BotHunter ®
  Cyber-TA Internet Release
  Computer Science Laboratory
  SRI International


  SAMPLE NAME:    Storm_botHunter.txt
  Last Updated: Mon Dec 28 21:19:32 2009
BOTHUNTER LOGO
www.BOTHUNTER.net


Victim IP
Max Score
Profiles
CCs
Events
192.168.184.132
1.8 VIEW 1
  • 222.254.25.22 (Localhost), Country: Viet Nam (Vn), City: (Unknown City).
  • 192.168.184.2 Country: (Private Address) City: (Private Address).
  • 1:2007701 {udp} C&C Communication: ET TROJAN Storm Worm Encrypted Variant 1 Traffic (1); 5650->26824
  • 777:7777005 {udp} Outbound Scan: Detected intense non-malware port scanning of 30 IPs (29 /24s) (# pkts S/M/O/I=3/84/110/4): 2836u:1, 53u:2, 123u:2, 28827u:1, 26391u:1, 1900u:3, 20142u:1, 80:1, 25606u:1, 23753u:1, 7404u:1, 5860u:1
  • 777:7777005 (2) {udp} Outbound Scan: Detected intense non-malware port scanning of 30 IPs (29 /24s) (# pkts S/M/O/I=3/88/162/4): 2836u:1, 25606u:1, 30963u:1, 53u:2, 123u:2, 28827u:1, 26391u:1, 14455u:1, 14579u:1, 1900u:3, 20142u:1, 21776u:1
  • 777:7777005 {udp} Outbound Scan: Detected moderate malware port scanning of 9 IPs (7 /24s) (# pkts S/M/O/I=3/83/8/4): 137u:67, 138u:16
  • 777:7777008 {udp} Malware Scan: Detected intense malware port scanning of 21 IPs (19 /24s) (# pkts S/M/O/I=3/83/20/4): 137u:67, 138u:16