ANNOUNCEMENT


"We are proud to announce the latest release of BotHunter v1.5.0.


Our Latest Threat Intelligence

The data on this website is supplied as is, without warranty of any kind. You may NOT redistribute this data. Use or reliance on this data is at your own risk. (If you REALLY REALLY must redistribute our stuff or get access to the live backend data, binaries, and traces, then click HERE.)

Most Aggressive Malware Attack Source and Filters

Tue Feb 9 08:47:23 2010

rank = 30-day importance ranking (1 to 100) of most aggressive infection sources

rank hits first last domain country filter
54 6 01/18 02/01 rr.com NL  deny ip host 24.213.224.238 any log
48 3 02/07 02/07 - IR  deny ip host 77.104.69.99 any log
46 4 01/22 02/03 hinet.net TW  deny ip host 60.249.37.106 any log
44 5 01/12 02/07 rr.com US  deny ip host 208.125.168.68 any log
43 4 01/22 02/06 - TW  deny ip host 203.118.238.245 any log
42 3 01/31 02/05 mesh.ad.jp JP  deny ip host 122.132.42.237 any log
42 3 01/29 02/08 rr.com US  deny ip host 69.193.74.22 any log
41 5 01/10 02/08 hinet.net TW  deny ip host 60.249.37.247 any log
39 4 01/13 02/03 cox.net US  deny ip host 98.175.167.93 any log
38 3 01/26 02/08 rr.com US  deny ip host 69.193.78.147 any log

show me more!

Most Effective Malware-Related Snort Signatures

Tue Feb 9 08:47:30 2010

detects = 30-day signature detection rates based on exposure to 8015 malware infections

detects sidrev author phase description
56% 299913:1 snort inbound exploit shellcode x86 0x90 unicode noop
39% 52123:3 snort outbound scan registered free attack-responses micros...
34% 5001684:99 bothunter egg download bothunter malware windows executable (p...
33% 2001683:3 emerging threats egg download bleeding-edge malware windows executabl...
33% 3001441:1 snort egg download tftp get .exe from external source
33% 1444:3 snort egg download tftp get from external source
33% 2008120:1 emerging threats egg download policy outbound tftp read request
28% 22466:7 snort inbound exploit netbios smb-ds ipc$ unicode share access
18% 2002750:10 snort inbound policy reserved ip space traffic - bogon nets 2
16% 292000032:99 bothunter inbound exploit bothunter exploit lsa exploit

show me more!

Most Prolific BotNet Command and Control Servers and Filters

Tue Feb 9 08:46:57 2010

rate hits first last domain country filter
26 48 01/10 02/08 eastweb.ru RU  deny ip host 213.219.245.212 any log
16 29 01/15 02/08 163data.com.cn CN  deny ip host 218.93.201.51 any log
16 37 01/10 02/03 your-server.de DE  deny ip host 88.198.228.238 any log
7 7 02/06 02/08 greatnet.de DE  deny ip host 83.133.119.206 any log
6 11 01/10 02/08 lightstorm.sk SK  deny ip host 92.240.234.164 any log
3 10 01/10 01/31 ipaper.com UK  deny ip host 193.104.94.11 any log
0 1 01/23 01/23 allytech.com AR  deny ip host 200.49.145.197 any log
0 1 01/22 01/22 secureserver.net US  deny ip host 68.178.232.100 any log

show me more!

Most Observed Malware-Related DNS Names

Tue Feb 9 08:50:52 2010

embeds = number of malware binaries in which this DNS name was discovered
lookups = number of observed infections in which this DNS name was looked up
rank = 30-day importance ranking (1 to 100) of most prolific malware-related DNS names

rank lookups embeds first last country DNS
18 134 0 01/10 02/08 RU  citi-bank.ru
10 73 0 01/10 02/08 EU  pozeml.com
9 68 0 01/10 02/08 XX  pozemle.cn
8 69 1 01/10 02/08 CN  proxim.ircgalaxy.pl
6 69 0 01/10 02/02 CN  down1130.iwillhavesexygirls.com
5 35 0 01/13 02/07 GB  www.vouchercodez.com
5 21 0 02/03 02/08 CN  down0129.iwillhavesexygirls.com
4 31 0 01/15 02/08 XX  jsactivity.com
4 31 0 01/15 02/08 US  bfkq.com
4 20 0 01/28 02/05 US  mjjia.cn

show me more!

Most Aggressively Spreading Malware Binaries

Tue Feb 9 08:54:29 2010

rank hits first last AV rate Binary MD5
43 01/10 02/08 33 0 of 32 53bfe15e9143d86b276d73fdcaf66265
13 01/10 02/08 3 of 32 d9cb288f317124a0e63e3405ed290765
5 01/11 02/08 26 of 32 7d99b0e9108065ad5700a899a1fe3441
3 01/10 02/08 3 of 32 dc331fb79112a1d334b667c4eeb15cb7
3 01/12 02/06 0 33 of 32 07fabc79ef32cb4c036786c25545a59c
2 01/29 02/08 40 of 32 2b9bc1463d38ca0b4a5cc78ff6d79836
2 02/03 02/04 18 12 12 15 11 12 of 32 081b51ed7ecbb6766f60831f0b8eb8b0
1 01/12 02/08 29 of 32 831f4ee0a7d2d1113c80033f8d6ac372
1 01/10 02/08 34 35 of 32 38ed850a0e32db83cfd95d996a802121
1 01/23 02/08 37 36 of 32 47d3548e36e39e2b9d7ae21ea3fc49ba

show me more!