Cluster AX

11 samples (Win2K-f (64%)
WinXP (36%))


Ports
InfectionListenEgg-downloadUpload
445 (36%)1957 (100%)
135 (64%)
500 (64%)
1026 (64%)
68 (60%)1957 (100%)
Filenames
ProcessesExecutables
soundman.exe (100%)
MSMSGS.EXE (36%)
index.dat (100%)
soundman.exe (100%)
Snort IDs
1:2000032 (100%)
1:2001683 (100%)
1:2466 (100%)
1:3000004 (100%)
1:5001684 (100%)
1:2000046 (80%)

full list

Network chatter
FTP
exec=soundman.exe (100%)
pass=1 (100%)
server=StnyFtpd 0wns j0 (100%)
user=1 (100%)
Static analysis
MD5Antivirus labels
5e6690... (27%)
858de5... (27%)
72d12d... (18%)
ccbc77... (18%)

diversity: 45.5%

full list

biww (100%)
ircbot (100%)
mybot (100%)
rbot (100%)
robobot (100%)
spybot (100%)

full list