Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

31 May 2008
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
T:00:20:00 WinXP 41.233.227.118 (TEDATA.NET):
PROVIDER LOCAL REGISTRY,
EG.
n/a CN:hail2.dns2go.com
US:209.63.232.19:8885
445 pcap raw alerts
ruleset
ftp
irc
23 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:51 hits: 05-29 to 06-02]
51c1525417 [0] none:none
Obsidium| none trace
01:16:00 WinXP 79.138.208.158 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a CN:hail2.dns2go.com
US:209.63.232.19:8885
445 pcap raw alerts
ruleset
ftp
irc
22 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:51 hits: 05-29 to 06-02]
51c1525417 [0] none:none
Obsidium| none trace
01:59:00 WinXP 116.59.34.14 (-):
MOBILE BUSINESS GROUP CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 a0139d7ad8
[Firefox:438 hits: 05-02 to 06-01]
d9e9662db1 [0] ASM:Graph
PolyEnE| lines=68 trace
T:03:38:00 WinXP 219.105.90.50 (ADACHI.NE.JP):
CABLE TELEVISION ADACHI CORP,
JP.
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
29 of 31 03c8316704
NEW
f8ba804137 [0] none:none
none|none none trace
04:09:00 Win2K-f 91.124.8.218 (UKRTEL.NET):
UKRTELECOM,
BROVARY, KYYIVS'KA OBLAST', UA.
n/a CN:hail2.dns2go.com
US:209.63.232.19:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:51 hits: 05-29 to 06-02]
51c1525417 [0] none:none
Obsidium| none trace
04:23:00 WinXP 118.86.203.252 (-):
.
n/a   445 pcap raw alerts
ruleset
http
1 line
Argh : 0.3
profile
none summary
tarball
none none none none none none none
05:09:00 Win2K-f 201.19.87.234 (STERLINGSTUDENTS.NET):
COMITE GESTOR DA INTERNET NO BRASIL,
BR. (DSL)
n/a CN:hail2.dns2go.com
US:209.63.232.19:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:51 hits: 05-29 to 06-02]
51c1525417 [0] none:none
Obsidium| none trace
T:06:09:00 Win2K-f 89.214.185.221 (-):
TMN - TELECOMUNICACOES MOVEIS NACIONAIS SA,
PT.
n/a CN:hail2.dns2go.com
US:209.63.232.19:8885
445 pcap raw alerts
ruleset
ftp
17 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:51 hits: 05-29 to 06-02]
51c1525417 [0] none:none
Obsidium| none trace
T:06:39:00 Win2K-f 96.13.246.127 (-):
.
n/a US:www.blackirc.us
US:64.131.76.60:80
445 pcap raw alerts
ruleset
http
9 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:06:40:00 Win2K-f 79.81.148.203 (G-M-I.NET):
EU-ZZ,
UK.
n/a US:qtas.net
SE:dzuc.net
SE:84.244.5.183:2345
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
8 of 31 859e6786f0
[Firefox: 2 hits: 05-30 to 05-31]
859e6786f0 [1] ASM:Graph
StarForce| lines=95 trace
T:07:42:00 Win2K-f 200.228.107.5 (STERLINGSTUDENTS.NET):
COMITE GESTOR DA INTERNET NO BRASIL,
BR. (DSL)
n/a US:qtas.net
SE:dzuc.net
SE:84.244.5.183:2345
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
3 of 31 f800daf83e
[Firefox: 2 hits: 05-31 to 05-31]
f800daf83e [1] ASM:Graph
StarForce| lines=86 trace
08:25:00 WinXP 122.2.146.156 (PLDT.NET):
IPG,
PH.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 d42c1cc7c0
[Firefox:279 hits: 05-01 to 05-31]
af9ca5bed1 [0] ASM:Graph
PolyEnE| lines=54 trace
T:08:34:00 Win2K-f 85.135.142.97 (SLOVANET.SK):
SLOVANET ADSL DATA POOL,
BRATISLAVA, BRATISLAVSKY, SK. (DSL)
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
15 of 31 6c4c3242ba
[Firefox: 5 hits: 05-31 to 06-02]
47300e90ee [0] none:none
none|none none trace
08:37:00 WinXP 60.52.99.161 (TM.NET.MY):
TELEKOM MALAYSIA BERHAD,
PUCHONG, SELANGOR, MY.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
15 of 31 6c4c3242ba
[Firefox: 5 hits: 05-31 to 06-02]
47300e90ee [0] none:none
none|none none trace
08:51:00 Win2K-f 81.190.93.175 (MM.PL):
MULTIMEDIA POLSKA S. A,
GDYNIA, POMORSKIE, PL.
