Your Peace of Mind is our Commitment

Contact Us English Recent Articles

May Hong Kong honeypot Report

First published: 31st May 2013

This is the seventeenth monthly report from West Coast Labs's honeypot in Hong Kong, providing some indication of the type and level of malware threat in Hong Kong, but it is only based on a single honeypot, so the conclusions should be treated with caution. The number of attacks remains at a low level.

Average Time To Infect: 51 hours 26 minutes

The average time to infect is an indication of how long it would be before a vulnerable computer connected to the internet in Hong Kong became infected.

Summary

Source of Attacks

The following breaks down where these attacks have come from by use of IP geolocation.

3Taiwan
3Japan
2Vietnam
1Spain
1China
1Luxembourg
1Germany
1Bulgaria
1Canada

Malware

Checksum (md5)This monthPrevious countDetection*
022aeb126d2d80e683f7f2a3ee9208741 0 ***NEWY (w32/agent.ix.gen!eldorado w32/genbl.022aeb12!olympus , Trojan-Spy.Win32.Agent.bmxb , , )
8454eb77939c3f3d8c2b61dc6d6e5e191 0 ***NEWY (w32/allaple.c , Net-Worm.Win32.Allaple.b , , )
954919ad5661e1b44803092360ac5d821 2Y (W32/Trojan.MEX , Backdoor.Win32.Rbot.bni Virus.Win32.Virut.n , , )
f9dc3945bdd7406bd8db06a47963ec14227Y (W32/Sdbot.OTR , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
c1989130056c32fa305e3de57f6f40f11 1Y (W32/Trojan.MEX , Backdoor.Win32.Rbot.bni Virus.Win32.Virut.n , , )
1f8a826b2ae94daa78f6542ad4ef173b1 6Y (w32/backdoor.zzr W32/Trojan5.DCW , Backdoor.Win32.Rbot.aftu Backdoor.Win32.Rbot.phv Backdoor.Win32.Rbot.ion , , )
94109e9b3f2b045350db9a5cb592b178114Y (w32/sdbot.otr , Net-Worm.Win32.Kolab.aefe Backdoor.Win32.Rbot.bqj , , )
f36fc8d2df690530b2032a4bad5ac2851 0 ***NEWN (, , , ) new file
14a09a48ad23fe0ea5a180bee8cb750a118Y (w32/backdoor.zzr W32/Trojan5.DCW , Backdoor.Win32.Rbot.aftu Backdoor.Win32.Rbot.bqj Backdoor.Win32.DsBot.vd , , )
bb39f29fad85db12d9cf7195da0e1bfe1 8Y (w32/backdoor.zzr W32/Trojan5.DCW , Backdoor.Win32.Rbot.aftu Net-Worm.Win32.Kolabc.eia , , )
052494f76e3a1f7b998c56e07062f5352 0 ***NEWY (w32/genbl.052494f7!olympus , Trojan-Spy.Win32.Zbot.lrjw , , )
3875b6257d4d21d51ec13247ee4c1cdb146Y (W32/Sdbot.AEFV W32/Malware!44f4 , Backdoor.Win32.Rbot.bni , W32Rbot!I2663.exe , )

Note:

The parameter 'Detection' here relates to whether one or more scanners was able to associate a name with this checksum.


More Information