Answers
Answers
Answers
---------------------------------------------------------------------------------------------------------------------------------------
Total IP's: 3
91.121.100.60
192.168.45.2
192.168.45.130
---------------------------------------------------------------------------------------------------------------------------------------
IP: 91.121.100.60
IP address: 91.121.100.60
192.168.45.2
192.168.45.130
---------------------------------------------------------------------------------------------------------------------------------------
On 91.121.100.60 a TCP port 5540 is running (as per SANS) the service is sdreport
On 192.168.45.130 a TCP port 1038 and UDP port 1037 is running and the service is Message Tracking
Query Protocol (MTQP) (as per SANS)
---------------------------------------------------------------------------------------------------------------------------------------
Question 4. Please explain the attack in detail and what you think is going on in this PCAP file:
From a quick glance on PCAP file we can find Command and Control communication between client
and server via IRC using port tcp/1038 and C&C server tcp/5540
Message:
PRIVMSG ##verga## :.4.{. USB.4 }.. Injected Virus into .4.autorun.inf.. on drive.4. D:
NICK pLagUe{USA}64007
:sex.accesox.net NOTICE AUTH :*** Couldn't resolve your hostname; using your IP address instead
PING :56EF9DAC
PONG 56EF9DAC
:sex.accesox.net 003 pLagUe{USA}64007 :This server was created ven mar 25 2011 at 02:34:51 CET
:sex.accesox.net 005 pLagUe{USA}64007 MAXTARGETS=20 WALLCHOPS WATCH=128 WATCHOPTS=A SILENCE=15 MODES=12 CHANTYPES=#
PREFIX=(qaohv)~&@%+ CHANMODES=beI,kfL,lj,psmntirRcOAQKVCuzNSMTGZ NETWORK=AccesoX CASEMAPPING=ascii EXTBAN=~,qjncrR
ELIST=MNUCT :are supported by this server
:sex.accesox.net 005 pLagUe{USA}64007 STATUSMSG=~&@%+ EXCEPTS INVEX :are supported by this server
JOIN ##verga##
JOIN ##verga##
:sex.accesox.net 372 pLagUe{USA}64007 :- This is the short MOTD. To view the complete MOTD type /motd
:[email protected] NOTICE pLagUe{USA}64007 :[.Random News. - Oct 14 2010] Registren sus nick de nuevo ... gracias.
JOIN ##verga##
JOIN ##verga##
JOIN ##verga##
JOIN ##verga##
PRIVMSG ##verga## :.4.{. USB.4 }.. Injected Virus into .4.autorun.inf.. on drive.4. D:
PING :sex.accesox.net
PONG sex.accesox.net
---------------------------------------------------------------------------------------------------------------------------------------