Cluster AW

11 samples (Win2K-f (55%)
WinXP (45%))


Ports
InfectionListenEgg-download
445 (45%)
135 (36%)
135 (67%)
500 (67%)
1026 (67%)
445 (30%)
1027 (30%)
1028 (30%)
1034 (30%)
Filenames
ProcessesExecutables
MSMSGS.EXE (45%)index.dat (100%)
Registry keys
...ProductName\ProductID (100%)
...Software\ProductName (100%)

full list

Snort IDs
1:2001683 (100%)
1:5001684 (100%)
1:99913 (60%)
1:1390 (40%)
1:99998 (40%)
1:2001944 (30%)

full list

Network chatter
FTP
server=- (100%)
pass=1 (67%)
user=1 (50%)
Static analysis
MD5Antivirus labels
fff8b6... (36%)
a39875... (27%)
ed1295... (18%)

diversity: 45.5%

full list

bbju (100%)
injeven (100%)
poebot (100%)
rizo (100%)
pakes (73%)
nepoe (45%)

full list