ANNOUNCEMENT


What's Next For Us: www.BLADE-DEFENDER.org





ATTENTION GRADUATE STUDENTS


SRI is seeking graduate student research interns for Summer 2010. For more details, click here.






Our Latest Threat Intelligence

The data on this website is supplied as is, without warranty of any kind. You may NOT redistribute this data. Use or reliance on this data is at your own risk. (If you REALLY REALLY must redistribute our stuff or get access to the live backend data, binaries, and traces, then click HERE.)

Most Aggressive Malware Attack Source and Filters

Sat May 18 12:42:43 2013

rank = 30-day importance ranking (1 to 100) of most aggressive infection sources

rank hits first last domain country filter
46 3 05/12 05/15 fpt-customers.fpt.vn VN  deny ip host 210.245.83.152 any log
34 3 05/04 05/16 localhost VN  deny ip host 222.255.132.123 any log
27 2 05/07 05/17 - HN  deny ip host 200.107.121.33 any log
26 3 04/18 05/17 163data.com.cn CN  deny ip host 61.150.5.66 any log
26 3 04/19 05/12 theplanet.com US  deny ip host 209.62.53.98 any log
24 3 04/18 05/07 - -  deny ip host 42.112.16.150 any log
23 3 04/27 05/07 - -  deny ip host 42.112.16.74 any log
23 2 05/07 05/07 122.airtelbroadband.in IN  deny ip host 122.180.147.214 any log
23 3 04/30 05/03 covad.net US  deny ip host 67.100.108.242 any log
23 2 05/05 05/09 - -  deny ip host 186.149.106.222 any log

show me more!

Most Effective Malware-Related Snort Signatures

Sat May 18 12:42:46 2013

detects = 30-day signature detection rates based on exposure to 5494 malware infections

detects sidrev author phase description
27% 2002750:10 snort inbound policy reserved ip space traffic - bogon nets 2
23% 22466:7 snort inbound exploit netbios smb-ds ipc$ unicode share access
12% 5001684:99 bothunter egg download bothunter malware windows executable (p...
11% 2001683:3 emerging threats egg download bleeding-edge malware windows executabl...
10% 299913:1 snort inbound exploit shellcode x86 0x90 unicode noop
09% 2002749:4 snort inbound policy reserved ip space traffic - bogon nets 1
08% 292000032:99 bothunter inbound exploit bothunter exploit lsa exploit
08% 22000032:6 emerging threats inbound exploit bleeding-edge exploit lsa exploit
08% 3000003:99 bothunter egg download bothunter http-based .exe upload on bac...
07% 3000000:99 bothunter egg download bothunter http-based .exe upload on bac...

show me more!

Most Prolific BotNet Command and Control Servers and Filters

Sat May 18 12:42:37 2013

rate hits first last domain country filter
3 13 04/19 05/08 - UA  deny ip host 213.155.14.161 any log

show me more!

Most Observed Malware-Related DNS Names

Sat May 18 12:43:21 2013

embeds = number of malware binaries in which this DNS name was discovered
lookups = number of observed infections in which this DNS name was looked up
rank = 30-day importance ranking (1 to 100) of most prolific malware-related DNS names

rank lookups embeds first last country DNS
5 52 0 04/19 05/13 DE  citi-bank.ru
0 4 0 04/21 05/09 DE  moscow-advokat.ru
0 2 0 04/23 05/06 PT  siliconfireware.ru
0 1 0 05/03 05/03 US  kidos-bank.ru
0 2 0 04/22 04/22 US  fx010413.whyi.org
0 2 0 04/22 04/22 XX  gynoman.weedns.com
0 2 0 04/22 04/22 XX  cx10man.weedns.com
0 2 0 04/22 04/22 TW  g.0x20.biz
0 1 0 04/23 04/23 EU  www.egg.com
0 1 0 04/23 04/23 PL  ilo.brenz.pl

show me more!

Most Aggressively Spreading Malware Binaries

Sat May 18 12:43:30 2013

rank hits first last AV rate Binary MD5
13 04/26 05/17 0 40 41 0 7 40 36 41 2 0 40 3 0 0 0 2 0 32 0 0 37 0 0 43 5 31 0 26 25 39 0 38 4 3 38 0 0 0 0 41 40 42 35 0 0 40 40 0 37 34 2 0 3 0 40 34 29 41 0 41 41 of 32 00632e0224390d5ebdfa50efc51ed8d3

show me more!