Score: 1.1 (>= 0.8) Infected Target: 192.168.1.249 Infector List: Egg Source List: C & C List: Peer Coord. List: Resource List: Observed Start: 02/15/2013 00:02:08.786 PST Gen. Time: 02/15/2013 00:02:09.181 PST INBOUND SCAN EXPLOIT EXPLOIT MALWARE DNS EGG DOWNLOAD C and C TRAFFIC C and C TRAFFIC (RBN) C and C DNS CHECK-IN OUTBOUND SKYPE CANDIDATE OUTBOUND SCAN (spp) 130.20.29.131 (00:02:08.786 PST) event=777:7777005 {tcp} E5[bh] Detected moderate malware port scanning of 10 IPs (10 /24s) (# pkts S/M/O/I=0/10/0/0): 445:10, [] MAC_Src: 00:30:48:30:03:AF 0->0 (00:02:08.786 PST) OUTBOUND SCAN ATTACK PREP PEER COORDINATION Info PEER COORDINATION DECLARE BOT Standard Port DECLARE BOT Non-standard Port DECLARE BOT OUTBOUND INTENSE MALWARE PORT SCAN 130.20.29.131 (00:02:09.181 PST) event=777:7777008 {tcp} E8[bh] Detected intense malware port scanning of 21 IPs (21 /24s) (# pkts S/M/O/I=0/21/0/0): 445:21, [] MAC_Src: 00:30:48:30:03:AF 0->0 (00:02:09.181 PST) tcpslice 1360915328.786 1360915328.787 inputFile.tcpd | tcpdump -r - -w outputFile.tcpd 'host 192.168.1.249' ============================== SEPARATOR ================================ Score: 1.1 (>= 0.8) Infected Target: 192.168.1.249 Infector List: Egg Source List: C & C List: Peer Coord. List: Resource List: Observed Start: 02/15/2013 01:16:25.233 PST Gen. Time: 02/15/2013 01:16:25.311 PST INBOUND SCAN EXPLOIT EXPLOIT MALWARE DNS EGG DOWNLOAD C and C TRAFFIC C and C TRAFFIC (RBN) C and C DNS CHECK-IN OUTBOUND SKYPE CANDIDATE OUTBOUND SCAN (spp) 130.92.27.224 (01:16:25.233 PST) event=777:7777005 {tcp} E5[bh] Detected moderate malware port scanning of 10 IPs (10 /24s) (# pkts S/M/O/I=0/10/0/0): 445:10, [] MAC_Src: 00:30:48:30:03:AF 0->0 (01:16:25.233 PST) OUTBOUND SCAN ATTACK PREP PEER COORDINATION Info PEER COORDINATION DECLARE BOT Standard Port DECLARE BOT Non-standard Port DECLARE BOT OUTBOUND INTENSE MALWARE PORT SCAN 130.175.168.240 (01:16:25.311 PST) event=777:7777008 {tcp} E8[bh] Detected intense malware port scanning of 21 IPs (21 /24s) (# pkts S/M/O/I=0/21/0/0): 445:21, [] MAC_Src: 00:30:48:30:03:AF 0->0 (01:16:25.311 PST) tcpslice 1360919785.233 1360919785.234 inputFile.tcpd | tcpdump -r - -w outputFile.tcpd 'host 192.168.1.249' ============================== SEPARATOR ================================ Score: 1.1 (>= 0.8) Infected Target: 192.168.1.249 Infector List: Egg Source List: C & C List: Peer Coord. List: Resource List: Observed Start: 02/15/2013 01:50:36.621 PST Gen. Time: 02/15/2013 01:50:36.780 PST INBOUND SCAN EXPLOIT EXPLOIT MALWARE DNS EGG DOWNLOAD C and C TRAFFIC C and C TRAFFIC (RBN) C and C DNS CHECK-IN OUTBOUND SKYPE CANDIDATE OUTBOUND SCAN (spp) 130.104.13.216 (01:50:36.621 PST) event=777:7777005 {tcp} E5[bh] Detected moderate malware port scanning of 11 IPs (11 /24s) (# pkts S/M/O/I=0/10/1/0): 135:10, [] MAC_Src: 00:30:48:30:03:AF 0->0 (01:50:36.621 PST) OUTBOUND SCAN ATTACK PREP PEER COORDINATION Info PEER COORDINATION DECLARE BOT Standard Port DECLARE BOT Non-standard