Cluster AD

30 samples (WinXP (100%))


Ports
InfectionEgg-downloadUpload
445 (53%)1032 (59%)
1031 (41%)
1032 (59%)
1031 (41%)
Filenames
ProcessesExecutables
MSMSGS.EXE (100%)

random 5/6/7/8
character filename
ftpupd.exe (100%)

random 5/6/7/8
character filename
Registry keys
...Microsoft\Wireless (100%)

full list

Snort IDs
1:2000032 (100%)
1:2000033 (100%)
1:2001683 (100%)
1:2466 (100%)
1:3000000 (100%)
1:3000003 (100%)

full list

Static analysis
MD5Antivirus labels
999e33... (23%)
589768... (13%)
0faa8c... (10%)
521292... (10%)
6b716e... (7%)
84ba18... (7%)

diversity: 46.7%

full list

korgo (100%)
virut (100%)
vipre (97%)
padobot (90%)
horst (70%)
vetor (50%)

full list