Score: 0.8 (>= 0.8) Infected Target: 130.107.232.131 Infector List: 95.89.121.192 Egg Source List: 95.89.121.192 C & C List: Peer Coord. List: Resource List: Observed Start: 09/02/2009 03:50:00.109 PDT Report End: 09/02/2009 03:50:03.139 PDT Gen. Time: 09/02/2009 03:50:03.139 PDT INBOUND SCAN EXPLOIT 95.89.121.192 (28) (03:50:00.115 PDT-03:50:03.139 PDT) event=1:21390 (14) {tcp} E2[rb] REGISTERED FREE SHELLCODE x86 inc ebx NOOP 2: 445<-1519 (03:50:02.938 PDT-03:50:02.949 PDT) 2: 445<-1524 (03:50:02.976 PDT-03:50:02.992 PDT) 2: 445<-1528 (03:50:03.092 PDT-03:50:03.102 PDT) 2: 445<-1105 (03:50:00.115 PDT-03:50:00.122 PDT) 2: 445<-1523 (03:50:03.019 PDT-03:50:03.027 PDT) 2: 445<-1527 (03:50:03.127 PDT-03:50:03.139 PDT) 2: 445<-1518 (03:50:03.064 PDT-03:50:03.072 PDT) ------------------------- event=1:299998 (14) {tcp} E2[rb] SHELLCODE x86 inc ebx NOOP 2: 445<-1527 (03:50:03.127 PDT-03:50:03.139 PDT) 2: 445<-1528 (03:50:03.092 PDT-03:50:03.102 PDT) 2: 445<-1523 (03:50:03.019 PDT-03:50:03.027 PDT) 2: 445<-1105 (03:50:00.115 PDT-03:50:00.122 PDT) 2: 445<-1518 (03:50:03.064 PDT-03:50:03.072 PDT) 2: 445<-1524 (03:50:02.976 PDT-03:50:02.992 PDT) 2: 445<-1519 (03:50:02.938 PDT-03:50:02.949 PDT) EXPLOIT (slade) EGG DOWNLOAD 95.89.121.192 (9) (03:50:00.109 PDT) event=1:2001683 {tcp} E3[rb] BLEEDING-EDGE Malware Windows executable sent from remote host 1028<-1535 (03:50:02.423 PDT) ------------------------- event=1:3000006 (7) {tcp} E3[rb] BotHunter MALWARE executable upload 445<-1105 (03:50:00.109 PDT) 445<-1519 (03:50:02.925 PDT) 445<-1524 (03:50:02.970 PDT) 445<-1523 (03:50:03.005 PDT) 445<-1518 (03:50:03.040 PDT) 445<-1528 (03:50:03.085 PDT) 445<-1527 (03:50:03.114 PDT) ------------------------- event=1:5001684 {tcp} E3[rb] BotHunter Malware Windows executable (PE) sent from remote host 1028<-1535 (03:50:02.423 PDT) C and C TRAFFIC PEER COORDINATION OUTBOUND SCAN ATTACK PREP DECLARE BOT tcpslice 1251888600.109 1251888603.140 inputFile.tcpd | tcpdump -r - -w outputFile.tcpd 'host 130.107.232.131' ============================== SEPARATOR ================================