Pattern JUL-AUGC

543 samples (Win2K-f (100%))


Ports
InfectionListenEgg-downloadUpload
445 (72%)
139 (27%)
135 (100%)
500 (100%)
1026 (100%)
1027 (100%)
445 (37%)
1028 (91%)1028 (100%)
Filenames
Processes
ntvdm.exe (100%)
Registry keys
...Microsoft\DownloadManager (100%)
...InternetSettings\5.0 (100%)
...InternetSettings\Connections (100%)

full list

Snort IDs
1:3000003 (100%)
1:99913 (100%)
1:5001684 (87%)
1:2466 (73%)
1:2001683 (27%)
Network chatter
HTTP
UA=Mozilla/4.0 (compatibl... (100%)
filename=/zmon.exe (100%)
version=1.0 (100%)

full list

Static analysis
MD5Antivirus labels
a0a7e8... (39%)
None (21%)
a7c70c... (10%)
5777cb... (10%)
cefc8f... (9%)

full list

ircbot (100%)
sdbot (100%)
delbot (100%)
rinbot (100%)
nirbot (99%)
hupigon (69%)

full list