Score: 0.8 (>= 0.8) Infected Target: 130.107.226.158 Infector List: 115.135.109.46 Egg Source List: 115.135.109.46 C & C List: Peer Coord. List: Resource List: Observed Start: 09/02/2009 04:24:11.752 PDT Report End: 09/02/2009 04:24:17.659 PDT Gen. Time: 09/02/2009 04:30:25.638 PDT INBOUND SCAN EXPLOIT 115.135.109.46 (44) (04:24:11.779 PDT-04:24:17.659 PDT) event=1:21390 (22) {tcp} E2[rb] REGISTERED FREE SHELLCODE x86 inc ebx NOOP 2: 445<-32523 (04:24:11.779 PDT-04:24:11.805 PDT) 2: 445<-32705 (04:24:13.638 PDT-04:24:13.663 PDT) 2: 445<-32708 (04:24:13.718 PDT-04:24:13.744 PDT) 2: 445<-32709 (04:24:13.881 PDT-04:24:13.907 PDT) 2: 445<-32660 (04:24:13.429 PDT-04:24:13.455 PDT) 2: 445<-32661 (04:24:13.264 PDT-04:24:13.290 PDT) 2: 445<-32673 (04:24:13.348 PDT-04:24:13.374 PDT) 2: 445<-32670 (04:24:13.183 PDT-04:24:13.209 PDT) 2: 445<-33083 (04:24:17.634 PDT-04:24:17.659 PDT) 2: 445<-32836 (04:24:14.931 PDT-04:24:14.956 PDT) 2: 445<-32706 (04:24:13.799 PDT-04:24:13.825 PDT) ------------------------- event=1:299998 (22) {tcp} E2[rb] SHELLCODE x86 inc ebx NOOP 2: 445<-32705 (04:24:13.638 PDT-04:24:13.663 PDT) 2: 445<-32706 (04:24:13.799 PDT-04:24:13.825 PDT) 2: 445<-32523 (04:24:11.779 PDT-04:24:11.805 PDT) 2: 445<-32660 (04:24:13.429 PDT-04:24:13.455 PDT) 2: 445<-32661 (04:24:13.264 PDT-04:24:13.290 PDT) 2: 445<-32673 (04:24:13.348 PDT-04:24:13.374 PDT) 2: 445<-33083 (04:24:17.634 PDT-04:24:17.659 PDT) 2: 445<-32670 (04:24:13.183 PDT-04:24:13.209 PDT) 2: 445<-32836 (04:24:14.931 PDT-04:24:14.956 PDT) 2: 445<-32708 (04:24:13.718 PDT-04:24:13.744 PDT) 2: 445<-32709 (04:24:13.881 PDT-04:24:13.907 PDT) EXPLOIT (slade) EGG DOWNLOAD 115.135.109.46 (13) (04:24:11.752 PDT) event=1:2001683 {tcp} E3[rb] BLEEDING-EDGE Malware Windows executable sent from remote host 1028<-32990 (04:24:15.469 PDT) ------------------------- event=1:3000006 (11) {tcp} E3[rb] BotHunter MALWARE executable upload 445<-32523 (04:24:11.752 PDT) 445<-32670 (04:24:13.157 PDT) 445<-32661 (04:24:13.237 PDT) 445<-32673 (04:24:13.321 PDT) 445<-32660 (04:24:13.402 PDT) 445<-32705 (04:24:13.611 PDT) 445<-32708 (04:24:13.692 PDT) 445<-32706 (04:24:13.772 PDT) 445<-32709 (04:24:13.855 PDT) 445<-32836 (04:24:14.904 PDT) 445<-33083 (04:24:17.607 PDT) ------------------------- event=1:5001684 {tcp} E3[rb] BotHunter Malware Windows executable (PE) sent from remote host 1028<-32990 (04:24:15.469 PDT) C and C TRAFFIC PEER COORDINATION OUTBOUND SCAN ATTACK PREP DECLARE BOT tcpslice 1251890651.752 1251890657.660 inputFile.tcpd | tcpdump -r - -w outputFile.tcpd 'host 130.107.226.158' ============================== SEPARATOR ================================