samples | ports | |||||||||||||||||
![]() | 1:2000033 (100%) 1:2466 (100%) 1:3000003 (100%) 1:99913 (100%) 1:3000000 (100%) | 1031 (31%) | 1031 (32%) | padobot (100%) lsabot (100%) | random 5/6/7/8 character filename | random 5/6/7/8 character filename | 3ae357... (11%) a0139d... (8%) 1fcc14... (5%) 986b59... (5%) diversity: 3.6% | asechka.ru (100%) citi-bank.ru (100%) color-bank.ru (100%) crutop.nu (100%) kavkaz.ru (100%) | ||||||||||
![]() | WinXP (38%) | 135 (63%) 500 (63%) 1026 (63%) | 1:2466 (100%) 1:3000004 (100%) 1:5001684 (100%) 1:2001683 (99%) 1:2000046 (64%) | rbot (100%) spybot (99%) mybot (97%) sdbo (94%) | random 9 character filename | random 4/17 character filename | diversity: 5.6% | ...Microsoft\OLE (99%) ...InternetSettings\5.0 (55%) ...InternetSettings\Connections (55%) | server=WinFtpd 1.2 (99%) pass=a (98%) user=a (98%) | 82.114.64.251 (7%) | ||||||||
![]() | Win2K-f (38%) | 135 (38%) 1026 (38%) 500 (38%) | 1:1390 (100%) 1:2001683 (100%) 1:99998 (100%) 1:2001944 (99%) 1:3000006 (98%) | 68 (39%) 73 (34%) 74 (27%) | sdbot (88%) sheur (64%) spybot (58%) heur (46%) rbot (45%) | random 8/9/10 character filename | diversity: 24.9% | ...CurrentVersion\Run (37%) ...InternetSettings\5.0 (37%) | de.yahoo.com (100%) nitro.ucsc.edu (100%) paypal.com (100%) reconnect.in (100%) reconnect.in.ms (100%) | user=1 (100%) pass=1 (100%) exec=updetwind.exe (30%) | 61.191.228.152 (1%) | |||||||
![]() | 3067 (99%) | 1:2000033 (100%) 1:2466 (100%) 1:99913 (100%) 1:2001683 (100%) 1:5001684 (100%) | 1031 (35%) | 1031 (26%) | padobot (100%) ircbot (71%) sdbot (71%) lsabot (28%) | random 5/6/7/8 character filename | random 5/6/7/8 character filename | 042774... (7%) 492957... (5%) diversity: 4.4% | caen.fr.eu.undernet.org (100%) flanders.be.eu.undernet.o... (100%) gaspode.zanet.org.za (100%) graz.at.eu.undernet.org (100%) lia.zanet.net (100%) | |||||||||
![]() | Win2K-f (36%) | 135 (68%) 500 (68%) | 1:3000005 (100%) 1:5001684 (100%) 1:99998 (100%) 1:2001683 (62%) | 73 (40%) 68 (38%) | ircbot (71%) spybot (61%) mybot (54%) cakl (44%) muldrop (44%) | MSNGR32.com (47%) Tilecomfree.com (41%) | diversity: 27.5% | ...Microsoft\OLE (99%) ...ProductName\ProductID (53%) ...Software\ProductName (53%) ...HKEY_CLASSES_ROOT\.key (39%) ...Classes\.key (39%) | server=fuckFtpd 0wns j0 (100%) user=1 (100%) exec=MSNGR32.com (53%) exec=Tilecomfree.com (41%) | |||||||||
![]() | 1:1390 (50%) 1:2000032 (50%) 1:2000033 (50%) 1:2001944 (50%) 1:2466 (50%) | 1033 (40%) | dnascan (98%) maximus (98%) nspack (98%) sdbot (97%) klone (96%) | resource32w.exe (56%) f0dns.exe (43%) | diversity: 15.6% | pass=a (100%) exec=resource32w.exe (53%) server=WinFtpd 1.2 (51%) exec=f0dns.exe (41%) | ||||||||||||
