Score: 1.3 (>= 0.8) Infected Target: 130.107.207.33 Infector List: 190.64.116.159 Egg Source List: 190.64.116.159 C & C List: Peer Coord. List: Resource List: 147.46.222.80 Observed Start: 04/25/2009 06:48:44.682 PDT Report End: 04/25/2009 06:48:46.146 PDT Gen. Time: 04/25/2009 06:54:28.549 PDT INBOUND SCAN EXPLOIT 190.64.116.159 (06:48:44.682 PDT) event=1:299913 {tcp} E2[rb] SHELLCODE x86 0x90 unicode NOOP 135<-29216 (06:48:44.682 PDT) EXPLOIT (slade) EGG DOWNLOAD 190.64.116.159 (6) (06:48:45.122 PDT-06:48:46.146 PDT) event=1:1444 (2) {udp} E3[rb] TFTP GET from external source 2: 1031->69 (06:48:45.122 PDT-06:48:46.146 PDT) ------------------------- event=1:2008120 (2) {udp} E3[rb] ET POLICY Outbound TFTP Read Request 2: 1031->69 (06:48:45.122 PDT-06:48:46.146 PDT) ------------------------- event=1:3001441 (2) {udp} E3[rb] TFTP GET .exe from external source 2: 1031->69 (06:48:45.122 PDT-06:48:46.146 PDT) C and C TRAFFIC PEER COORDINATION OUTBOUND SCAN ATTACK PREP 147.46.222.80 (06:54:28.549 PDT) event=1:2000352 {tcp} E6[rb] ET ATTACK RESPONSE IRC - dns request on non-std port 1038->3305 (06:54:28.549 PDT) DECLARE BOT tcpslice 1240667324.682 1240667326.147 inputFile.tcpd | tcpdump -r - -w outputFile.tcpd 'host 130.107.207.33' ============================== SEPARATOR ================================ Score: 1.0 (>= 0.8) Infected Target: 130.107.207.33 Infector List: Egg Source List: C & C List: 147.46.222.80 Peer Coord. List: Resource List: 147.46.222.80 Observed Start: 04/25/2009 06:54:28.904 PDT Gen. Time: 04/25/2009 06:54:36.377 PDT INBOUND SCAN EXPLOIT EXPLOIT (slade) EGG DOWNLOAD C and C TRAFFIC 147.46.222.80 (06:54:28.904 PDT) event=1:2000346 {tcp} E4[rb] ET ATTACK RESPONSE IRC - Name response on non-std port 1038<-3305 (06:54:28.904 PDT) PEER COORDINATION OUTBOUND SCAN ATTACK PREP 147.46.222.80 (06:54:28.912 PDT) event=1:2000352 {tcp} E6[rb] ET ATTACK RESPONSE IRC - dns request on non-std port 1038->3305 (06:54:28.912 PDT) DECLARE BOT tcpslice 1240667668.904 1240667668.905 inputFile.tcpd | tcpdump -r - -w outputFile.tcpd 'host 130.107.207.33' ============================== SEPARATOR ================================