Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


PUBLIC PAGE


<Click here: to download BotHunter>

01 July 2008
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
00:07:00 Win2K-f 118.236.169.2 (-):
.
n/a US:chat-shqip.org
US:w3bs.chat-shqip.org
US:69.247.147.113:12351
US:69.247.147.113:13001
445 pcap raw alerts
ruleset
ftp
27 lines
Yeah : 1.3
profile
none summary
tarball
23 of 33 3b05a7e449
[Firefox: 2 hits: 06-29 to 06-30]
none [none] none:none
none|none none none
00:10:00 WinXP 217.218.253.231 (-):
MARKAZI TELECOMUNICATION COMPANY,
IR. (100Mbps)
n/a   445 pcap raw alerts
ruleset
other
9 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
00:14:00 Win2K-f 86.138.220.245 (BTCENTRALPLUS.COM):
BT-CENTRAL-PLUS,
LONDON, ENGLAND, UK.
n/a HK:proxim.ircgalaxy.pl 445 pcap raw alerts
ruleset
ftp
21 lines
Yeah : 1.3
profile
none summary
tarball
30 of 33 c789e64d64
NEW
none [none] none:none
none|none none none
T:00:16:00 Win2K-f 60.38.129.95 (OCN.NE.JP):
OPEN COMPUTER NETWORK,
JP.
n/a   445 pcap raw alerts
ruleset
ftp
28 lines
Yeah : 1.3
profile
none summary
tarball
30 of 33 1f7c55af5a
[Firefox: 2 hits: 06-27 to 06-28]
none [none] none:none
none|none none none
00:20:00 WinXP 217.237.94.111 (T-IPCONNECT.DE):
DEUTSCHE TELEKOM AG,
TRIER, RHEINLAND-PFALZ, DE.
n/a US:chat-shqip.org
US:w3bs.chat-shqip.org
US:69.247.147.113:12351
US:69.247.147.113:13001
445 pcap raw alerts
ruleset
ftp
20 lines
Yeah : 1.3
profile
none summary
tarball
20 of 33 17739a55ad
[Firefox:165 hits: 06-27 to 06-30]
none [none] none:none
none|none none none
00:28:00 WinXP 78.8.21.75 (NET.PL):
DIALOG,
WROCLAW, DOLNOSLASKIE, PL.
n/a US:chat-shqip.org
US:w3bs.chat-shqip.org
US:69.247.147.113:12351
US:69.247.147.113:13001
445 pcap raw alerts
ruleset
ftp
26 lines
Yeah : 1.3
profile
none summary
tarball
20 of 33 17739a55ad
[Firefox:165 hits: 06-27 to 06-30]
none [none] none:none
none|none none none
00:30:00 Win2K-f 91.66.67.182 (SUPERKABEL.DE):
KABEL DEUTSCHLAND BREITBAND SERVICE GMBH,
DE.
n/a   445 pcap raw alerts
ruleset
ftp
27 lines
Yeah : 1.3
profile
none summary
tarball
31 of 33 f0661a9806
NEW
none [none] none:none
none|none none none
00:35:00 WinXP 121.115.108.58 (PLALA.OR.JP):
PLALA NETWORKS INC,
JP.
n/a US:chat-shqip.org
US:w3bs.chat-shqip.org
US:69.247.147.113:12351
US:69.247.147.113:13001
445 pcap raw alerts
ruleset
ftp
27 lines
Yeah : 1.3
profile
none summary
tarball
32 of 33 0d4eb498e6
NEW
none [none] none:none
none|none none none
T:00:37:00 WinXP 119.11.112.35 (-):
.