n/a   445 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:09:06:00 Win2K-f 170.51.102.21 (COM.AR):
CTI COMPANIA DE TELEFONAS DEL INTERIOR S.A,
AR.
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
28 of 31 703730b32b
[Firefox: 2 hits: 05-31 to 05-31]
5e5af423e8 [0] none:none
Armadillo| none trace
T:09:24:00 Win2K-f 166.136.224.202 (MYVZW.COM):
SERVICE PROVIDER CORPORATION,
BEDMINSTER, NEW JERSEY, US.
n/a US:qtas.net
SE:dzuc.net
445 pcap raw alerts
ruleset
http
irc
2 lines
Yeah : 0.8
profile
none summary
tarball
3 of 31 f800daf83e
[Firefox: 2 hits: 05-31 to 05-31]
f800daf83e [1] ASM:Graph
StarForce| lines=86 trace
09:56:00 WinXP 201.19.137.33 (STERLINGSTUDENTS.NET):
COMITE GESTOR DA INTERNET NO BRASIL,
BR. (DSL)
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:51 hits: 05-29 to 06-02]
51c1525417 [0] none:none
Obsidium| none trace
10:17:00 WinXP 60.53.245.255 (TM.NET.MY):
TELEKOM MALAYSIA BERHAD,
MALACCA, MELAKA, MY.
n/a   445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
4 of 31 fcb2cd80a1
NEW
none[3] none:none
Obsidium| none trace
T:10:27:00 Win2K-f 130.13.220.227 (QWEST.NET):
QWEST BROADBAND SERVICES INC,
PHOENIX, ARIZONA, US.
64.32.28.8:1977 FI:neo12.cjb.net 135 pcap raw alerts
ruleset
irc
368 lines
Yeah : 1.3
profile
none summary
tarball
5 of 31 0b6af9e88a
[Firefox: 3 hits: 05-31 to 06-01]
24b6fb10de [0] none:none
StarForce| none trace
T:10:28:00 Win2K-f 82.253.105.70 (PROXAD.NET):
PROXAD / FREE SAS,
NICE, PROVENCE-ALPES-COTE D'AZUR, FR. (DSL)
84.244.5.183:2345 US:wow.blackirc.us
SE:tap.radioprishtina.net
445 pcap raw alerts
ruleset
http
irc
37 lines
Yeah : 1.3
profile
none summary
tarball
3 of 31 0c6fc94f09
NEW
0c6fc94f09 [1] ASM:Graph
StarForce| lines=86 trace
10:42:00 WinXP 190.31.241.168 (NET.AR):
APOLO -GOLD-TELECOM-PER,
BUENOS AIRES, BUENOS AIRES, AR.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
19 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:51 hits: 05-29 to 06-02]
51c1525417 [0] none:none
Obsidium| none trace
T:11:10:00 Win2K-f 59.96.48.11 (10/24.BSNL.IN):
NIB (NATIONAL INTERNET BACKBONE),
BANGALORE, KARNATAKA, IN.
