Pattern JULYR

11 samples (Win2K-f (91%))


Ports
InfectionListenEgg-download
135 (91%)500 (91%)
1026 (91%)
1027 (100%)
Filenames
Processes
ntvdm.exe (100%)
Registry keys
...Microsoft\SecurityCenter (100%)
...Microsoft\WindowsFirewall (100%)
...Software\Symantec (100%)
...Symantec\LiveUpdateAdmin (100%)
...WindowsFirewall\DomainProfile (100%)
...WindowsFirewall\StandardProfile (100%)

full list

Snort IDs
1:5001684 (100%)
1:99913 (100%)
Static analysis
MD5Antivirus labelsDomain
5ddac0... (55%)
259613... (36%)

full list

ircbot (91%)
petribot (91%)
sdbot (91%)
spybot (91%)
tilebot (91%)
generic5 (55%)

full list

.com (100%)
.net (100%)
.org (100%)
.ru (100%)
http://tn0828-web.hp.info... (100%)
http://www.anonymitytest.... (100%)

full list