n/a US:chat-shqip.org
US:w3bs.chat-shqip.org
US:69.247.147.113:12351
US:69.247.147.113:13001
445 pcap raw alerts
ruleset
ftp
21 lines
Yeah : 1.3
profile
none summary
tarball
13 of 33 a896c13b26
NEW
none [none] none:none
none|none none none
T:00:44:00 WinXP 218.210.225.206 (SPARQNET.NET):
NEW CENTURY INFOCOMM TECH CO. LTD,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a US:microsoft.com
US:download.microsoft.com
135 pcap raw alerts
ruleset
http
77 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
0 of 33
53bfe15e91
[Firefox:301 hits: 06-17 to 06-30]
73f1082158
[Firefox:128 hits: 06-18 to 06-30]
e07c29c4ae
[Firefox:46 hits: 06-19 to 06-30]
none[4]
73f1082158[1]
e07c29c4ae[1]
e07c29c4ae[1]
none:none
ASM:Graph
ASM:Graph
tElock|
Armadillo|
FSG|
none
lines=81
lines=92
trace
trace
trace
00:50:00 Win2K-f 77.198.205.21 (GAOLAND.NET):
DYNAMIC POOLS,
FR.
n/a US:chat-shqip.org
US:w3bs.chat-shqip.org
US:69.247.147.113:12351
US:69.247.147.113:13001
445 pcap raw alerts
ruleset
ftp
26 lines
Yeah : 1.3
profile
none summary
tarball
8 of 33 646da52c64
NEW
none [none] none:none
none|none none none
00:50:00 Win2K-f 87.4.159.128 (RETAIL.TELECOMITALIA.IT):
TELECOM ITALIA S.P.A. TIN EASY LITE,
MILANO, LOMBARDIA, IT.
n/a HK:proxim.ircgalaxy.pl 445 pcap raw alerts
ruleset
ftp
26 lines
Yeah : 1.3
profile
none summary
tarball
30 of 33 5f160b61fa
NEW
none [none] none:none
none|none none none
T:00:51:00 Win2K-f 91.141.109.12 (I-ONE.AT):
NETWORK OF ONE GMBH,
VIENNA, WIEN, AT.
n/a US:chat-shqip.org
US:w3bs.chat-shqip.org
US:69.247.147.113:12351
US:69.247.147.113:13001
445 pcap raw alerts
ruleset
ftp
25 lines
Yeah : 1.3
profile
none summary
tarball
10 of 33 d2c26e07fd
[Firefox:109 hits: 06-27 to 06-30]
none [none] none:none
none|none none none
00:56:00 Win2K-f 122.221.13.92 (UCOM.NE.JP):
UCOM CORP,
JP.
n/a US:chat-shqip.org
US:w3bs.chat-shqip.org
US:69.247.147.113:12351
US:69.247.147.113:13001
445 pcap raw alerts
ruleset
ftp
27 lines
Yeah : 1.3
profile
none summary
tarball
21 of 33 ffbcbff716
NEW
none [none] none:none
none|none none none
T:00:56:00 Win2K-f 221.113.242.64 (OCN.NE.JP):
OPEN COMPUTER NETWORK,
OSAKA, OSAKA, JP.
n/a   445 pcap raw alerts
ruleset
ftp
28 lines
Yeah : 1.3
profile
none summary
tarball
26 of 33 ca15c09536
[Firefox:136 hits: 06-27 to 06-30]
none [none] none:none
none|none none none
T:00:57:00 WinXP 98.30.146.23 (-):
.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 3ae357d17b
[Firefox:727 hits: 05-01 to 06-29]
462a7be171 [0] ASM:Graph
PolyEnE| lines=73 trace
01:00:00 WinXP 221.126.128.32 (HUTCHCITY.COM):
HUTCHISON GLOBAL COMMUNICATIONS,
HONG KONG, HONG KONG (SAR), HK.
n/a US:chat-shqip.org
US:w3bs.chat-shqip.org
US:69.247.147.113:12351
US:69.247.147.113:13001
445 pcap raw alerts
ruleset
ftp
26 lines
Yeah : 1.3
profile
none summary
tarball
10 of 33 d2c26e07fd
[Firefox:109 hits: 06-27 to 06-30]
none [none] none:none
none|none none none
01:06:00 WinXP 85.180.9.240 (ALICEDSL.DE):
HANSENET-ADSL,
STUTTGART, BADEN-WURTTEMBERG, DE. (DSL)
n/a US:chat-shqip.org
US:w3bs.chat-shqip.org
US:69.247.147.113:12351
US:69.247.147.113:13001
445 pcap raw alerts
ruleset
ftp
26 lines
Yeah : 1.3
profile
none summary
tarball
10 of 33 d2c26e07fd
[Firefox:109 hits: 06-27 to 06-30]
none [none] none:none
none|none none none
T:01:11:00 Win2K-f 123.217.214.106 (OCN.NE.JP):
OPEN COMPUTER NETWORK,
JP.
