Score: 0.8 (>= 0.8) Infected Target: 130.107.151.42 Infector List: 123.213.5.12 Egg Source List: 193.105.174.106, 64.120.232.147, 60.190.222.131, 123.213.5.12, 222.170.127.203 C & C List: Peer Coord. List: Resource List: Observed Start: 04/15/2010 08:21:08.433 PDT Report End: 04/15/2010 08:21:08.619 PDT Gen. Time: 04/15/2010 08:21:54.997 PDT INBOUND SCAN EXPLOIT 123.213.5.12 (3) (08:21:08.433 PDT-08:21:08.619 PDT) event=1:2003081 {tcp} E2[rb] ET EXPLOIT NETBIOS SMB DCERPC NetrpPathCanonicalize request (possible MS06-040) 139<-2297 (08:21:08.619 PDT) ------------------------- event=1:299913 (2) {tcp} E2[rb] SHELLCODE x86 0x90 unicode NOOP 2: 139<-2297 (08:21:08.433 PDT-08:21:08.619 PDT) EXPLOIT (slade) EGG DOWNLOAD 193.105.174.106 (08:21:26.730 PDT) event=1:3000003 {tcp} E3[rb] BotHunter HTTP-based .exe Upload on backdoor port 1032->80 (08:21:26.730 PDT) 64.120.232.147 (08:21:47.382 PDT) event=1:3000003 {tcp} E3[rb] BotHunter HTTP-based .exe Upload on backdoor port 1036->80 (08:21:47.382 PDT) 60.190.222.131 (2) (08:21:26.189 PDT) event=1:2001683 {tcp} E3[rb] BLEEDING-EDGE Malware Windows executable sent from remote host 1030<-81 (08:21:26.189 PDT) ------------------------- event=1:5001684 {tcp} E3[rb] BotHunter Malware Windows executable (PE) sent from remote host 1030<-81 (08:21:26.189 PDT) 123.213.5.12 (2) (08:21:16.816 PDT) event=1:2001683 {tcp} E3[rb] BLEEDING-EDGE Malware Windows executable sent from remote host 9988<-2386 (08:21:16.816 PDT) ------------------------- event=1:5001684 {tcp} E3[rb] BotHunter Malware Windows executable (PE) sent from remote host 9988<-2386 (08:21:16.816 PDT) 222.170.127.203 (8) (08:21:32.351 PDT) event=1:2001683 (3) {tcp} E3[rb] BLEEDING-EDGE Malware Windows executable sent from remote host 1034<-88 (08:21:32.572 PDT) 1037<-88 (08:21:49.327 PDT) 1043<-88 (08:21:54.997 PDT) ------------------------- event=1:3000003 (2) {tcp} E3[rb] BotHunter HTTP-based .exe Upload on backdoor port 1034->88 (08:21:32.351 PDT) 1037->88 (08:21:49.106 PDT) ------------------------- event=1:5001684 (3) {tcp} E3[rb] BotHunter Malware Windows executable (PE) sent from remote host 1034<-88 (08:21:32.572 PDT) 1037<-88 (08:21:49.327 PDT) 1043<-88 (08:21:54.997 PDT) C and C TRAFFIC PEER COORDINATION OUTBOUND SCAN ATTACK PREP DECLARE BOT tcpslice 1271344868.433 1271344868.620 inputFile.tcpd | tcpdump -r - -w outputFile.tcpd 'host 130.107.151.42' ============================== SEPARATOR ================================