Pattern JUL-AUGJ

107 samples (WinXP (100%))


Ports
InfectionListenEgg-downloadUpload
445 (100%)80 (100%)1031 (70%)
1032 (30%)
80 (94%)
Filenames
ProcessesExecutables
MSMSGS.EXE (100%)ndisrd.sys (100%)
DCPROMO.LOG (98%)
index.dat (98%)

random 6/7/8
character filename
Registry keys
...CurrentVersion\InternetSettings (100%)
...InternetSettings\Zones (100%)
...Windows\CurrentVersion (100%)
...Zones\0 (100%)
...Zones\1 (100%)
...Zones\2 (100%)

full list

Snort IDs
1:2000032 (100%)
1:2000033 (100%)
1:2001683 (100%)
1:2466 (100%)
1:3000000 (100%)
1:99913 (100%)

full list

Static analysis
MD5Antivirus labelsDomain
a12cab... (69%)
df17a6... (21%)

full list

berbew (100%)
berkor (100%)
doxpar (100%)
padobot (100%)
korgo (95%)
padodor (71%)

full list

53bank.com (100%)
acrolein-hawk.rubanking.h... (100%)
alfabank.ru (100%)
asmworm.com (100%)
atmacasoft.com (100%)
barclays.com (100%)

full list