Description
- Probable Name: Zbot at first, then others probably.
- Binary used: yL0T.exe
- MD5: e1090d7126dd88d0d1d39b68ea3aae11
- SHA1: e0513664515eacc65e9530afe665619f2bce3802
- SHA256: 3fc6bef5eac0656be77f8e96f2b7e08cadb418c11430e8c3d53b33788a93c86a
- VirusTotal
- HybridAnalysis
- RobotHash

- Infected Machines:
- Windows Name: Win3, IP: 10.0.2.103
- Duration: 2.6 days
Analysis of DNS connections
- 10.0.2.103-4.4.4.4-53-udp (From-Botnet-UDP-DNS-DGA-15)
- 10.0.2.103-8.8.8.8-53-udp (From-Botnet-UDP-DNS-DGA-14)
- 2669 flows (Original amount of flows: 94015)
Timeline
Fri, 07 Feb 2014 16:58:45 GMT
Win3 infected
## Mon, 10 Feb 2014 07:26:54 GMT
stopped win3