84.244.6.253:2345 66.29.25.194:80 US:www.blackirc.us
SE:tap.tronko.net
445 pcap raw alerts
ruleset
http
irc
70 lines
Yeah : 1.3
profile
none summary
tarball
3 of 32
3 of 31
05ec072edf
[Firefox: 4 hits: 05-30 to 06-01]
7287487211
[Firefox: 3 hits: 05-30 to 05-31]
05ec072edf [1]
7287487211[1]
ASM:Graph
ASM:Graph
StarForce|
StarForce|
lines=86
lines=86
trace
trace
T:12:05:00 WinXP 216.79.206.161 (BELLSOUTH.NET):
BELLSOUTH.NET INC,
SHREVEPORT, LOUISIANA, US.
85.114.137.60:65520 DE:proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
DE:85.114.137.60:65520
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
30 of 31 bcbabdf952
NEW
none[4] none:none
PolyEnE| none trace
T:12:06:00 Win2K-f 89.116.229.125 (ERDVES.LT):
SC LITHUANIAN RADIO AND TV CENTER,
VILNIUS, VILNIAUS APSKRITIS, LT.
n/a CN:hail2.dns2go.com 445 pcap raw alerts
ruleset
ftp
irc
22 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:51 hits: 05-29 to 06-02]
51c1525417 [0] none:none
Obsidium| none trace
T:12:15:00 WinXP 200.114.10.214 (INTERCABLE.NET.CO):
TV CABLE PROMISION S.A,
BUCARAMANGA, SANTANDER, CO. (DSL)
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:3018 hits: 12-31 to 06-01]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
T:12:22:00 WinXP 200.127.190.248 (NET.AR):
PRIMA S.A,
BUENOS AIRES, BUENOS AIRES, AR. (DSL)
194.54.90.246:80 UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
31 of 31 af0c4989ca
[Firefox: 3 hits: 05-31 to 06-02]
none[4] none:none
PolyEnE| none trace
T:12:28:00 WinXP 98.140.130.18 (-):
.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
31 of 33 bce12aa21f
[Firefox:12 hits: 05-12 to 06-01]
none[4] none:none
PolyEnE| none trace
12:30:00 WinXP 66.75.88.141 (RR.COM):
ROAD RUNNER HOLDCO LLC,
RESEDA, CALIFORNIA, US.
n/a RU:moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 55fe9d9ade
[Firefox:49 hits: 05-03 to 05-31]
4bce6c4887 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
12:49:00 WinXP 170.51.101.120 (COM.AR):
CTI COMPANIA DE TELEFONAS DEL INTERIOR S.A,
AR.
85.114.137.60:65520 DE:proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
DE:85.114.137.60:65520
445 pcap raw alerts
ruleset
http
irc
3 lines
Yeah : 1.3
profile
none summary
tarball
31 of 31 ed6e30072f
NEW
none[4] none:none
PolyEnE| none trace
T:13:48:00 Win2K-f 78.96.171.204 (ASTRAL.RO):
ASTRAL TELECOM SA,
RO.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:51 hits: 05-29 to 06-02]
51c1525417 [0] none:none
Obsidium| none trace
T:13:51:00 Win2K-f 170.51.166.127 (COM.AR):
CTI COMPANIA DE TELEFONAS DEL INTERIOR S.A,
AR.
85.114.137.60:80 64.85.160.111:5001 DE:proxim.ircgalaxy.pl
US:cookie.roltf.ws
DE:85.114.137.60:80
445 pcap raw alerts
ruleset
ftp
irc
22 lines
Yeah : 1.3
profile
none summary
tarball
28 of 31 703730b32b
[Firefox: 2 hits: 05-31 to 05-31]
5e5af423e8 [0] none:none
Armadillo| none trace
13:53:00 Win2K-f 200.29.234.189 (-):
.
n/a CN:hail2.dns2go.com 445 pcap raw alerts
ruleset
ftp
irc
24 lines
Yeah : 0.8
profile
none summary
tarball
15 of 31 6c4c3242ba
[Firefox: 5 hits: 05-31 to 06-02]
47300e90ee [0] none:none
none|none none trace
14:00:00 WinXP 86.7.169.209 (NTL.COM):
NTL INFRASTRUCTURE - BROMLEY,
WARRINGTON, ENGLAND, UK. (DSL)
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 dd02947289
[Firefox:10 hits: 05-09 to 05-31]
62b3e97bda [0] ASM:Graph
PolyEnE| lines=68 trace
T:14:07:00 WinXP 91.124.77.77 (UKRTEL.NET):
UKRTELECOM,
BROVARY, KYYIVS'KA OBLAST', UA.
