Cluster U

41 samples (WinXP (100%))


Ports
Attack portPorts
445 (100%)-
Files
DropsProcesses
cmd.exe (100%)
csrss.exe (100%)
explorer.exe (100%)
lsass.exe (100%)
services.exe (100%)
spoolsv.exe (100%)

full list

cmd.exe (100%)
csrss.exe (100%)
explorer.exe (100%)
lsass.exe (100%)
services.exe (100%)
spoolsv.exe (100%)

full list

Snort
Snort IDsSnort Egg IDsSnort Outbound IDs
1:1390:5 (66%)
1:2001944:3 (66%)
1:99998:2 (66%)
1:3003:4 (63%)
1:21390:5 (34%)
1:299998:1 (34%)
1:3000006:99 (100%)
1:2001684:3 (50%)
-
Registry
Registry keysRegistry values
--
Servers
DNS LookupsFailed connectionsC & C IPs
---
Chatter
FTP chatterHTTP chatterIRC chatter
pass=a (100%)
user=a (100%)
exec=msnmanegers.exe (78%)
--
Static Analysis
Antivirus labelsPacked MD5Unpacked MD5
-

diversity: N/A

diversity: N/A