Welcome to the Cyber-TA
Daily Malware Binary DIGEST Summary Page



16 May 2008

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.



Packed
MD5
UnPacket
MD5
Victim
OS
AntiVirus
Hit-Cnt
First
Encounter
Last
Encounter
Freq
Cnt
Behavioral
Clusters
Unpacked
Egg.asm
Packer
Fingerprint
API
Resolution
String
Cnt
Syscall
Trace
b6d843862c
NEW
none[4] WinXP 27 of 30 14:46:45 14:46:45 1 none none:none
none|none none trace
1e5df7ba74
[Firefox:12 hits: 03-24 to 05-12]
a5331b711f [0] WinXP 31 of 32 13:39:03 13:39:14 2 none ASM:Graph
PolyEnE| 99% lines=68 trace
4842a5d70d
NEW
none[4] Win2K-f 27 of 31 09:59:50 09:59:50 1 none none:none
none|none none trace
4b9bdc4835
NEW
none[4] WinXP 28 of 32 11:20:12 11:20:12 1 none none:none
none|none none trace
5e1a836af5
NEW
none[4] Win2K-f 0 of 0 09:09:00 09:09:00 1 none none:none
FSG| none trace
32b7295760
[Firefox: 2 hits: 05-04 to 05-07]
443ee2d2f0 [0] Win2K-f 28 of 32 04:47:38 04:47:38 1 none ASM:Graph
TXT2COM| 0% lines=11 trace
f0e02bee5f
[Firefox: 3 hits: 04-27 to 05-15]
none[4] Win2K-f 22 of 31 07:37:06 09:35:59 2 none none:none
none|none none trace
60ccb46de8
NEW
60ccb46de8 [1] Win2K-f 5 of 32 22:34:14 22:34:14 1 none ASM:Graph
StarForce| 44% lines=88 trace
27cff6b597
NEW
none[4] Win2K-f 0 of 0 05:57:48 05:57:48 1 none none:none
none|none none trace
76b4ab852e
[Firefox:48 hits: 04-29 to 05-15]
none[4] Win2K-f 12 of 30 11:52:49 11:52:49 1 none none:none
none|none none trace
15e3c1deb8
NEW
none[4] WinXP 0 of 0 00:55:29 00:55:29 1 none none:none
none|none none trace
93282471f7
[Firefox:16 hits: 04-28 to 05-12]
95951dee58 [0] Win2K-f 19 of 30 02:55:48 22:10:06 2 none ASM:Graph
ASProtect| 0% lines=0 trace
af98fe0c94
[Firefox:63 hits: 04-27 to 05-15]
480d076a0a [0] WinXP 20 of 31 01:31:19 09:13:31 3 none ASM:Graph
ASProtect| 57% lines=422
embedded dns
trace
7da73663ea
NEW
none[4] Win2K-f 30 of 32 15:12:16 15:12:16 1 none none:none
FSG| none trace
52338e9fc1
NEW
none[4] Win2K-f 0 of 0 09:52:54 09:52:54 1 none none:none
none|none none trace
5c151befe0
NEW
none[4] Win2K-f 0 of 0 10:13:01 10:13:01 1 none none:none
none|none none trace
a12cab51ef
[Firefox:1016 hits: 05-01 to 05-15]
40f7f463c4 [0] WinXP 29 of 29 16:28:49 16:28:49 1 none ASM:Graph
ASPack| 54% lines=281
embedded dns
trace
16044bb1ff
NEW
none[4] Win2K-f 0 of 0 11:03:20 11:03:20 1 none none:none
none|none none trace
a4a30636e5
NEW
none[4] Win2K-f 30 of 32 17:22:23 17:22:23 1 none none:none
FSG| none trace
4e9457ee8b
NEW
none[4] WinXP 0 of 0 10:35:21 10:35:21 1 none none:none
StarForce| none trace
54df1dbf7e
NEW
54df1dbf7e [1] Win2K-f 21 of 32 05:02:15 05:02:15 1 none ASM:Graph
StarForce| 50% lines=6 trace
a2a036466a
[Firefox:196 hits: 05-05 to 05-15]
none[4] Win2K-f
WinXP
14 of 32 00:56:51 18:22:27 9 none none:none
none|none none trace
9a331ca0d6
NEW
none[4] WinXP 31 of 32 13:28:33 13:28:33 1 none none:none
PolyEnE| none trace
53123fadcc
[Firefox:46 hits: 01-26 to 05-15]
none[4] WinXP 13 of 32 00:17:05 18:15:59 2 none none:none
none|none none trace
639a247ece