n/a CN:hail2.dns2go.com 445 pcap raw alerts
ruleset
ftp
irc
26 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:51 hits: 05-29 to 06-02]
51c1525417 [0] none:none
Obsidium| none trace
14:33:00 WinXP 122.18.136.81 (OCN.NE.JP):
OPEN COMPUTER NETWORK,
JP.
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:616 hits: 07-11 to 06-01]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
15:30:00 Win2K-f 82.236.37.172 (PROXAD.NET):
PROXAD / FREE SAS,
NICE, PROVENCE-ALPES-COTE D'AZUR, FR.
213.239.192.125:5001 DE:cookie.roltf.ws
US:64.85.160.111:5001
445 pcap raw alerts
ruleset
ftp
irc
21 lines
Yeah : 1.3
profile
none summary
tarball
19 of 32 382279b44f
[Firefox: 7 hits: 05-22 to 06-01]
049e62d55b [0] none:none
Armadillo| none trace
T:17:13:00 Win2K-f 88.160.61.162 (PROXAD.NET):
PROXAD / FREE SAS,
FR.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:51 hits: 05-29 to 06-02]
51c1525417 [0] none:none
Obsidium| none trace
17:30:00 Win2K-f 190.31.174.248 (NET.AR):
APOLO -GOLD-TELECOM-PER,
BUENOS AIRES, BUENOS AIRES, AR.
n/a CN:hail2.dns2go.com 445 pcap raw alerts
ruleset
ftp
irc
22 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:51 hits: 05-29 to 06-02]
51c1525417 [0] none:none
Obsidium| none trace
17:39:00 Win2K-f 220.131.229.66 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAINAN, KAO-HSIUNG, TW.
222.177.11.165:8885 CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
irc
23 lines
Yeah : 1.3
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:51 hits: 05-29 to 06-02]
51c1525417 [0] none:none
Obsidium| none trace
19:21:00 WinXP 121.102.134.60 (HI-HO.NE.JP):
PANASONIC NETWORK SERVICES INC,
JP.
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:616 hits: 07-11 to 06-01]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
T:19:22:00 Win2K-f 190.31.174.248 (NET.AR):
APOLO -GOLD-TELECOM-PER,
BUENOS AIRES, BUENOS AIRES, AR.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
irc
26 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:51 hits: 05-29 to 06-02]
51c1525417 [0] none:none
Obsidium| none trace
21:41:00 WinXP 62.11.157.65 (DIALUP.TISCALI.IT):
TISCALI ITALIA SPA,
CAGLIARI, SARDEGNA, IT. (DIAL)
n/a DE:siliconfireware.ru
US:searchportal.information.com
:www.proxy-socks.net
:wpad
US:208.73.212.12:80
DE:217.11.54.126:80
445 pcap raw alerts
ruleset
http
http
http
3 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 df17a625ee
[Firefox:453 hits: 05-04 to 06-02]
9bbdd086c5 [0] none:none
ASPack| none trace
T:22:14:00 Win2K-f 85.179.248.78 (ALICEDSL.DE):
HANSENET-ADSL,
DE. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
19 of 32 382279b44f
[Firefox: 7 hits: 05-22 to 06-01]
049e62d55b [0] none:none
Armadillo| none trace
T:23:36:00 Win2K-f 78.60.172.115 (ZEBRA.LT):
LIETUVOS,
LT.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:51 hits: 05-29 to 06-02]
51c1525417 [0] none:none
Obsidium| none trace
23:39:00 Win2K-f 78.62.109.132 (ZEBRA.LT):
LIETUVOS,
LT.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:51 hits: 05-29 to 06-02]
51c1525417 [0] none:none
Obsidium| none trace