Your Peace of Mind is our Commitment

Contact Us English Recent Articles

July Hong Kong Honeypot Report

First published: 28th July 2012

This is the seventh monthly report from West Coast Labs's honeypot in Hong Kong, providing some indication of the type and level of malware threat in Hong Kong, but it is only based on a single honeypot, so the conclusions should be treated with caution. The number of attacks this month has jumped up sharply, with most coming from Finland.

Average Time To Infect: 2 hours 44 minutes

The average time to infect is an indication of how long it would be before a vulnerable computer connected to the internet in Hong Kong became infected.

Summary

Source of Attacks

The following breaks down where these attacks have come from by use of IP geolocation.

230Finland
7Taiwan
6Japan
5United_States
2Kazakstan
2Brazil
2Spain
2Vietnam
2Canada
1Indonesia
1Singapore
1Australia
1Malaysia
1Hong_Kong

Malware

Checksum (md5)This monthPrevious countDetection*
e42f4d2d96bea46838e780b2b40cd54b10 ***NEWY (w32/sdbot.aefv W32/Backdoor2.AJVM , Backdoor.Win32.Rbot.bni , , )
5857bdf42f797445cfa3b09ed7c77f6b10 ***NEWY (w32/allaple.a.gen!eldorado , Net-Worm.Win32.Allaple.e , , )
3dd2c2b97fc8824ebc7c770752899bed13Y (w32/genbl.3dd2c2b9!olympus , Trojan.Win32.Jorik.Poebot.eq , , )
94109e9b3f2b045350db9a5cb592b17848Y (w32/sdbot.otr , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
382fdcff132b058cfe50065b84fd8a4c10 ***NEWY (w32/virut.7116 W32/Sdbot.AEFV , Backdoor.Win32.Rbot.adqd , , )
0ab0fa91709a5fb0b48b9b10e51b16d110 ***NEWY (w32/virut.7116 , Backdoor.Win32.Rbot.adqd , , )
961dcb5a7c03b7f9acceab3e7e66c13412Y (w32/virut.7116 , Virus.Win32.Virut.av Net-Worm.Win32.Allaple.e , , )
2f26fd2edab6f916d686604db20264f210 ***NEWY (W32/RAHack.A.gen!Eldorado , Net-Worm.Win32.Allaple.b , , )
865915650a85e7c27cdd11850a13f86e211Y (w32/sdbot.otr , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
5db68cd45f0c95c9cba56ae6a2bacc6b10 ***NEWY (w32/virut.7116 , Backdoor.Win32.Rbot.adqd , , )
3875b6257d4d21d51ec13247ee4c1cdb226Y (W32/Sdbot.AEFV W32/Malware!44f4 , Backdoor.Win32.Rbot.bni , W32Rbot!I2663.exe , )
4711e0fccd0565f1826fe10909f1698e10 ***NEWY (W32/RAHack.A.gen!Eldorado , Net-Worm.Win32.Allaple.b , , )
9987b5cbff8f6942a29b707d1a549b772300 ***NEWN ( , , , ) * not a new file but with limited detection
65dfcfe7988418e7b7eb084c96051b9210 ***NEWY (w32/genbl.65dfcfe7!olympus , Backdoor.Win32.Azbreg.awc , , )
4d6c4cc06bacbab059ba52607530d1ec10 ***NEWY (w32/genbl.4d6c4cc0!olympus , HEUR:Backdoor.Win32.Generic , , )
5fe9bf522fb0160b50e4737bd9e09fe710 ***NEWY (w32/genbl.5fe9bf52!olympus , Backdoor.Win32.Azbreg.bch , , )
bbb5034e33568e100dd3dadabb5a57e9212Y (w32/sdbot.otr , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
4ed217391b897fc2d46ec9ce8af282cf13Y (W32/Virut.AG , Backdoor.Win32.Rbot.adqd , , )
6e2fa9031a05b9649da062c550d14a3d13Y (w32/sdbot.otr , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
32610374d3922a1ae50fada7a684931e10 ***NEWY (W32/Allaple.C , Net-Worm.Win32.Allaple.b , , )
9cf15714790fd07ad2955dfef7255af010 ***NEWY (W32/Emailworm.AMX , Net-Worm.Win32.Allaple.b , , )
15965bb88165d1eb06851d8f076130ba114Y (w32/sdbot.otr , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
4dc508b15c0b748ff16e79088a1179ea10 ***NEWY (W32/RAHack.A.gen!Eldorado, Net-Worm.Win32.Allaple.b , , )
cb576cca04946b3d0829703d108ae270114Y (w32/sdbot.otr , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
33fdb683c37fe3d87a403a5db0cbe82111Y (w32/sdbot.otr , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
df630013dccf7c7741a924e9353005e210 ***NEWY (W32/Virut.AG , Backdoor.Win32.Rbot.adqd , , )
85a786387d1511bececc87843631ddc210 ***NEWY (W32/Trojan.MEX , Backdoor.Win32.Rbot.bni , , )
b0599b847e5df4109e7a0e4ad883e00e10 ***NEWY (W32/Virut.AG , Net-Worm.Win32.Allaple.e Virus.Win32.Virut.at , , )

One of these files has been in the Wildlist.

Note:

The parameter 'Detection' here relates to whether one or more scanners was able to associate a name with this checksum.


More Information