Cluster Q

112 samples (WinXP (98%))


Ports
Attack portPorts
135 (100%)-
Files
DropsProcesses
cmd.exe (98%)
csrss.exe (98%)
explorer.exe (98%)
lsass.exe (98%)
services.exe (98%)
spoolsv.exe (98%)

full list

cmd.exe (98%)
csrss.exe (98%)
explorer.exe (98%)
lsass.exe (98%)
services.exe (98%)
spoolsv.exe (98%)

full list

Snort
Snort IDsSnort Egg IDsSnort Outbound IDs
1:299913:1 (92%)1:1444:3 (100%)
1:3001441:1 (100%)
1:2008120:1 (92%)
1:52123:3 (100%)
Registry
Registry keysRegistry values
--
Servers
Failed connectionsC & C IPs
--
Chatter
FTP chatterHTTP chatterIRC chatter
---
Static Analysis
Antivirus labelsPacked MD5Unpacked MD5
ikarus (83%)
authentium (75%)
fortinet (75%)
kaspersky (75%)
sophos (75%)
webwasher (75%)

full list

diversity: 88.9%

diversity: 80.0%