Port DECLARE BOT OUTBOUND INTENSE MALWARE PORT SCAN 130.104.13.216 (01:50:36.780 PST) event=777:7777008 {tcp} E8[bh] Detected intense malware port scanning of 21 IPs (21 /24s) (# pkts S/M/O/I=0/20/1/0): 135:20, [] MAC_Src: 00:30:48:30:03:AF 0->0 (01:50:36.780 PST) tcpslice 1360921836.621 1360921836.622 inputFile.tcpd | tcpdump -r - -w outputFile.tcpd 'host 192.168.1.249' ============================== SEPARATOR ================================ Score: 1.1 (>= 0.8) Infected Target: 192.168.1.249 Infector List: Egg Source List: C & C List: Peer Coord. List: Resource List: Observed Start: 02/15/2013 05:25:49.216 PST Gen. Time: 02/15/2013 05:25:49.447 PST INBOUND SCAN EXPLOIT EXPLOIT MALWARE DNS EGG DOWNLOAD C and C TRAFFIC C and C TRAFFIC (RBN) C and C DNS CHECK-IN OUTBOUND SKYPE CANDIDATE OUTBOUND SCAN (spp) 130.201.65.101 (05:25:49.216 PST) event=777:7777005 {tcp} E5[bh] Detected moderate malware port scanning of 10 IPs (10 /24s) (# pkts S/M/O/I=0/10/0/0): 445:10, [] MAC_Src: 00:30:48:30:03:AF 0->0 (05:25:49.216 PST) OUTBOUND SCAN ATTACK PREP PEER COORDINATION Info PEER COORDINATION DECLARE BOT Standard Port DECLARE BOT Non-standard Port DECLARE BOT OUTBOUND INTENSE MALWARE PORT SCAN 130.130.214.56 (05:25:49.447 PST) event=777:7777008 {tcp} E8[bh] Detected intense malware port scanning of 21 IPs (21 /24s) (# pkts S/M/O/I=0/21/0/0): 445:21, [] MAC_Src: 00:30:48:30:03:AF 0->0 (05:25:49.447 PST) tcpslice 1360934749.216 1360934749.217 inputFile.tcpd | tcpdump -r - -w outputFile.tcpd 'host 192.168.1.249' ============================== SEPARATOR ================================ Score: 1.1 (>= 0.8) Infected Target: 192.168.1.249 Infector List: Egg Source List: C & C List: Peer Coord. List: Resource List: Observed Start: 02/15/2013 14:01:21.524 PST Gen. Time: 02/15/2013 14:01:22.030 PST INBOUND SCAN EXPLOIT EXPLOIT MALWARE DNS EGG DOWNLOAD C and C TRAFFIC C and C TRAFFIC (RBN) C and C DNS CHECK-IN OUTBOUND SKYPE CANDIDATE OUTBOUND SCAN (spp) 130.3.149.120 (14:01:21.524 PST) event=777:7777005 {tcp} E5[bh] Detected moderate malware port scanning of 10 IPs (10 /24s) (# pkts S/M/O/I=0/10/0/0): 135:10, [] MAC_Src: 00:30:48:30:03:AF 0->0 (14:01:21.524 PST) OUTBOUND SCAN ATTACK PREP PEER COORDINATION Info PEER COORDINATION DECLARE BOT Standard Port DECLARE BOT Non-standard Port DECLARE BOT OUTBOUND INTENSE MALWARE PORT SCAN 130.3.149.120 (14:01:22.030 PST) event=777:7777008 {tcp} E8[bh] Detected intense malware port scanning of 21 IPs (21 /24s) (# pkts S/M/O/I=0/21/0/0): 135:21, [] MAC_Src: 00:30:48:30:03:AF 0->0 (14:01:22.030 PST) tcpslice 1360965681.524 1360965681.525 inputFile.tcpd | tcpdump -r - -w outputFile.tcpd 'host 192.168.1.249' ============================== SEPARATOR ================================ Score: 1.1 (>= 0.8) Infected Target: 192.168.1.249 Infector List: Egg Source List: C & C List: Peer Coord. List: Resource List: Observed Start: 02/15/2013 20:01:35.440 PST Gen. Time: 02/15/2013 20:01:35.655 PST INBOUND SCAN EXPLOIT EXPLOIT MALWARE