Pattern AUG-SEP-D

409 samples (Win2K-f (100%))


Ports
InfectionListenEgg-downloadUpload
445 (63%)
139 (37%)
135 (100%)
500 (100%)
1026 (100%)
1027 (93%)
1028 (86%)1028 (92%)
Filenames
Processes
ntvdm.exe (48%)
Registry keys
...InternetSettings\5.0 (100%)
...InternetSettings\Connections (99%)
...Microsoft\DownloadManager (96%)

full list

Snort IDs
1:3000003 (93%)
1:99913 (93%)
1:5001684 (89%)
1:2466 (64%)
1:2001683 (26%)
Network chatter
FTPHTTP
pass=1 (100%)
user=1 (96%)
server=fuckFtpd 0wns j0 (78%)
exec=Tilecomfree.com (44%)
UA=Mozilla/4.0 (compatibl... (100%)
version=1.0 (100%)
filename=/zmon.exe (97%)

full list

Static analysis
MD5Antivirus labels
a0a7e8... (43%)
None (22%)
a7c70c... (9%)
5777cb... (7%)
cefc8f... (6%)

full list

ircbot (99%)
sdbot (97%)
delbot (97%)
rinbot (97%)
nirbot (97%)
rbot (75%)

full list