Pattern D

750 samples (always WinXP)


Ports
InfectionEgg-downloadUpload
mostly 4451031 (99%)
445 (96%)
1031 (96%)
Filenames
ProcessesExecutables
MSMSGS.EXE (100%)
random 5/6/7/8 character filename
ftpupd.exe (100%)
random 5/6/7/8 character filename
Registry keys
HKEY_LOCAL_MACHINE@...Microsoft\Wireless (100%)
Snort IDs
1:2000032 (99%)
1:99913 (99%)
555:5555005 (98%)
1:2001683 (98%)
1:2466 (98%)
1:2000033 (98%)
1:2001569 (96%)
1:3000000 (96%)
1:3000003 (96%)
1:5001684 (72%)
Static analysis
MD5
usually None