samples | ports | |||||||||||||
500 (100%) 1026 (100%) 1027 (99%) 445 (40%) | 1:3000003 (98%) 1:2466 (69%) 1:2001683 (34%) | rinbot (37%) nirbot (37%) ircbot (37%) vanbot (36%) delbot (33%) hupigon (26%) rbot (26%) | a0a7e837cba166943b44455ff2cb4fd9 (16%) cefc8f1802900f1b7028355b2fae0fd8 (7%) | HKEY_LOCAL_MACHINE@...Microsoft\DownloadManager (100%) HKEY_USERS@...InternetSettings\Connections (100%) | version=1.0 (96%) filename=/zmon.exe (69%) | |||||||||
1:99913 (100%) 1:2001683 (99%) 555:5555005 (99%) 1:2001569 (99%) 1:2000033 (98%) 1:2466 (98%) 1:3000003 (94%) 1:3000000 (94%) | 445 (99%) | padobot (97%) lsabot (79%) ircbot (24%) sdbot (24%) | random 5/6/7/8 character filename | random 5/6/7/8 character filename | 7f60162c2c0bd2cc7531e51328e98290 (18%) 3ae357d17b1d2e0174bf477c28422c29 (8%) 986b59708d2ca33f4c1ad682a5d7a673 (6%) | |||||||||
1033 (76%) | 1:2466 (50%) 1:1390 (49%) 1:99998 (49%) 1:3000004 (47%) 1:2001944 (40%) 1:3000006 (40%) 1:3003 (39%) 1:2000032 (34%) 1:2000033 (34%) | ftp.exe (76%) | o (71%) | pass=1 (46%) user=1 (46%) server=StnyFtpd 0wns j0 (37%) | ||||||||||
1:99913 (99%) 555:5555005 (98%) 1:2001683 (98%) 1:2466 (98%) 1:2000033 (98%) 1:2001569 (96%) 1:3000000 (96%) 1:3000003 (96%) 1:5001684 (72%) | 445 (96%) | random 5/6/7/8 character filename | random 5/6/7/8 character filename | |||||||||||
135 (45%) 500 (45%) 1026 (45%) | 1:2001683 (91%) 1:1390 (79%) 1:99998 (79%) 1:2001944 (69%) 1:3003 (68%) 1:3000006 (68%) | 73 (49%) 68 (44%) | random 8/9/10 character filename | HKEY_USERS@...Microsoft\OLE (45%) HKEY_USERS@...InternetSettings\5.0 (45%) | user=1 (79%) server=StnyFtpd 0wns j0 (51%) | |||||||||
500 (100%) 1026 (100%) 1027 (100%) 1028 (100%) 44445 (55%) | 1:2000032 (55%) 1:99906 (55%) 1:2000046 (54%) 1:2466 (54%) 1:1390 (43%) 1:99998 (43%) 1:2001944 (36%) 1:3000006 (36%) 1:3003 (34%) | exec=resource32w.exe (54%) pass=a (53%) user=a (53%) server=WinFtpd 1.2 (52%) destIP=10.2.32.201 (48%) pass=1 (46%) user=1 (46%) server=StnyFtpd 0wns j0 (37%) | ||||||||||||
1:2000032 (98%) 1:2001683 (98%) 1:2000033 (97%) 1:2466 (97%) 1:3000000 (97%) 1:5001684 (42%) | berkor (38%) padobot (38%) doxpar (36%) hangup (36%) korgo (34%) padodor (26%) | index.dat (95%) DCPROMO.LOG (94%) random 6/7/8 character filename | a12cab51ef99e98305668d189d0db147 (25%) df17a625eec94cdcd4b1b7998c099d87 (8%) | HKEY_USERS@...Zones\0 (99%) HKEY_USERS@...Zones\1 (99%) HKEY_USERS@...Zones\2 (99%) HKEY_USERS@...Zones\3 (99%) HKEY_USERS@...Zones\4 (99%) HKEY_LOCAL_MACHINE@...CurrentVersion\InternetSettings (99%) HKEY_LOCAL_MACHINE@...InternetSettings\Zones (99%) HKEY_LOCAL_MACHINE@...Windows\CurrentVersion (99%) HKEY_LOCAL_MACHINE@...Zones\0 (99%) | ||||||||||
1026 (99%) 135 (92%) 1027 (91%) | 1:3000003 (90%) 1:2466 (36%) | HKEY_USERS@...InternetSettings\Connections (99%) HKEY_LOCAL_MACHINE@...Microsoft\DownloadManager (90%) | version=1.0 (89%) filename=/zmon.exe (51%) | |||||||||||
500 (97%) 1026 (97%) | 1:99998 (100%) 1:2001944 (94%) 1:3000006 (93%) 1:3003 (89%) 1:5001684 (59%) 1:2001683 (57%) | 68 (54%) | user=1 (77%) server=StnyFtpd 0wns j0 (62%) | |||||||||||
500 (100%) 1026 (100%) 44445 (98%) | 1:2000046 (99%) 1:2466 (99%) 1:3000004 (99%) 1:99906 (99%) | user=a (58%) exec=resource32w.exe (54%) server=WinFtpd 1.2 (38%) | ||||||||||||
1:2000033 (100%) 1:2466 (100%) 1:99913 (100%) 1:3000003 (92%) 1:3000000 (53%) 1:2001683 (42%) | ||||||||||||||
555:5555005 (100%) 1:2000032 (96%) 1:2466 (96%) 1:5001684 (82%) 1:3000004 (64%) 1:2002024 (57%) 1:2000046 (50%) 1:2000345 (50%) 1:99906 (50%) | 443 (43%) 68 (39%) | 443 (36%) | pass=a (64%) user=a (57%) server=WinFtpd 1.2 (54%) |