BotHunter ®
  Cyber-TA Internet Release
  Computer Science Laboratory
  SRI International


  SAMPLE NAME:    Stamler.TrojanDownloader_botHunter.txt
  Last Updated: Mon Dec 28 21:19:17 2009
BOTHUNTER LOGO
www.BOTHUNTER.net


Victim IP
Max Score
Profiles
CCs
Events
192.168.1.157
2.1 VIEW 1
  • 24.87.46.107 Country: Canada (Ca), City: (Unknown City).
  • 1:299913 {tcp} Inbound Attack: SHELLCODE x86 0x90 unicode NOOP; 135<-3611
  • 1:1444 (2) {udp} Egg Download: TFTP GET from external source; 1028->69
  • 1:2008120 (2) {udp} Egg Download: ET POLICY Outbound TFTP Read Request; 1028->69
  • 1:3001441 (2) {udp} Egg Download: TFTP GET .exe from external source; 1028->69
  • 1:52123 {tcp} Outbound Attack: REGISTERED FREE ATTACK-RESPONSES Microsoft cmd.exe banner; 1027->707
  • 777:7777005 {tcp} Outbound Scan: Detected moderate malware port scanning of 9 IPs (3 /24s) (# pkts S/M/O/I=0/602/12/0): 69u:602