Score: 0.9 (>= 0.8) Infected Target: 192.168.1.57 Infector List: Egg Source List: C & C List: 222.173.188.54, 221.13.128.166 Peer Coord. List: Resource List: Observed Start: 06/20/2011 09:35:31.091 PDT Gen. Time: 06/20/2011 09:35:50.953 PDT INBOUND SCAN EXPLOIT EXPLOIT MALWARE DNS EGG DOWNLOAD C and C TRAFFIC 222.173.188.54 (09:35:50.953 PDT) event=1:2003620 {tcp} E4[rb] ET MALWARE 51yes.com Spyware Reporting User Activity, [/sa.aspx?id=350976759&refe=http:/www.sodu.org/mulu_91449.html&location=http:/www.93zw.com/content/Book/2/2749/5568129.shtml&col] MAC_Src: 00:01:64:FF:CE:EA 52707->80 (09:35:50.953 PDT) C and C TRAFFIC (RBN) 221.13.128.166 (09:35:31.091 PDT) event=1:3810007 {tcp} E4[nbr] ET Known Russian Business Network Monitored Domain, [] MAC_Src: 00:01:64:FF:CE:EA 52655->80 (09:35:31.091 PDT) C and C DNS CHECK-IN OUTBOUND SKYPE CANDIDATE OUTBOUND SCAN (spp) OUTBOUND SCAN ATTACK PREP PEER COORDINATION DECLARE BOT tcpslice 1308587731.091 1308587731.092 inputFile.tcpd | tcpdump -r - -w outputFile.tcpd 'host 192.168.1.57' ============================== SEPARATOR ================================ Score: 0.8 (>= 0.8) Infected Target: 192.168.1.57 Infector List: 150.145.4.65 Egg Source List: 150.145.4.65 C & C List: Peer Coord. List: Resource List: Observed Start: 06/20/2011 12:52:38.389 PDT Gen. Time: 06/20/2011 12:52:38.389 PDT INBOUND SCAN EXPLOIT 150.145.4.65 (12:52:38.389 PDT) event=1:22009201 {tcp} E2[rb] ET CURRENT_EVENTS Conficker.b Shellcode, [] MAC_Dst: 00:30:48:30:03:AE 445<-3335 (12:52:38.389 PDT) EXPLOIT MALWARE DNS EGG DOWNLOAD 150.145.4.65 (12:52:38.389 PDT) event=1:3300007 {tcp} E3[rb] BotHunter Malware Windows executable (PE) sent from remote host, [] MAC_Src: 00:21:1C:EE:14:00 445<-3335 (12:52:38.389 PDT) C and C TRAFFIC C and C TRAFFIC (RBN) C and C DNS CHECK-IN OUTBOUND SKYPE CANDIDATE OUTBOUND SCAN (spp) OUTBOUND SCAN ATTACK PREP PEER COORDINATION DECLARE BOT tcpslice 1308599558.389 1308599558.390 inputFile.tcpd | tcpdump -r - -w outputFile.tcpd 'host 192.168.1.57' ============================== SEPARATOR ================================