Cluster AK

22 samples (Win2K-f (50%)
WinXP (50%))


Ports
InfectionListenEgg-download
445 (45%)135 (92%)
500 (92%)
1026 (92%)
445 (100%)
74 (60%)
68 (40%)
Filenames
ProcessesExecutables
service.exe (91%)
MSMSGS.EXE (50%)
index.dat (100%)
o (100%)
service.exe (100%)
Snort IDs
1:1390 (100%)
1:2001683 (100%)
1:2001944 (100%)
1:3000006 (100%)
1:3003 (100%)
1:5001684 (100%)

full list

Network chatter
FTP
exec=service.exe (100%)
pass=1 (100%)
server=StnyFtpd 0wns j0 (100%)
user=1 (100%)
Static analysis
MD5Antivirus labels
7e4f94... (59%)
084c60... (18%)
19563a... (9%)

diversity: 20.0%

full list

heur (100%)
sdbot (100%)
themida (100%)
vipre (100%)