] none [none] none [3] none [3] none [none] 60590b8b67[0] none [none] none [none] 8d5f86583f[0] none [none] none [none] none [none] none [none] none [none] f697adabdd[0] none [none] none [3] none [0] none [none] none [none] none [0] none [0] none [none] 445f56b6dd[0] none [none] none [none] none [0] none [3] none [3] none [none] none [none] none [none] none [3] none [0] none [none] none [none] none [none] none [none] none [none] 52953fed05[0] none [none] none [none] none [none] none [3] none [none] none [none] 738f555183[0] none [none] none [3] none [none] d683995e84[0] none [none] 45603a001c[0] none [3] none [none] 2b011e15ba[0] none [0] none [none] none [none] none [none] none [none] none [none] none [none] none [none] |
none:none ASM:Graph none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none ASM:Graph none:none none:none ASM:Graph none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none none:none ASM:Graph none:none none:none none:none ASM:Graph none:none ASM:Graph none:none none:none ASM:Graph none:none none:none none:none none:none none:none none:none none:none none:none |
none|none PolyEnE| none|none none|none none|none none|none MEW| none|none none|none none|none none|none PolyEnE| none|none none|none none|none none|none none|none none|none none|none none|none none|none none|none none|none StarForce| none|none StarForce| none|none none|none none|none none|none Armadillo| none|none none|none UPX| none|none none|none none|none UPX| none|none MEW| UPX| none|none none|none none|none none|none PolyEnE| none|none none|none none|none none|none none|none StarForce| none|none UPX| none|none none|none none|none PolyEnE| PolyEnE| none|none StarForce| none|none none|none PolyEnE| Armadillo| Armadillo| none|none none|none none|none StarForce| ASPack| none|none none|none none|none none|none none|none StarForce| none|none none|none none|none tElock| none|none none|none PolyEnE| none|none UPX| none|none PolyEnE| none|none UPX| UPX| none|none StarForce| ASPack| none|none none|none none|none none|none none|none none|none none|none |
none lines=68 lines=64 none none none none none none none none lines=68 none none none none none none none lines=60 none none none none none none none none none none none none none none none none none none none none none none lines=59 none none lines=68 none none none none none none none none lines=61 none none lines=68 lines=93 embedded dns none none none none lines=68 none none none none none none lines=281 embedded dns none none none none none none none none none none none none lines=68 none none none lines=73 none lines=174 embedded dns none none lines=3122 embedded dns lines=298 embedded dns none none none none none none none |
none trace trace none none none trace none none none none trace none none none none none none none trace none none none trace none trace none none none none trace none none trace none none none trace none trace trace none trace none none trace none none none none none trace none trace trace none none trace trace none trace none none trace trace trace none none none trace trace none none none none none trace none none none trace none none trace none trace none trace none trace trace none trace trace none none none none none none none |