Cluster S

84 samples (WinXP (100%))


Ports
Attack portPorts
445 (100%)12045 (43%)
44445 (38%)
Files
DropsProcesses
cmd.exe (100%)
csrss.exe (100%)
explorer.exe (100%)
lsass.exe (100%)
services.exe (100%)
spoolsv.exe (100%)

full list

cmd.exe (100%)
csrss.exe (100%)
explorer.exe (100%)
lsass.exe (100%)
services.exe (100%)
spoolsv.exe (100%)

full list

Snort
Snort IDsSnort Egg IDsSnort Outbound IDs
1:22000032:6 (100%)
1:22466:7 (100%)
1:292000032:99 (100%)
1:299913:1 (100%)
1:31000004:99 (62%)
1:5001684:99 (38%)
1:2001683:3 (28%)
1:52123:3 (100%)
Registry
Registry keysRegistry values
--
Servers
DNS LookupsFailed connectionsC & C IPs
---
Chatter
FTP chatterHTTP chatterIRC chatter
user=a (100%)
pass=a (68%)
exec=iexplorer.exe (27%)
--
Static Analysis
Antivirus labelsPacked MD5Unpacked MD5
authentium (100%)
stz_like (100%)
suspicious_malware (100%)

diversity: 100.0%

diversity: N/A