Pattern JUL-AUGM

35 samples (WinXP (100%))


Ports
InfectionEgg-downloadUpload
445 (100%)445 (86%)
1031 (66%)
1032 (31%)
1031 (66%)
1032 (26%)
Filenames
ProcessesExecutables
MSMSGS.EXE (100%)

random 5/6/7/8
character filename
ftpupd.exe (97%)

random 4/5/6/7/8
character filename
Registry keys
...Microsoft\Wireless (97%)

full list

Snort IDs
1:2001683 (100%)
1:5001684 (100%)
1:2000032 (97%)
1:2000033 (97%)
1:2466 (97%)
1:99913 (97%)

full list

Static analysis
MD5Antivirus labels
736531... (46%)
86d186... (11%)
199fd8... (6%)
2edcd6... (6%)

full list

korgo (97%)
parite (97%)
pinfi (97%)
lsabot (86%)
padobot (83%)
win32_parite_b (71%)

full list