Your Peace of Mind is our Commitment

Contact Us English Recent Articles

October Hong Kong Honeypot Report

First published: 31st October 2012

This is the tenth monthly report from West Coast Labs's honeypot in Hong Kong, providing some indication of the type and level of malware threat in Hong Kong, but it is only based on a single honeypot, so the conclusions should be treated with caution. The number of attacks this month has fallen slightly from last month's figure

Average Time To Infect: 32 hours 21 minutes

The average time to infect is an indication of how long it would be before a vulnerable computer connected to the internet in Hong Kong became infected.

Summary

Source of Attacks

The following breaks down where these attacks have come from by use of IP geolocation.

6Japan
2Taiwan
2United States
2Hong Kong
1Israel
1France
1Romania
1Austria
1Vietnam
1Philippines
1Russia
1Canada
1Poland
1Portugal
1Malaysia

Malware

Checksum (md5)This monthPrevious countDetection*
0e8f41329cb1bbe2230c83564fe16c0110 ***NEWY (w32/emailworm.amv , Net-Worm.Win32.Allaple.d , , )
bbb5034e33568e100dd3dadabb5a57e920 ***NEWY (W32/Sdbot.OTR , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
87247ad165eddf91ee2cd8b154c72abd20 ***NEWN (, , , ) an old file with little detection - probably a PUA
6e2fa9031a05b9649da062c550d14a3d10 ***NEWY (W32/Sdbot.OTR , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , WL-dc1ca4287875927725689f45b31ba338-0 , )
15965bb88165d1eb06851d8f076130ba10 ***NEWY (W32/Sdbot.OTR , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
f9dc3945bdd7406bd8db06a47963ec1410 ***NEWY (W32/Sdbot.OTR , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
c2e9a9884a40f242bac1d7d9fe39056d10 ***NEWY (w32/virut.7116 , Backdoor.Win32.Rbot.adqd , , )
04721e2041b088a0a1a175cbeb44febe10 ***NEWY (w32/allaple.a.gen!eldorado , Net-Worm.Win32.Allaple.a , , )
96843f69e602e96a04c5557ca96243f610 ***NEWY (w32/virut.7116 , Virus.Win32.Virut.av Net-Worm.Win32.Allaple.e , , )
94109e9b3f2b045350db9a5cb592b17810 ***NEWY (W32/Sdbot.OTR , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
4d4c2729b8aa56e70eaf9ef84e9d5d3d10 ***NEWY (w32/agent.ix.gen!eldorado w32/genbl.4d4c2729!olympus , Trojan-Spy.Win32.Agent.bmxb , , )
3875b6257d4d21d51ec13247ee4c1cdb20 ***NEWY (W32/Sdbot.AEFV W32/Malware!44f4 , Backdoor.Win32.Rbot.bni , W32Rbot!I2663.exe , )
9e209d037787e76d9c57e263ff86f33510 ***NEWY (w32/rahack.a.gen!eldorado , Net-Worm.Win32.Allaple.b , , )
33959bb2c48363ddd3637ea78c048b6c10 ***NEWY (w32/sdbot.aefv , Virus.Win32.Suspic.gen Virus.Win32.Virut.n Type_Win32 , , )
3be3a929774b8dc0ac56065a0c716e8710 ***NEWY (w32/genbl.3be3a929!olympus , Backdoor.Win32.Azbreg.hik , , )
95262bd40b2be4a9c2ef328e14286d0010 ***NEWN (, , , ) an old file with no detections
27e0cb71d5229bf0290590dc9eef70ba10 ***NEWY (w32/allaple.h , trojan.win32.genome.rioo Net-Worm.Win32.Allaple.e , , )
aab0b68982d2babcf3656cd686b3ac9f10 ***NEWY (w32/trojan2.kexn , Trojan-Spy.Win32.Agent.bmxb , , )
14c31fa0f1fdeee959074fda2fdb78fc10 ***NEWY (w32/emailworm.amt , Net-Worm.Win32.Allaple.a , , )
fbafdef020622e5c62c7a3be49faaa7910 ***NEWY (w32/genbl.fbafdef0!olympus , Worm.Win32.Hamweq.hz , , )

Two of these files has been in the Wildlist.

Note:

The parameter 'Detection' here relates to whether one or more scanners was able to associate a name with this checksum.


More Information