![]() | Win2K-f (42%) | 500 (67%) 1026 (67%) | 1:2001944 (100%) 1:99998 (100%) 1:2001683 (99%) 1:5001684 (99%) 1:3003 (96%) | 68 (43%) 73 (29%) 74 (28%) | sheur (93%) sdbot (92%) heur (55%) rbot (38%) behav (36%) | random 9 character filename | 1fdbd6... (5%) diversity: 27.3% | ...Microsoft\OLE (99%) ...InternetSettings\5.0 (42%) ...InternetSettings\Connections (42%) | clone.ni (100%) clone.pm (100%) com.cm (100%) com.mv (100%) com.net (100%) | pass=1 (100%) server=NzmxFtpd 0wns j0 (100%) user=1 (100%) | 61.191.228.152 (1%) 211.169.249.223 (1%) | |||||||
![]() | 139 (22%) | 500 (100%) 1026 (100%) 1027 (100%) | 1:99913 (100%) 1:5001684 (81%) 1:2466 (69%) | ircbot (100%) nirbot (100%) rinbot (100%) sdbot (100%) vanbot (100%) | cefc8f... (10%) 147d16... (6%) diversity: 2.5% | ...InternetSettings\5.0 (100%) ...InternetSettings\Connections (100%) | version=1.0 (100%) filename=/zmon.exe (87%) | |||||||||||
![]() | 1:2000033 (100%) 1:2001683 (100%) 1:2466 (100%) 1:5001684 (100%) 1:99913 (100%) | 1031 (46%) | padobot (100%) berkor (99%) doxpar (98%) korgo (95%) hangup (95%) | DCPROMO.LOG (100%) index.dat (100%) random 6/7/8 character filename | df17a6... (27%) diversity: 2.9% | ...InternetSettings\Zones (100%) ...Windows\CurrentVersion (100%) ...Zones\0 (100%) ...Zones\1 (100%) ...Zones\2 (100%) | acrolein-hawk.rubanking.h... (100%) alfabank.ru (100%) asmworm.com (100%) atmacasoft.com (100%) barclays.com (100%) | |||||||||||
![]() | 1:99998 (100%) 1:2001944 (97%) 1:3000006 (97%) 1:3003 (87%) 1:5001684 (74%) | 73 (48%) | vipre (100%) rbot (78%) sheur (56%) spybot (44%) ircbot (22%) | o (100%) | diversity: 55.6% | pass=1 (99%) server=StnyFtpd 0wns j0 (97%) | ||||||||||||
![]() | Win2K-f (40%) | 500 (65%) 1026 (65%) | 1:1390 (89%) 1:99998 (89%) 1:3000005 (84%) 1:2001683 (79%) | 68 (44%) 73 (27%) 74 (27%) | mybot (97%) spybot (89%) gaobot (85%) ircbot (82%) sdbot (73%) | Tilecomnu.com (39%) random 9 character filename | diversity: 50.4% | ...Microsoft\OLE (99%) ...InternetSettings\5.0 (40%) ...InternetSettings\Connections (35%) | box.cm (77%) box.mv (77%) box.net (77%) box.ni (77%) box.ps (77%) | user=1 (100%) server=fuckFtpd 0wns j0 (83%) exec=Tilecomnu.com (39%) | ||||||||
![]() | 500 (100%) 1026 (100%) | 1:2001944 (100%) 1:99998 (100%) 1:3000006 (99%) 1:3003 (87%) 1:5001684 (53%) | 68 (52%) | diversity: 50.0% | pass=1 (91%) server=StnyFtpd 0wns j0 (79%) | |||||||||||||
![]() | 500 (100%) 1026 (100%) 44445 (100%) | 1:2000046 (100%) 1:2466 (100%) 1:3000004 (100%) 1:99906 (100%) | diversity: N/A | pass=a (88%) server=WinFtpd 1.2 (69%) exec=resource32w.exe (56%) | ||||||||||||||
![]() | WinXP (37%) | 139 (18%) | 500 (89%) 1026 (89%) | 1:2001683 (100%) 1:5001684 (100%) 1:99998 (100%) 1:2001944 (73%) 1:3000006 (73%) | 68 (65%) 139 (27%) | vipre (100%) sheur (62%) behav (61%) rbot (59%) ircbot (45%) | msupdates.exe (30%) | msupdates.exe (43%) wupdate.exe (37%) | a3e1e3... (17%) 51be10... (14%) 418432... (6%) 2a8ea0... (5%) diversity: 26.6% | ...CurrentVersion\Run (67%) ...InternetSettings\5.0 (67%) | user=1 (100%) server=StnyFtpd 0wns j0 (56%) server=NzmxFtpd 0wns j0 (44%) exec=msupdates.exe (30%) | |||||||