[Firefox:30 hits: 04-28 to 05-14]
29d53eec72 [0] WinXP 10 of 32 13:16:26 13:16:26 1 none ASM:Graph
StarForce| 77% lines=132 trace
54df1dbf7e
NEW
c0e4027c8e
NEW
54df1dbf7e [1]
none [4]
Win2K-f 29 of 33 05:02:15 05:02:15 1 none ASM:Graph
none:none
StarForce|
ASProtect|
lines=6
none
trace
trace
7fdfe363d5
[Firefox:2617 hits: 12-31 to 05-15]
10862ea8b8 [0] Win2K-f
WinXP
25 of 28 09:25:56 20:44:26 3 none ASM:Graph
FSG| 95% lines=1933
embedded dns
trace
ccf7ce9bb5
[Firefox: 2 hits: 05-01 to 05-15]
none[4] WinXP 12 of 30 23:52:19 23:52:19 1 none none:none
none|none none trace
7f60162c2c
[Firefox:1286 hits: 12-31 to 05-15]
1aad8e4632 [0] WinXP 25 of 25 17:01:41 17:01:41 1 none ASM:Graph
PolyEnE| 100% lines=93
embedded dns
trace
94a6d556e1
NEW
none[4] Win2K-f 29 of 32 01:09:40 01:09:40 1 none none:none
none|none none trace
bc3bc01a41
NEW
none[4] Win2K-f 0 of 0 19:59:43 19:59:43 1 none none:none
none|none none trace
831f4ee0a7
[Firefox:588 hits: 07-11 to 05-15]
eb7546c600 [0] WinXP 29 of 29 01:41:51 19:33:35 2 none ASM:Graph
none|none 100% lines=61 trace
5f78ff609d
[Firefox:1229 hits: 04-27 to 05-15]
d4a06bdc3a [0] Win2K-f
WinXP
21 of 32 00:19:39 23:02:34 41 none ASM:Graph
none|none 46% lines=4 trace
3ae357d17b
[Firefox:704 hits: 05-01 to 05-13]
462a7be171 [0] WinXP 29 of 29 04:51:56 23:00:56 2 none ASM:Graph
PolyEnE| 99% lines=73 trace
4620861e2d
[Firefox:13 hits: 04-27 to 05-10]
none[4] Win2K-f 11 of 31 12:35:32 12:35:32 1 none none:none
StarForce| none trace
7d99b0e910
[Firefox:2974 hits: 12-31 to 05-15]
7a70e1b592 [0] WinXP 26 of 28 13:31:10 23:42:43 3 none ASM:Graph
PolyEnE| 99% lines=68 trace
e1b5e07fac
NEW
none[4] Win2K-f 27 of 31 05:11:11 05:11:11 1 none none:none
none|none none trace
7e28dac8de
[Firefox:18 hits: 04-27 to 05-15]
none[4] Win2K-f
WinXP
18 of 32 16:13:57 17:09:54 2 none none:none
none|none none trace
dc8e1c63cd
[Firefox:87 hits: 12-27 to 05-15]
e0eb8646ee [0] WinXP
Win2K-f
22 of 32 06:21:30 09:18:58 2 none ASM:Graph
none|none 62% lines=601
embedded dns
trace
c1f12e0109
[Firefox:18 hits: 04-28 to 05-15]
none[4] WinXP 21 of 31 21:12:46 21:12:46 1 none none:none
none|none none trace
d464763855
NEW
none[4] Win2K-f 0 of 0 11:12:59 11:12:59 1 none none:none
ASProtect| none trace
5019ff53bf
NEW
none[4] Win2K-f 0 of 0 07:43:28 07:43:28 1 none none:none
none|none none trace
cb89ccfe52
[Firefox:10 hits: 04-29 to 05-15]
881f6fa4b7 [0] WinXP 20 of 31 10:57:21 10:57:21 1 none ASM:Graph
TXT2COM| 59% lines=406
embedded dns
trace
7947cc5c5b
[Firefox: 3 hits: 03-25 to 04-18]
1a99881187 [0] WinXP 30 of 32 12:06:24 12:06:24 1 none ASM:Graph
PolyEnE| 100% lines=93
embedded dns
trace
e5d062be59
[Firefox: 6 hits: 12-28 to 05-15]
none[4] Win2K-f 11 of 32 00:28:36 00:28:36 1 none none:none
ASPack| none trace
fd0bf48a75
[Firefox:10 hits: 04-28 to 05-14]
none[3] WinXP 20 of 32 20:39:21 20:39:21 1 none none:none
ASProtect| none trace
8f367186c3
[Firefox:76 hits: 12-27 to 05-15]
01a06977c4 [0] Win2K-f 14 of 32 00:56:52 00:56:52 1 none ASM:Graph
TXT2COM| 0% lines=0 trace