Score: 0.8 (>= 0.8) Infected Target: 130.107.206.169 Infector List: 80.140.116.163 Egg Source List: 80.140.116.163 C & C List: Peer Coord. List: Resource List: Observed Start: 09/02/2009 06:43:28.453 PDT Report End: 09/02/2009 06:43:40.354 PDT Gen. Time: 09/02/2009 06:43:40.354 PDT INBOUND SCAN EXPLOIT 80.140.116.163 (25) (06:43:28.453 PDT-06:43:40.354 PDT) event=1:21390 (12) {tcp} E2[rb] REGISTERED FREE SHELLCODE x86 inc ebx NOOP 2: 445<-4478 (06:43:39.640 PDT-06:43:39.670 PDT) 2: 445<-4464 (06:43:29.652 PDT-06:43:29.681 PDT) 2: 445<-4520 (06:43:40.323 PDT-06:43:40.354 PDT) 2: 445<-4479 (06:43:39.734 PDT-06:43:39.764 PDT) 2: 445<-4338 (06:43:28.514 PDT-06:43:28.544 PDT) 2: 445<-4508 (06:43:40.230 PDT-06:43:40.259 PDT) ------------------------- event=1:23003 {tcp} E2[rb] NETBIOS SMB-DS Session Setup NTMLSSP unicode asn1 overflow attempt 445<-4338 (06:43:28.453 PDT) ------------------------- event=1:299998 (12) {tcp} E2[rb] SHELLCODE x86 inc ebx NOOP 2: 445<-4478 (06:43:39.640 PDT-06:43:39.670 PDT) 2: 445<-4508 (06:43:40.230 PDT-06:43:40.259 PDT) 2: 445<-4338 (06:43:28.514 PDT-06:43:28.544 PDT) 2: 445<-4520 (06:43:40.323 PDT-06:43:40.354 PDT) 2: 445<-4479 (06:43:39.734 PDT-06:43:39.764 PDT) 2: 445<-4464 (06:43:29.652 PDT-06:43:29.681 PDT) EXPLOIT (slade) EGG DOWNLOAD 80.140.116.163 (8) (06:43:28.484 PDT) event=1:2001683 {tcp} E3[rb] BLEEDING-EDGE Malware Windows executable sent from remote host 1028<-4559 (06:43:30.748 PDT) ------------------------- event=1:3000006 (6) {tcp} E3[rb] BotHunter MALWARE executable upload 445<-4338 (06:43:28.484 PDT) 445<-4464 (06:43:29.621 PDT) 445<-4478 (06:43:39.608 PDT) 445<-4479 (06:43:39.704 PDT) 445<-4508 (06:43:40.198 PDT) 445<-4520 (06:43:40.291 PDT) ------------------------- event=1:5001684 {tcp} E3[rb] BotHunter Malware Windows executable (PE) sent from remote host 1028<-4559 (06:43:30.748 PDT) C and C TRAFFIC PEER COORDINATION OUTBOUND SCAN ATTACK PREP DECLARE BOT tcpslice 1251899008.453 1251899020.355 inputFile.tcpd | tcpdump -r - -w outputFile.tcpd 'host 130.107.206.169' ============================== SEPARATOR ================================