11.06.2015 Views

NTRG_ElasticBotnetReport_06102015

NTRG_ElasticBotnetReport_06102015

NTRG_ElasticBotnetReport_06102015

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

13 222.186.21.120 222.186.21.120:6633 Cmak_32 BILL CN CN<br />

14 222.186.34.70 23.234.25.203:15826 udpg BILL CN US<br />

15 222.186.56.21 23.107.16.6:80<br />

WN (FAILED DL) CN US<br />

2818 UNKNOWN CN US<br />

16 58.218.213.211<br />

58.218.213.211:2568<br />

xudp ELKNOT CN CN<br />

Manager BILL CN CN<br />

111.74.239.77:8080 xudp ELKNOT CN CN<br />

17 60.163.21.177 60.163.21.177:6663<br />

18 60.169.75.99 60.169.75.99:3113<br />

ddos2.4 BILL CN CN<br />

gsaa BILL CN CN<br />

wc1 BILL CN CN<br />

wc BILL CN CN<br />

19 61.160.215.111 122.224.48.28:8000 tooles ELKNOT CN CN<br />

20 61.160.232.221 61.160.232.221:9939<br />

ka AES CN CN<br />

fd AES CN CN<br />

61.176.223.77:111 zlbq ELKNOT CN CN<br />

61.176.223.77<br />

61.176.223.77:222<br />

zlby ELKNOT CN CN<br />

zlbu ELKNOT CN CN<br />

21<br />

61.176.222.160<br />

61.176.222.160:111<br />

zlwanby ELKNOT CN CN<br />

zlwanbq ELKNOT CN CN<br />

61.176.222.160:222 zlby ELKNOT CN CN<br />

61.176.220.162:111 zlbsr BILL CN CN<br />

61.176.220.162<br />

61.176.220.162:222<br />

zlbyy ELKNOT CN CN<br />

zlwanby ELKNOT CN CN<br />

Given that some of the files did not download from their respective HFS web server (marked in the<br />

previous table as “FAILED DL”), it is not possible to extract any configuration information from the<br />

entirety of the possible samples. But for the samples that Novetta was able to collect, the following C2<br />

information was extracted from 15 of the above patterns:<br />

THE ELASTIC BOTNET REPORT<br />

43

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!