BotHunter ®
  Cyber-TA Internet Release
  Computer Science Laboratory
  SRI International


  SAMPLE NAME:    Kublu_botHunter.txt
  Last Updated: Tue Dec 29 13:38:30 2009
BOTHUNTER LOGO
www.BOTHUNTER.net


Victim IP
Max Score
Profiles
CCs
Events
192.168.1.203
1.8 VIEW 2
  • 88.198.228.238 (Static.88-198-228-238.Clients.Your-Server.De), Country: Germany (De), City: Nuremberg.
  • 1:22351 {tcp} Inbound Attack: REGISTERED FREE NETBIOS DCERPC ISystemActivator path overflow attempt little endian unicode MAC_Dst: 00:30:48:30:03:AE; 135<-1887
  • 1:2299913 {tcp} Inbound Attack: ET SHELLCODE x86 0x90 unicode NOOP MAC_Dst: 00:30:48:30:03:AE; 135<-1887
  • 1:552123 {tcp} Outbound Attack: REGISTERED FREE ATTACK-RESPONSES Microsoft cmd.exe banner; 1027->707
  • 1:2001894 {tcp} Egg Download: ET MALWARE ToolbarPartner Spyware Agent Partner Install, [/inst.php?id=32&sid=0]; 1034->80
  • 1:2000419 (3) {tcp} Egg Download: ET POLICY PE EXE or DLL Windows file download; 1036<-88