NAME ==== Zotob.E + WORM_ZOTOB.E (TrendMicro) + W32.Zotob.E (Symantec) EXPERIMENTAL TYPE ================= Retrieval Behavior - includes retrieval packets only. EXPERIMENTAL ENVIRONMENT ======================== 131.113.1.1 131.113.1.2 +-----------+ +-----+-----+ | Infected | | Targeted | | PC | | PC | | (*1)(*2) | | | +-----+-----+ +-----+-----+ | | ------+----------------------------+------ 131.113.1.0/31 (*1) Windows XP on VMware (*2) Default Route = 131.113.1.2 PCAP SUMMARY ============ Total: 50945 START: 1 0.000000 ----------------- 445/TCP;: 29343 1 0.000000 131.113.1.1 150.212.8.169 TCP 1039 > 445 [SYN] Seq=0 Ack=0 Win=16384 Len=0 MSS=1460 ----------------- 8080/TCP;: 1 80 1.195901 131.113.1.1 72.20.27.115 TCP 1125 > 8080 [SYN] Seq=0 Ack=0 Win=16384 Len=0 MSS=1460