BotHunter ®
  Cyber-TA Internet Release
  Computer Science Laboratory
  SRI International


  SAMPLE NAME:    Nepoe_botHunter.txt
  Last Updated: Tue Dec 29 13:38:32 2009
BOTHUNTER LOGO
www.BOTHUNTER.net


Victim IP
Max Score
Profiles
CCs
Events
192.168.1.159
1.8 VIEW 1
  • 67.43.236.67 Country: Canada (Ca), City: (Unknown City).
  • 1:299913 {tcp} Inbound Attack: SHELLCODE x86 0x90 unicode NOOP; 135<-27887
  • 1:3000003 (2) {tcp} Egg Download: BotHunter HTTP-based .exe Upload on backdoor port; 1038->80
  • 1:1444 (2) {udp} Egg Download: TFTP GET from external source; 1028->69
  • 1:2008120 (2) {udp} Egg Download: ET POLICY Outbound TFTP Read Request; 1028->69
  • 1:3001441 (2) {udp} Egg Download: TFTP GET .exe from external source; 1028->69
  • 1:2404011 {tcp} C&C Communication: ET DROP Known Bot C&C Server Traffic (group 12) ; 1031->10324