ANNOUNCEMENT
What's Next For Us: www.BLADE-DEFENDER.org
ATTENTION GRADUATE STUDENTS
SRI is seeking graduate student research interns for Summer 2010. For more details, click here.
Our Latest Threat Intelligence
The data on this website is supplied as is, without warranty of any kind. You may NOT redistribute this data. Use or reliance on this data is at your own risk. (If you REALLY REALLY must redistribute our stuff or get access to the live backend data, binaries, and traces, then click HERE.)
Most Aggressive Malware Attack Source and Filters
Sat Feb 11 08:38:21 2012
rank = 30-day importance ranking (1 to 100) of most aggressive infection sources
| rank | hits | first | last | domain | country | filter |
|---|---|---|---|---|---|---|
| 61 | 5 | 01/25 | 02/08 | rr.com | |
deny ip host 98.103.24.169 any log |
| 58 | 4 | 01/31 | 02/10 | covad.net | |
deny ip host 66.166.121.174 any log |
| 57 | 6 | 01/15 | 02/08 | starcat.ne.jp | |
deny ip host 58.146.5.26 any log |
| 57 | 4 | 02/02 | 02/08 | - | |
deny ip host 110.12.71.127 any log |
| 55 | 5 | 01/15 | 02/06 | jws.com | |
deny ip host 123.81.252.189 any log |
| 50 | 4 | 01/28 | 02/09 | htoj.j-cnet.jp | |
deny ip host 118.87.216.2 any log |
| 48 | 3 | 02/08 | 02/08 | link.net | |
deny ip host 82.201.187.118 any log |
| 45 | 3 | 02/05 | 02/06 | caucasus.net | |
deny ip host 95.104.45.153 any log |
| 45 | 5 | 01/15 | 02/06 | cox.net | |
deny ip host 70.182.76.81 any log |
| 44 | 4 | 01/24 | 02/10 | fpt-customers.fpt.vn | |
deny ip host 210.245.87.80 any log |
Most Effective Malware-Related Snort Signatures
Sat Feb 11 08:38:24 2012
detects = 30-day signature detection rates based on exposure to 5737 malware infections
| detects | sidrev | author | phase | description |
|---|---|---|---|---|
| 72% | 299913:1 | snort | inbound exploit | shellcode x86 0x90 unicode noop |
| 63% | 3000003:99 | bothunter | egg download | bothunter http-based .exe upload on bac... |
| 58% | 5001684:99 | bothunter | egg download | bothunter malware windows executable (p... |
| 58% | 2001683:3 | emerging threats | egg download | bleeding-edge malware windows executabl... |
| 57% | 22466:7 | snort | inbound exploit | netbios smb-ds ipc$ unicode share access |
| 48% | 292000032:99 | bothunter | inbound exploit | bothunter exploit lsa exploit |
| 48% | 22000032:6 | emerging threats | inbound exploit | bleeding-edge exploit lsa exploit |
| 47% | 3000000:99 | bothunter | egg download | bothunter http-based .exe upload on bac... |
| 27% | 2002750:10 | snort | inbound | policy reserved ip space traffic - bogon nets 2 |
| 23% | 52123:3 | snort | outbound scan | registered free attack-responses micros... |
Most Prolific BotNet Command and Control Servers and Filters
Sat Feb 11 08:38:15 2012
| rate | hits | first | last | domain | country | filter |
|---|---|---|---|---|---|---|
| 100 | 186 | 01/12 | 02/10 | - | |
deny ip host 213.155.14.161 any log |
| 11 | 24 | 01/12 | 02/10 | greatnet.de | |
deny ip host 83.133.119.197 any log |
| 1 | 1 | 02/07 | 02/07 | nacksystem.net | |
deny ip host 91.226.212.159 any log |
| 0 | 1 | 02/06 | 02/06 | ipv4ilink.net | |
deny ip host 94.63.147.131 any log |
Most Observed Malware-Related DNS Names
Sat Feb 11 08:41:28 2012
embeds = number of malware binaries in which this DNS name was discovered
lookups = number of observed infections in which this DNS name was looked up
rank = 30-day importance ranking (1 to 100) of most prolific malware-related DNS names
| rank | lookups | embeds | first | last | country | DNS |
|---|---|---|---|---|---|---|
| 70 | 552 | 0 | 01/12 | 02/10 | |
citi-bank.ru |
| 4 | 32 | 3 | 01/12 | 02/10 | |
moscow-advokat.ru |
| 3 | 20 | 0 | 01/13 | 02/08 | |
adiyamanlicigkoftecim.com |
| 3 | 19 | 0 | 01/13 | 02/08 | |
akcainsaat.com |
| 3 | 19 | 0 | 01/13 | 02/08 | |
akordketrzyn.ugu.pl |
| 3 | 19 | 0 | 01/13 | 02/08 | |
jsthomes.com |
| 3 | 18 | 0 | 01/13 | 02/08 | |
alsharqpaper.net |
| 3 | 18 | 0 | 01/13 | 02/08 | |
apadanapub.com |
| 2 | 17 | 0 | 01/13 | 02/08 | |
akdari.com |
| 2 | 21 | 0 | 01/12 | 02/08 | |
proxim.ircgalaxy.pl |
Most Aggressively Spreading Malware Binaries
Sat Feb 11 08:43:00 2012
| rank | hits | first | last | AV rate | Binary MD5 |
|---|---|---|---|---|---|
| 22 | 01/12 | 02/10 | 33 0 of 32 | 53bfe15e9143d86b276d73fdcaf66265 | |
| 19 | 01/12 | 02/10 | 26 of 32 | 7d99b0e9108065ad5700a899a1fe3441 | |
| 8 | 01/15 | 02/10 | 38 of 32 | 9276456bf8f5b676ccd60d249e025a11 | |
| 6 | 01/13 | 02/09 | 38 38 of 32 | d031b42d3fae9174b101871ef25cb257 | |
| 6 | 01/13 | 02/10 | 3 of 32 | d9cb288f317124a0e63e3405ed290765 | |
| 6 | 01/13 | 02/10 | 40 of 32 | bcb3ec60f24c71b13afaea068503ded8 | |
| 4 | 01/12 | 02/08 | 41 of 32 | fb486908b086c67488dab1deb871f706 | |
| 3 | 01/12 | 02/09 | 39 of 32 | d8040f84d47c7ab0476b8f624098b29b | |
| 3 | 01/13 | 02/09 | 37 of 32 | ca3e3b13f395bcff75a749d13806e251 | |
| 2 | 01/12 | 02/09 | 32 34 of 32 | 0b951c2832d8f4f56a9a07731ed287e3 |

