67.43.236.68(Palevo worm)

Remote Host Port Number 67.43.236.68 1863 98.126.28.121 80 * The data identified by the following URLs was then requested from the remote web server: o http://host3.idfc2.info/fdc2.exe o http://host3.idfc2.info/fdc1.exe USER cakzts cakzts cakzts :vyrkvehxejzvjqvi NICK obpHQJTST MODE obpHQJTST +xi JOIN #rstn3 USERHOST obpHQJTST MODE ##a +smntu MODE ##b +smntu MODE ##c +smntu MODE #rstn3 +smntu There

tes.stuckin.org

tes.stuckin.org 98.126.47.218 tes.memehehz.info 98.126.176.186 tes.enterhere2.biz 98.126.176.186 UDP Connections Remote IP Address: 98.126.47.218 Port: 4444 Send Datagram: packet(s) of size 7 Recv Datagram: 1869 packet(s) of size 0 Remote IP Address: 98.126.176.186 Port: 4444 Send Datagram: packet(s) of size 7 Recv Datagram: 1868 packet(s) of size 0 Remote IP Address: 98.126.176.186 Port: 4444 Send Datagram: packet(s)

204.45.6.194

Remote Host Port Number 112.78.112.208 80 218.5.74.190 80 204.45.6.194 47221 * The following ports were open in the system: Port Protocol Process 1055 TCP ccdrive32.exe (%Windir%ccdrive32.exe) 1058 TCP ccdrive32.exe (%Windir%ccdrive32.exe) 1059 TCP ccdrive32.exe (%Windir%ccdrive32.exe) 2088 TCP ccdrive32.exe (%Windir%ccdrive32.exe) 2089 TCP ccdrive32.exe (%Windir%ccdrive32.exe) 2090 TCP ccdrive32.exe (%Windir%ccdrive32.exe) 2091 TCP ccdrive32.exe (%Windir%ccdrive32.exe) 2092 TCP ccdrive32.exe (%Windir%ccdrive32.exe) 2093

64.120.14.52

Remote Host Port Number 64.120.14.52 27034 PASS sextsex MODE #!!pp!!# +ix NICK [00|USA|765097] USER XP-4182 * 0 :COMPUTERNAME MODE [00|USA|765097] +ix JOIN #!!pp!!# sextsex Other details * The following port was open in the system: Port Protocol Process 1052 TCP tub3tex.exe.exe (%Windir%tub3tex.exe.exe) Registry Modifications * The newly created Registry Value is: o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun] + Java

62.193.242.95

Remote Host Port Number 62.193.242.95 8080 NICK [New|OutBreak|USA|XP|026717] PONG 22 MOTD USER [New|OutBreak|USA|XP|026717] * 0 :(null) MODE [New|OutBreak|USA|XP|026717] +iR JOIN #out PRIVMSG #out :[OutBreak]: 08New * The following port was open in the system: Port Protocol Process 1056 TCP iexplore.exe (%Windir%iexplore.exe) Registry Modifications * The newly created Registry Values are: o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun] + iexplore.exe =