Pattern JULYU

6 samples (Win2K-f (50%)
WinXP (50%))


Ports
InfectionEgg-downloadUpload
445 (100%)80 (50%)
1028 (50%)
1031 (50%)
445 (33%)
1038 (33%)
1039 (33%)
80 (50%)
1031 (50%)
44445 (50%)
1039 (33%)
Snort IDs
1:2000032 (100%)
1:2001683 (100%)
1:2466 (100%)
1:3000003 (100%)
1:5001684 (100%)
555:5555005 (100%)

full list

Network chatter
FTP
exec=resource32w.exe (100%)
pass=a (100%)
server=- (100%)
Static analysis
Antivirus labelsDomain
bobax (100%)
bobic (100%)
baxbo (80%)
vipre (60%)
korgo (40%)
lsabot (40%)

full list

SOFTWARE\Classes\Applicat... (100%)
paypal.com (100%)

full list