Your Peace of Mind is our Commitment

Contact Us English Recent Articles

June Hong Kong Honeypot Report

First published: 30th June 2012

This is the sixth monthly report from West Coast Labs's honeypot in Hong Kong, providing some indication of the type and level of malware threat in Hong Kong, but it is only based on a single honeypot, so the conclusions should be treated with caution. This month, Taiwan is the top attack source, but the United States and Japan tie for second. The number of attacks has fallen slightly.

Average Time To Infect: 11 hours 6 minutes

The average time to infect is an indication of how long it would be before a vulnerable computer connected to the internet in Hong Kong became infected.

Summary

Source of Attacks

The following breaks down where these attacks have come from by use of IP geolocation.

20Taiwan
13United States
13Japan
4Singapore
3Canada
1South Korea
1France
1Sri Lanka
1Hong Kong
1Malaysia
1Indonesia
1India
1Australia
1Cambodia
1Vietnam
1Hungary
1Ukraine
1Israel
1Switzerland

Malware

Checksum (md5)This monthPrevious countDetection*
15965bb88165d1eb06851d8f076130ba410Y (w32/sdbot.otr , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
75f2a6be36973cc9f3e1cc2a821bb05b1 1Y (w32/autorun.aj.gen!eldorado , Backdoor.Win32.Floder.gmq Trojan.Win32.Jorik.IRCbot.gwe , , )
6527ce860cd40ceda4e2a81782d46c2c1 0 ***NEWY (W32/Sdbot.AEFV , Backdoor.Win32.Rbot.adqd , , )
94109e9b3f2b045350db9a5cb592b1782 6Y (w32/sdbot.otr , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
c89ff74dfe8aff4bc176106a51f051101 0 ***NEWY (w32/virut.7116 , Virus.Win32.Virut.av Net-Worm.Win32.Allaple.e , , )
bbb5034e33568e100dd3dadabb5a57e94 8Y (w32/sdbot.otr , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
f9dc3945bdd7406bd8db06a47963ec14413Y (w32/sdbot.otr , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
3f0fee7c18c9aa7763f44045c52d4be31 0 ***NEWY (w32/virut.ag , Virus.Win32.Virut.at Net-Worm.Win32.Allaple.e , , )
cb576cca04946b3d0829703d108ae2705 9Y (w32/sdbot.otr , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
f14a2e20de2c62ef68e2e68ead3773982 0 ***NEWY (w32/virut.7116 , Backdoor.Win32.Rbot.adqd , , )
3875b6257d4d21d51ec13247ee4c1cdb323Y (W32/Sdbot.AEFV W32/Malware!44f4 , Backdoor.Win32.Rbot.bni , W32Rbot!I2663.exe , )
e2a1e197bed7e57ec3094d87636797da1 0 ***NEWY (w32/virut.7116 , Backdoor.Win32.Rbot.adqd Backdoor.Win32.Rbot.adqd , , )
c5ff7232868333107fa3efe895f123612 2Y (w32/sdbot.otr , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
6add73efbe973a02cc1036568923f3771 0 ***NEWY (w32/virut.7116 , Backdoor.Win32.Rbot.adqd backdoor.win32.rbot.adqd , , )
d9d4c7a42f91d94665b65598895ffe321 0 ***NEWY (w32/rahack.a.gen!eldorado , Net-Worm.Win32.Allaple.b , , )
6e2fa9031a05b9649da062c550d14a3d1 2Y (w32/sdbot.otr , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
865915650a85e7c27cdd11850a13f86e3 7Y (w32/sdbot.otr , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
54f83c5a2d52482a8c60df30487a6e501 0 ***NEWY (, Trojan.Win32.Jorik.IRCbot.msf , , )
b43ad71209c5100b9ed71edb100415144 4N (, , , ) an older file with limited detection
b82698a30e07fc71349f06750cae26641 4Y (w32/sdbot.otr , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
809fe9b32845edf5c09b871e0e68f2272 2Y (w32/sdbot.otr , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
2016f3f8bae9ff3044c2d53a580a591c1 0 ***NEWY (w32/virut.7116 , Virus.Win32.Virut.av , , )
de7c46aca53ed3eb84295405dfc8d72b1 0 ***NEWY (w32/allaple.a.gen!eldorado , Net-Worm.Win32.Allaple.e , , )
82c7266ff4dd5ccd348a4056feb5eb051 0 ***NEWY (w32/allaple.a.gen!eldorado , Net-Worm.Win32.Allaple.a , , )
c7f024ddc8200fcb7fabd372c2804a4b1 0 ***NEWY (w32/emailworm.amv , Net-Worm.Win32.Allaple.d , , )
7d5b46b8c8a4757c2af5348ff9fbffbe1 0 ***NEWY (W32/Virut.7116 , Virus.Win32.Virut.av Net-Worm.Win32.Allaple.e , , )
b8faf7ea2cd91a318e070f224b4393121 0 ***NEWY (w32/virut.7116 , Virus.Win32.Virut.av , , )
95262bd40b2be4a9c2ef328e14286d001 0 ***NEWN (, , , )
f11d86b86efb1d523a07ec8bcb94a61e1 2N (, , , ) a new file with no detection
be26cb9839249fb9201c4df0a3d746691 0 ***NEWY (w32/virut.7116 w32/sdbot.aefv , Backdoor.Win32.Rbot.adqd , , )
74473505ef968e2f8cd764d9af12adb21 1Y (W32/Allaple.H , Net-Worm.Win32.Allaple.e , , )
ebdc5a80a546740740f86017bb4ef7b81 0 ***NEWY (, Backdoor.Win32.Azbreg.aag , , )
860100849e6962873f097d8d92e1ca331 0 ***NEWY (w32/virut.7116 , Backdoor.Win32.Rbot.adqd , , )
6e9924223fb797722cf654f80640ec432 0 ***NEWY (, HEUR:Trojan.Win32.Generic , , )
a0f7bc4600b926cc466c3f13284820881 1Y (w32/virut.7116 , Virus.Win32.Virut.av Net-Worm.Win32.Allaple.e , , )
3c3011089708c7a49346f648f1e793841 0 ***NEWY (w32/trojan2.kexn , Trojan-Spy.Win32.Agent.bmxb , , )
cb2ef50637b9fa9c51d1d6d09a3008991 0 ***NEWY (w32/genbl.cb2ef506!olympus , HEUR:Trojan.Win32.Generic , , )
3dd2c2b97fc8824ebc7c770752899bed3 0 ***NEWY (, Trojan.Win32.Jorik.Poebot.eq , , )
c0276991baff7a50b6f774d7055c440b1 0 ***NEWY (W32/Allaple.H , Net-Worm.Win32.Allaple.e Virus.Win32.Virut.n , , )
2c7ebd64fccf9e0414ae24190839575c1 1N (, , , ) a recent file with no detection

One of these files has been in the Wildlist.

Note:

The parameter 'Detection' here relates to whether one or more scanners was able to associate a name with this checksum.


More Information