![]() | 1:2000033 (100%) 1:2001683 (100%) 1:2466 (100%) 1:3000000 (100%) 1:3000003 (100%) | 1031 (39%) | 1031 (39%) | padobot (99%) lsabot (98%) paradrop (22%) | MSMSGS.EXE (100%) random 5/6/7/8 character filename | random 5/6/7/8 character filename | a0139d... (14%) 3ae357... (12%) 1fcc14... (6%) 986b59... (5%) d6df39... (5%) diversity: 19.4% | |||||||||||
![]() | 1033 (38%) | 1:99998 (100%) 1:2001944 (98%) 1:3000006 (98%) 1:3003 (89%) 1:2001683 (46%) | 1033 (39%) | sdbot (100%) vipre (100%) wootbot (100%) agobot (90%) rbot (90%) | seegcom.exe (45%) ForBot-NoSSL_out.pr (42%) o (41%) | diversity: 7.7% | user=a (74%) exec=seegcom.exe (69%) user=1 (26%) | |||||||||||
![]() | 1028 (24%) | 500 (100%) 1026 (100%) | 1:2001944 (100%) 1:3000006 (100%) 1:99998 (100%) 1:2001683 (95%) 1:3003 (94%) | 1028 (96%) | wootbot (99%) ircbot (95%) agobot (92%) behav (75%) dnascan (75%) | b018b9... (18%) diversity: 16.1% | ...CurrentVersion\Run (100%) | pass=a (80%) exec=f0dns.exe (73%) exec=seegcom.exe (25%) | ||||||||||
![]() | WinXP (42%) | 135 (58%) 500 (58%) 1026 (58%) 1027 (58%) 1032 (42%) | 1:99998 (82%) 1:2001944 (71%) 1:3000006 (71%) 1:3003 (67%) 1:2001683 (36%) | 68 (25%) | MSMSGS.EXE (42%) | o (62%) ii (38%) | diversity: 100.0% | user=1 (76%) server=StnyFtpd 0wns j0 (45%) | ||||||||||
![]() | 139 (19%) | 1:99998 (100%) 1:5001684 (80%) 1:2001683 (73%) 1:2001944 (67%) 1:3000006 (67%) | 73 (45%) 74 (33%) 139 (33%) | ircbot (85%) sdbot (85%) behav (54%) heur (46%) rbot (38%) | firstswin.exe (47%) | diversity: 46.2% | user=1 (100%) server=NzmxFtpd 0wns j0 (59%) exec=firstswin.exe (42%) server=fuckFtpd 0wns j0 (31%) | |||||||||||
![]() | 500 (100%) 1026 (100%) 44445 (100%) | diversity: N/A | user=a (100%) server=WinFtpd 1.2 (94%) exec=resource32w.exe (92%) | |||||||||||||||
![]() | Win2K-f (34%) | 135 (34%) 500 (34%) 1026 (34%) | 1:2001944 (100%) 1:99998 (100%) 1:2001683 (98%) 1:5001684 (98%) 1:3000006 (96%) | 73 (49%) 68 (36%) | sdbot (79%) vipre (78%) spybot (73%) ircbot (68%) gaobot (51%) | random 8/9/10 character filename | fca931... (11%) 5a5345... (8%) 5b8445... (5%) d6bbb2... (5%) diversity: 53.4% | ...CurrentVersion\Run (34%) ...InternetSettings\5.0 (34%) | server=StnyFtpd 0wns j0 (100%) user=1 (100%) exec=windsservc.exe (26%) | 211.169.249.223 (3%) | ||||||||
![]() | 1034 (24%) 445 (19%) | 5554 (62%) 445 (29%) | 1:2466 (100%) 1:99913 (100%) 1:3000004 (84%) 1:2001056 (73%) | corr (92%) jobaka (90%) | dwwin.exe (39%) random 7/8 character filename | avserve2.exe (62%) random 7/8 character filename | 1a2c0e... (19%) diversity: 10.4% | pass=bin (94%) server=OK (87%) | ||||||||||
![]() | 500 (100%) 1026 (100%) | diversity: N/A | user=1 (100%) server=StnyFtpd 0wns j0 (65%) | |||||||||||||||