n/a US:chat-shqip.org
US:w3bs.chat-shqip.org
US:69.247.147.113:12351
US:69.247.147.113:13001
445 pcap raw alerts
ruleset
ftp
27 lines
Yeah : 1.3
profile
none summary
tarball
13 of 33 16df44dfe9
NEW
none [none] none:none
none|none none none
01:18:00 Win2K-f 82.234.83.146 (PROXAD.NET):
PROXAD / FREE SAS,
TOULOUSE, MIDI-PYRENEES, FR.
n/a HK:proxim.ircgalaxy.pl 445 pcap raw alerts
ruleset
ftp
26 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32 00710a2ffa
[Firefox: 2 hits: 06-28 to 06-30]
none [none] none:none
none|none none none
T:01:20:00 Win2K-f 119.11.101.195 (-):
.
n/a   445 pcap raw alerts
ruleset
ftp
19 lines
Yeah : 1.3
profile
none summary
tarball
30 of 33 c4fe07012a
[Firefox: 2 hits: 06-30 to 06-30]
none [none] none:none
none|none none none
01:23:00 Win2K-f 125.192.176.254 (MESH.AD.JP):
NEC CORPORATION,
JP.
n/a US:chat-shqip.org
US:w3bs.chat-shqip.org
US:69.247.147.113:12351
US:69.247.147.113:13001
445 pcap raw alerts
ruleset
ftp
26 lines
Yeah : 1.3
profile
none summary
tarball
10 of 33 d2c26e07fd
[Firefox:109 hits: 06-27 to 06-30]
none [none] none:none
none|none none none
01:30:00 Win2K-f 222.147.239.113 (OCN.NE.JP):
OPEN COMPUTER NETWORK,
JP.
n/a US:chat-shqip.org
US:w3bs.chat-shqip.org
US:69.247.147.113:12351
US:69.247.147.113:13001
445 pcap raw alerts
ruleset
ftp
26 lines
Yeah : 1.3
profile
none summary
tarball
12 of 33 a96d6f6d31
[Firefox: 4 hits: 06-28 to 06-30]
none [none] none:none
none|none none none
T:01:31:00 WinXP 81.181.16.175 (-):
GENIUS NETWORK SYSTEM SRL,
GALATI, GALATI, RO. (DSL)
n/a HK:proxim.ircgalaxy.pl
US:chat-shqip.org
US:w3bs.chat-shqip.org
US:69.247.147.113:12351
US:69.247.147.113:13001
445 pcap raw alerts
ruleset
ftp
28 lines
Yeah : 1.3
profile
none summary
tarball
30 of 33 54f0165aa3
NEW
none [none] none:none
none|none none none
01:37:00 Win2K-f 85.181.190.0 (ALICEDSL.DE):
HANSENET-ADSL,
DE. (DSL)
n/a US:chat-shqip.org
US:w3bs.chat-shqip.org
US:69.247.147.113:12351
US:69.247.147.113:13001
445 pcap raw alerts
ruleset
ftp
28 lines
Yeah : 1.3
profile
none summary
tarball
10 of 33 d2c26e07fd
[Firefox:109 hits: 06-27 to 06-30]
none [none] none:none
none|none none none
T:01:38:00 Win2K-f 217.202.74.139 (-):
TELECOM ITALIA MOBILE,
IT.
n/a HK:proxim.ircgalaxy.pl 445 pcap raw alerts
ruleset
ftp
24 lines
Yeah : 1.3
profile
none summary
tarball
30 of 33 ff4b083ee6
NEW
none [none] none:none
none|none none none
01:39:00 WinXP 122.135.154.231 (MESH.AD.JP):
NEC BIGLOBE LTD,
TOKYO, TOKYO, JP.