DNS EGG DOWNLOAD C and C TRAFFIC C and C TRAFFIC (RBN) C and C DNS CHECK-IN OUTBOUND SKYPE CANDIDATE OUTBOUND SCAN (spp) 130.250.168.176 (20:01:35.440 PST) event=777:7777005 {tcp} E5[bh] Detected moderate malware port scanning of 10 IPs (10 /24s) (# pkts S/M/O/I=0/10/0/0): 445:10, [] MAC_Src: 00:30:48:30:03:AF 0->0 (20:01:35.440 PST) OUTBOUND SCAN ATTACK PREP PEER COORDINATION Info PEER COORDINATION DECLARE BOT Standard Port DECLARE BOT Non-standard Port DECLARE BOT OUTBOUND INTENSE MALWARE PORT SCAN 130.250.168.176 (20:01:35.655 PST) event=777:7777008 {tcp} E8[bh] Detected intense malware port scanning of 21 IPs (21 /24s) (# pkts S/M/O/I=0/21/0/0): 445:21, [] MAC_Src: 00:30:48:30:03:AF 0->0 (20:01:35.655 PST) tcpslice 1360987295.440 1360987295.441 inputFile.tcpd | tcpdump -r - -w outputFile.tcpd 'host 192.168.1.249' ============================== SEPARATOR ================================ Score: 1.1 (>= 0.8) Infected Target: 192.168.1.249 Infector List: Egg Source List: C & C List: Peer Coord. List: Resource List: Observed Start: 02/15/2013 20:21:34.905 PST Gen. Time: 02/15/2013 20:21:35.001 PST INBOUND SCAN EXPLOIT EXPLOIT MALWARE DNS EGG DOWNLOAD C and C TRAFFIC C and C TRAFFIC (RBN) C and C DNS CHECK-IN OUTBOUND SKYPE CANDIDATE OUTBOUND SCAN (spp) 130.210.82.228 (20:21:34.905 PST) event=777:7777005 {tcp} E5[bh] Detected moderate malware port scanning of 10 IPs (10 /24s) (# pkts S/M/O/I=0/10/0/0): 445:10, [] MAC_Src: 00:30:48:30:03:AF 0->0 (20:21:34.905 PST) OUTBOUND SCAN ATTACK PREP PEER COORDINATION Info PEER COORDINATION DECLARE BOT Standard Port DECLARE BOT Non-standard Port DECLARE BOT OUTBOUND INTENSE MALWARE PORT SCAN 130.226.70.130 (20:21:35.001 PST) event=777:7777008 {tcp} E8[bh] Detected intense malware port scanning of 21 IPs (21 /24s) (# pkts S/M/O/I=0/21/0/0): 445:21, [] MAC_Src: 00:30:48:30:03:AF 0->0 (20:21:35.001 PST) tcpslice 1360988494.905 1360988494.906 inputFile.tcpd | tcpdump -r - -w outputFile.tcpd 'host 192.168.1.249' ============================== SEPARATOR ================================ Score: 0.8 (>= 0.8) Infected Target: 192.168.1.249 Infector List: Egg Source List: C & C List: Peer Coord. List: Resource List: Observed Start: 02/15/2013 20:27:05.429 PST Gen. Time: 02/15/2013 20:27:05.429 PST INBOUND SCAN EXPLOIT EXPLOIT MALWARE DNS EGG DOWNLOAD C and C TRAFFIC C and C TRAFFIC (RBN) C and C DNS CHECK-IN OUTBOUND SKYPE CANDIDATE OUTBOUND SCAN (spp) OUTBOUND SCAN ATTACK PREP PEER COORDINATION Info PEER COORDINATION DECLARE BOT Standard Port DECLARE BOT Non-standard Port DECLARE BOT OUTBOUND INTENSE MALWARE PORT SCAN 130.228.73.147 (20:27:05.429 PST) event=777:7777008 {tcp} E8[bh] Detected intense malware port scanning of 26 IPs (26 /24s) (# pkts S/M/O/I=0/26/0/0): 445:25, 135, [] MAC_Src: 00:30:48:30:03:AF 0->0 (20:27:05.429 PST) tcpslice 1360988825.429 1360988825.430 inputFile.tcpd | tcpdump -r - -w outputFile.tcpd 'host 192.168.1.249' ============================== SEPARATOR ================================