![]() | 1032 (26%) | 1:5001684 (100%) 1:2000032 (90%) 1:2000033 (90%) 1:2466 (90%) 1:99913 (90%) | 1031 (33%) | 1031 (33%) | virutas (89%) vipre (84%) korgo (82%) padobot (75%) horst (74%) | random 5/6/7/8 character filename | HelpHost.exe (100%) HelpSvc.exe (100%) NOTEPAD.EXE (100%) UploadM.exe (100%) accwiz.exe (100%) | b37139... (6%) diversity: 73.0% | brussels.be.eu.undernet.o... (35%) caen.fr.eu.undernet.org (35%) ced.dal.net (35%) coins.dal.net (35%) diemen.nl.eu.undernet.org (35%) | server=StnyFtpd 0wns j0 (90%) user=1 (90%) exec=sertys.exe (30%) exec=windervs.exe (30%) | ||||||||
![]() | 139 (26%) | 500 (100%) 1026 (100%) 1027 (100%) | 1:3000003 (100%) 1:5001684 (100%) 1:99913 (100%) 1:2466 (63%) | delbot (100%) generic5 (100%) ircbot (100%) nirbot (100%) rinbot (100%) | 5777cb... (29%) aef2e2... (6%) diversity: 4.8% | ...InternetSettings\5.0 (100%) ...InternetSettings\Connections (100%) | filename=/zmon.exe (100%) version=1.0 (100%) | |||||||||||
![]() | 1:2000033 (100%) 1:2466 (100%) 1:99913 (100%) 1:3000004 (69%) 1:2001683 (31%) | ftpupd.exe (31%) | diversity: N/A | |||||||||||||||
![]() | WinXP (26%) | 135 (76%) 500 (76%) 1026 (76%) | 1:2466 (100%) 1:3000004 (100%) 1:2001683 (97%) 1:5001684 (97%) 1:2000046 (74%) | sality (100%) hllp (92%) sdbot (90%) vipre (86%) gaobot (84%) | random 9 character filename | vcmgcd32.dll (100%) | f37730... (10%) 5fa3a9... (6%) 75a2c7... (6%) 760bc3... (6%) abccf3... (6%) diversity: 60.0% | ...Microsoft\OLE (95%) ...InternetSettings\5.0 (74%) ...InternetSettings\Connections (74%) | pass=a (100%) user=a (98%) server=WinFtpd 1.2 (84%) | |||||||||
![]() | 1:2000033 (100%) 1:2001683 (100%) 1:2466 (100%) 1:3000000 (100%) 1:3000003 (100%) | parite (100%) perite (100%) pinfi (100%) win32_parite_b (98%) lsabot (96%) | random 5/6/7/8 character filename | random 4/5/6/8 character filename | 744033... (7%) diversity: 37.0% | |||||||||||||
![]() | Win2K-f (43%) | 135 (20%) 139 (13%) | 500 (67%) 1026 (67%) 44445 (27%) | 1:2001683 (57%) 1:1390 (46%) 1:99913 (46%) 1:99998 (46%) 1:2001944 (25%) | 445 (25%) 1028 (25%) | ircbot (96%) poebot (83%) vanbot (80%) linkbot (78%) agobot (43%) | random 8 character filename | 04af72... (15%) 1f79d9... (13%) 0a0261... (9%) diversity: 43.5% | pass=1 (72%) user=1 (66%) pass=a (28%) exec=resource32w.exe (25%) user=a (25%) | |||||||||
1:2000033 (100%) 1:2001683 (100%) 1:2466 (100%) 1:3000000 (100%) 1:3000003 (100%) | 1031 (41%) | 1031 (41%) | virut (100%) vipre (97%) padobot (90%) horst (70%) vetor (50%) | random 5/6/7/8 character filename | random 5/6/7/8 character filename | 589768... (13%) 0faa8c... (10%) 521292... (10%) 6b716e... (7%) 84ba18... (7%) diversity: 46.7% | ||||||||||||
