Botnet3

  • Start:           Mon Sep 14 22:24:25 2009
  • End:             Tue Sep 15 08:35:58 2009
  • Duration: 611 min or 36693 sec or 10 hs
  • Packets: 147302
  • Netflows: 32045
  • Size: 12M
  • Exes: Rbot-eldorado-2.exe
  • IRC Strings: Yes
  • SPAM Strings: No

Quick Description
This botnet uses the custom TCP port 2081 to connect to its IRC C&C server. It received the order to scan for open 445/TCP ports in the internal network. 
ċ
192.168.3.104-eldorado2-1.pcap.bz2
(1879k)
Unknown user,
May 31, 2012, 1:15 PM
Comments