Description
- Probable Name: Zbot at first, then others probably.
- Binary used: yL0T.exe
- MD5: e1090d7126dd88d0d1d39b68ea3aae11
- SHA1: e0513664515eacc65e9530afe665619f2bce3802
- SHA256: 3fc6bef5eac0656be77f8e96f2b7e08cadb418c11430e8c3d53b33788a93c86a
- VirusTotal
- HybridAnalysis
- RobotHash

- Infected Machines:
- Windows Name: Win3, IP: 10.0.2.103
- Duration: 42.09 days
Analysis of DNS connections and Labels
- 10.0.2.103-4.4.4.4-53-udp (From-Botnet-UDP-DNS-DGA-19)
- 10.0.2.103-8.8.8.8-53-udp (From-Botnet-UDP-DNS-DGA-18)
Timeline
Wed, 05 Nov 2014 14:49:36 GMT
Win3 infected
Wed, 17 Dec 2014 17:07:48 GMT
stopped win3