Win2K-f (39%) | 500 (65%) 1026 (65%) | 1:3000005 (100%) 1:5001684 (100%) 1:99998 (100%) 1:2001683 (33%) | 68 (50%) 73 (25%) 74 (25%) | ircbot (100%) mybot (100%) rbot (100%) sdbot (100%) sdbot2 (100%) | MSMSGS.EXE (61%) | 1d9b3a... (11%) 243aa2... (7%) cadc24... (7%) f1256e... (7%) f81454... (7%) diversity: 67.9% | ...Microsoft\OLE (100%) ...InternetSettings\5.0 (39%) ...InternetSettings\Connections (39%) | Tilehome.com (100%) clone.ac (100%) clone.ni (100%) clone.pm (100%) home.najd.us (100%) | pass=1 (100%) server=NzmxFtpd 0wns j0 (100%) user=1 (100%) | |||||||||
1028 (29%) | 1:2000033 (100%) 1:2466 (100%) 1:99913 (100%) 1:3000003 (89%) 1:3000000 (71%) | diversity: N/A | ||||||||||||||||
Win2K-f (32%) | 135 (64%) 500 (64%) 1028 (29%) 6388 (29%) | 1:2001683 (100%) 1:2001944 (100%) 1:3003 (100%) 1:5001684 (100%) 1:99998 (100%) | 73 (58%) 68 (29%) | rbot (70%) spybot (65%) ircbot (60%) dcom (50%) eggdrop (50%) | random 7/9 character filename | 5e25ca... (21%) e15c1e... (7%) diversity: 46.2% | ...Microsoft\OLE (100%) ...InternetSettings\5.0 (33%) ...InternetSettings\Connections (33%) | server=NzmxFtpd 0wns j0 (100%) user=1 (100%) exec=firstswin.exe (50%) exec=yfiswin.exe (43%) | ||||||||||
WinXP (26%) | 500 (91%) 1026 (91%) 69 (32%) | 1:3001441 (100%) 1:99913 (100%) | 1027 (30%) | random 7 character filename | diversity: N/A | ...CurrentVersion\Run (60%) ...InternetSettings\5.0 (60%) | ||||||||||||
WinXP (46%) | 445 (21%) 139 (12%) | 500 (81%) 1026 (81%) | 1:99913 (62%) 1:1390 (29%) 1:99998 (29%) | 1028 (29%) | delf (100%) eggdrop (100%) generic4 (100%) linkbot (100%) ms06040 (100%) | o (27%) | diversity: 4.2% | pass=1 (58%) user=1 (58%) exec=Tilecomfc.com (25%) | ||||||||||
WinXP (29%) | 1:5001684 (100%) 1:2000032 (94%) 1:2466 (94%) 1:3000004 (81%) 1:2000046 (69%) | bobic (91%) vipre (65%) baxbo (61%) proxed (57%) mytob (43%) | 7c0547... (8%) diversity: 87.5% | exec=resource32w.exe (94%) pass=a (94%) user=a (89%) | ||||||||||||||
WinXP (50%) | 500 (92%) 1026 (92%) | 1:2001683 (100%) 1:2001944 (100%) 1:3000006 (100%) 1:3003 (100%) 1:5001684 (100%) | 74 (60%) 68 (40%) | sdbot (100%) themida (100%) vipre (100%) | MSMSGS.EXE (50%) | o (100%) service.exe (100%) | 084c60... (18%) 19563a... (9%) diversity: 20.0% | pass=1 (100%) server=StnyFtpd 0wns j0 (100%) user=1 (100%) | ||||||||||
1:2000033 (100%) 1:2001683 (100%) 1:2466 (100%) 1:3000000 (100%) 1:3000003 (100%) | pepatch (100%) resourcer (100%) horst (90%) luder (90%) lsabot (81%) | dwwin.exe (38%) | 87a78a... (14%) 0313a9... (10%) 561de8... (10%) 76b306... (10%) 923941... (10%) diversity: 57.1% | |||||||||||||||
1:2000032 (67%) 1:2000033 (67%) 1:2466 (67%) 1:5001684 (67%) 1:2001683 (61%) | lsabot (90%) padobot (90%) | MSMSGS.EXE (100%) defrag.exe (100%) | index.dat (52%) random 5 character filename | diversity: 50.0% | server=StnyFtpd 0wns j0 (67%) user=1 (67%) exec=windervs.exe (33%) user=a (33%) | |||||||||||||
