15.07.2013 Views

Report - CrySyS Lab

Report - CrySyS Lab

Report - CrySyS Lab

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Table stat_TV_log has essentially the same content. Most of the Russian IP addresses seem to<br />

located in Ingushethia (e.g., 212.94.14.XXX from ingushsvyaz network). Note, that this map was<br />

created by the IP addresses only, so it is possible that some victims with dynamic IP addresses are<br />

shown multiple times.<br />

While stat_TV table is the most interesting, as “TV” refers to the TeamViewer campaign, the victim IP<br />

information stored in different tables among different C&C servers are also revealing.<br />

Here, we show distribution of IP addresses on heat maps for each information source. One can<br />

clearly see how different campaigns focus on different geographic regions.<br />

Figure 20 – Distribution of IP address used to upload files into the bannetwork.org FTP server,<br />

2010-02-01 – 2013-02-25<br />

16

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!