Pattern AUGUST-K

8 samples (WinXP (100%))


Ports
InfectionListenEgg-downloadUpload
1034 (62%)
445 (25%)
9996 (88%)
5554 (50%)
445 (38%)
1028 (25%)
1842 (25%)
1844 (25%)

full list

9996 (88%)
445 (50%)
9996 (50%)
1083 (25%)
Filenames
ProcessesExecutables
MSMSGS.EXE (100%)

random 8
character filename
index.dat (100%)
avserve2.exe (50%)
Snort IDs
1:99913 (100%)
1:2000047 (88%)
1:2466 (88%)
1:2001056 (62%)
1:2001569 (50%)
1:3000004 (50%)

full list

Network chatter
FTP
user=anonymous (100%)
pass=bin (86%)
server=OK (71%)
destport=1025 (29%)
Static analysis
MD5Antivirus labels
1a2c0e... (25%)
831f4e... (25%)
None (25%)

full list

jobaka (67%)
bbju (33%)
injeven (33%)
poebot (33%)
rizo (33%)