Pattern L

28 samples


Ports
InfectionEgg-downloadUpload
mostly 445445 (50%)
443 (43%)
68 (39%)
44445 (64%)
443 (36%)
Filenames
Executables
Abort (46%)
Snort IDs
1:2001683 (100%)
555:5555005 (100%)
1:2000032 (96%)
1:2466 (96%)
1:5001684 (82%)
1:3000004 (64%)
1:2002024 (57%)
1:2000046 (50%)
1:2000345 (50%)
1:99906 (50%)
Network chatter
FTP
exec=resource32w.exe (64%)
pass=a (64%)
user=a (57%)
server=WinFtpd 1.2 (54%)
Static analysis
MD5
usually None