Description
- Probable Name: Zbot at first, then others probably.
- Binary used: yL0T.exe
- MD5: e1090d7126dd88d0d1d39b68ea3aae11
- SHA1: e0513664515eacc65e9530afe665619f2bce3802
- SHA256: 3fc6bef5eac0656be77f8e96f2b7e08cadb418c11430e8c3d53b33788a93c86a
- VirusTotal
- HybridAnalysis
- RobotHash

- Infected Machines:
- Windows Name: Win3, IP: 10.0.2.103
- Duration: 6.15 days
Analysisof DNS connections
- 10.0.2.103-4.4.4.4-53-udp (From-Botnet-UDP-DNS-DGA-11)
- 10.0.2.103-8.8.8.8-53-udp (From-Botnet-UDP-DNS-DGA-12)
Timeline
Sat, 25 Jan 2014 13:01:41 GMT
Infected (approx)
Fri, 31 Jan 2014 16:40:53 GMT
Stopped (approx)