Report - CrySyS Lab
Report - CrySyS Lab
Report - CrySyS Lab
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
Table stat_TV_log has essentially the same content. Most of the Russian IP addresses seem to<br />
located in Ingushethia (e.g., 212.94.14.XXX from ingushsvyaz network). Note, that this map was<br />
created by the IP addresses only, so it is possible that some victims with dynamic IP addresses are<br />
shown multiple times.<br />
While stat_TV table is the most interesting, as “TV” refers to the TeamViewer campaign, the victim IP<br />
information stored in different tables among different C&C servers are also revealing.<br />
Here, we show distribution of IP addresses on heat maps for each information source. One can<br />
clearly see how different campaigns focus on different geographic regions.<br />
Figure 20 – Distribution of IP address used to upload files into the bannetwork.org FTP server,<br />
2010-02-01 – 2013-02-25<br />
16