Description

Analysis

The DNS connections are:

An example of the DNS domains requested is:

An example of DGA subdomains that got an IP

Timeline

Sun Feb 23 11:44:48 CET 2014

started win17

Sun Feb 23 11:52:50 CET 2014

infected

Mon Apr 7 10:17:23 CEST 2014

Huge powerdown on Sun 06, at 10am... powering up now.