Description
- Probable Name: Zbot at first, then others probably.
- Binary used: yL0T.exe
- MD5: e1090d7126dd88d0d1d39b68ea3aae11
- SHA1: e0513664515eacc65e9530afe665619f2bce3802
- SHA256: 3fc6bef5eac0656be77f8e96f2b7e08cadb418c11430e8c3d53b33788a93c86a
- VirusTotal
- HybridAnalysis
- RobotHash

- Infected Machines:
- Windows Name: Win3, IP: 10.0.2.103
- Duration: 29.9 days
Analysis of DNS connections and Labels
- 10.0.2.103-4.4.4.4-53-udp (From-Botnet-UDP-DNS-DGA-16)
- 10.0.2.103-8.8.8.8-53-udp (From-Botnet-UDP-DNS-DGA-17)
- 3000 flows (Original amount of flows: 792097)
Timeline
Mon, 10 Feb 2014 09:36:05 GMT (approx)
Win3 infected
Wed, 12 Mar 2014 07:50:42 GMT (approx)
stopped win3