Cluster AO

17 samples (WinXP (94%))


Ports
InfectionListenEgg-downloadUpload
445 (59%)80 (94%)1032 (60%)
1031 (30%)
80 (90%)
Filenames
ProcessesExecutables
MSMSGS.EXE (100%)DCPROMO.LOG (100%)
index.dat (100%)
ndisrd.sys (100%)

random 6/8
character filename
Registry keys
...InternetSettings\Zones (100%)
...Zones\0 (100%)
...Zones\1 (100%)
...Zones\2 (100%)
...Zones\3 (100%)
...Zones\4 (100%)

full list

Snort IDs
1:2001683 (100%)
1:2466 (100%)
1:5001684 (100%)
1:99913 (100%)
1:2000032 (90%)
1:2000033 (90%)

full list

Static analysis
MD5Antivirus labels
ada8af... (12%)

diversity: 94.1%

full list

berbew (93%)
berkor (93%)
doxpar (93%)
hangup (93%)
korgo (93%)
padobot (93%)

full list