1:2000033 (100%) 1:2466 (100%) 1:99913 (100%) 1:3000000 (75%) 1:2001683 (70%) | 80 (30%) | diversity: 100.0% | ||||||||||||||||
1:2466 (100%) 1:5001684 (100%) 1:99913 (100%) 1:2000032 (90%) 1:2000033 (90%) | 1031 (30%) | berkor (93%) doxpar (93%) hangup (93%) korgo (93%) padobot (93%) | index.dat (100%) ndisrd.sys (100%) random 6/8 character filename | diversity: 94.1% | ...Zones\0 (100%) ...Zones\1 (100%) ...Zones\2 (100%) ...Zones\3 (100%) ...Zones\4 (100%) | |||||||||||||
diversity: 100.0% | ||||||||||||||||||
1:2000033 (100%) 1:2466 (100%) 1:3000000 (100%) 1:3000003 (100%) 1:99913 (100%) | 1032 (50%) | 1032 (50%) | random 5/8 character filename | random 5/8 character filename | diversity: 75.0% | |||||||||||||
diversity: N/A | ||||||||||||||||||
500 (100%) 1026 (100%) 1027 (36%) | 1:3000005 (100%) 1:99998 (100%) 1:5001684 (58%) 1:2001683 (50%) | 68 (50%) | diversity: 100.0% | user=1 (100%) server=fuckFtpd 0wns j0 (73%) exec=MSNGR32.com (36%) | ||||||||||||||
1:2000033 (100%) 1:2001683 (100%) 1:2466 (100%) 1:3000000 (100%) 1:3000003 (100%) | hckpk (92%) vipre (83%) padobot (75%) dabber (33%) paradrop (25%) | diversity: 91.7% | ||||||||||||||||
diversity: N/A | ||||||||||||||||||
500 (100%) 1026 (100%) 113 (91%) 69 (45%) 2001 (45%) | 1:2001683 (100%) 1:2001944 (100%) 1:5001684 (100%) 1:99998 (100%) 1:3000006 (90%) | 445 (89%) | vipre (100%) rbot (80%) spybot (80%) sheur (60%) dnascan (40%) | random 8/9 character filename | diversity: 100.0% | ...InternetSettings\5.0 (100%) ...CurrentVersion\RunServices (91%) | server=StnyFtpd 0wns j0 (100%) user=1 (100%) exec=windervs.exe (36%) exec=windservc.exe (36%) | |||||||||||
WinXP (45%) | 135 (36%) | 500 (67%) 1026 (67%) | 1:5001684 (100%) 1:99913 (60%) 1:1390 (40%) 1:99998 (40%) 1:2001944 (30%) | 1027 (30%) 1028 (30%) 1034 (30%) | injeven (100%) poebot (100%) rizo (100%) pakes (73%) nepoe (45%) | a39875... (27%) ed1295... (18%) diversity: 45.5% | ...Software\ProductName (100%) | pass=1 (67%) user=1 (50%) | ||||||||||
WinXP (36%) | 135 (64%) 500 (64%) 1026 (64%) | 1:2001683 (100%) 1:2466 (100%) 1:3000004 (100%) 1:5001684 (100%) 1:2000046 (80%) | ircbot (100%) mybot (100%) rbot (100%) robobot (100%) spybot (100%) | MSMSGS.EXE (36%) | soundman.exe (100%) | 858de5... (27%) 72d12d... (18%) ccbc77... (18%) diversity: 45.5% | pass=1 (100%) server=StnyFtpd 0wns j0 (100%) user=1 (100%) | |||||||||||
WinXP (50%) | 135 (60%) 500 (50%) 1026 (50%) | 1:99913 (100%) 1:3000004 (71%) | 1034 (29%) | 44152 (29%) | ec1d (100%) explet (100%) mudrop (100%) muldrop (100%) multidropper (100%) | MSMSGS.EXE (50%) | supu.exe (100%) index.dat (60%) fa4537ef.tmp (40%) fe43e701.htm (40%) feff35a0.htm (40%) full list | diversity: 22.2% | ...Software\SARS (100%) ...InternetSettings\5.0 (71%) ...InternetSettings\Connections (71%) | pass=p (100%) user=l (100%) destport=1028 (40%) | ||||||||
1031 (40%) | index.dat (100%) | diversity: N/A |