Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

03 June 2008
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
T:00:59:00 Win2K-f 78.96.76.190 (ASTRAL.RO):
ASTRAL TELECOM SA,
RO.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
irc
24 lines
Yeah : 0.8
profile
none summary
tarball
15 of 31 6c4c3242ba
[Firefox: 5 hits: 05-31 to 06-02]
47300e90ee [0] none:none
none|none none trace
01:12:00 Win2K-f 89.117.77.137 (ERDVES.LT):
SC LITHUANIAN RADIO AND TV CENTER,
VILNIUS, VILNIAUS APSKRITIS, LT.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
22 of 32 9a8996e51e
NEW
none[none] none:none
none|none none none
01:41:00 Win2K-f 83.8.107.46 (TPNET.PL):
NEOSTRADA PLUS,
PL.
n/a US:qtas.net
SE:scl.jullope.com
SE:84.244.5.183:2345
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
3 of 33 1c8163ae44
NEW
none[none] none:none
none|none none none
02:38:00 Win2K-f 41.203.225.227 (-):
.
85.114.137.60:65520 DE:proxim.ircgalaxy.pl
CN:hail2.dns2go.com
CN:222.177.11.165:8885
DE:85.114.137.60:65520
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
28 of 32 dc0b7d619d
NEW
none[none] none:none
none|none none none
02:46:00 WinXP 218.173.176.150 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
30 of 32 23c6886399
NEW
none[none] none:none
none|none none none
T:02:48:00 Win2K-f 24.185.110.88 (OPTONLINE.NET):
OPTIMUM ONLINE (CABLEVISION SYSTEMS),
BROOKLYN, NEW YORK, US.
n/a   135 pcap raw alerts
ruleset
other
112 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:02:48:00 WinXP 218.173.176.150 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
30 of 32 23c6886399
NEW
none[none] none:none
none|none none none
T:02:50:00 WinXP 79.132.202.253 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a EU:siliconfireware.ru
UA:vit.ln.ua
:baner.vit
:www.proxy-socks.net
:wpad
DE:217.11.54.126:80
EU:78.47.200.154:80
445 pcap raw alerts
ruleset
http
22 lines
Yeah : 0.8
profile
none summary
tarball
30 of 32 7dd1fe2970
[Firefox:19 hits: 09-07 to 04-01]
dcc673c815 [0] ASM:Graph
ASPack| lines=374
embedded dns
trace
02:50:00 Win2K-f 92.46.6.17 (IKBCC.COM):
EU-ZZ,
UK.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:51 hits: 05-29 to 06-02]
51c1525417 [0] none:none
Obsidium| none trace
04:16:00 WinXP 87.61.171.12 (IP.TELE.DK):
TDC-TELEDANMARK-BREDBAANDSADSL-NET,
DK.
n/a DE:siliconfireware.ru
:wpad
DE:212.227.111.29:80
DE:217.11.54.126:80
EU:78.47.200.154:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 df17a625ee
[Firefox:453 hits: 05-04 to 06-02]
9bbdd086c5 [0] none:none
ASPack| none trace
T:04:42:00 WinXP 91.142.20.64 (KABELSPEED.AT):
KABELSPEED,
AT.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
28 of 32 7cafcda796
NEW
none[none] none:none
none|none none none
06:38:00 WinXP 86.155.86.208 (BTCENTRALPLUS.COM):
BT-CENTRAL-PLUS,
SWANSEA, WALES, UK.
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:616 hits: 07-11 to 06-01]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
T:06:50:00 WinXP 222.236.119.144 (HANANET.NET):
HANARO TELECOM INC,
KR.
n/a   135 pcap raw alerts
ruleset
other
94 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
07:04:00 Win2K-f 79.185.194.231 (TPNET.PL):
TPSA,
PL.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
12 of 32 2b3773ee10
NEW
none[none] none:none
none|none none none
T:07:38:00 WinXP 86.7.142.217 (NTL.COM):
NTL INFRASTRUCTURE - BROMLEY,
LONDON, ENGLAND, UK. (DSL)
n/a   445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 a0139d7ad8
[Firefox:438 hits: 05-02 to 06-01]
d9e9662db1 [0] ASM:Graph
PolyEnE| lines=68 trace
T:09:01:00 WinXP 92.40.61.67 (IKBCC.COM):
EU-ZZ,
UK.
85.114.137.60:80 DE:proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
DE:85.114.137.60:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
31 of 32 6f1691e3b3
NEW
none[none] none:none
none|none none none
T:09:12:00 Win2K-f 79.140.12.128 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:51 hits: 05-29 to 06-02]
51c1525417 [0] none:none
Obsidium| none trace
T:09:44:00 Win2K-f 92.47.253.174 (IKBCC.COM):
EU-ZZ,
UK.
n/a   445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
28 of 32 6acb8a7a56
NEW
none[none] none:none
none|none none none
T:09:54:00 Win2K-f 87.70.56.143 (012.NET.IL):
GOLDEN LINES INTERNATIONAL COMMUNICATION SERVICES LTD,
IL.
n/a   445 pcap raw alerts
ruleset
ftp
17 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:10:19:00 WinXP 201.74.162.191 (STERLINGSTUDENTS.NET):
COMITE GESTOR DA INTERNET NO BRASIL,
BR. (DSL)
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:3018 hits: 12-31 to 06-01]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
10:37:00 WinXP 216.255.167.30 (TVCCONNECT.NET):
THAMES VALLEY COMMUNICATIONS INC,
GROTON, CONNECTICUT, US.
n/a DE:siliconfireware.ru
EU:ebookfinaltrash.ru
:wpad
DE:212.227.111.29:80
DE:217.11.54.126:80
EU:78.47.200.154:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 a12cab51ef
[Firefox:1032 hits: 05-01 to 06-02]
40f7f463c4 [0] ASM:Graph
ASPack| lines=281
embedded dns
trace
T:11:17:00 WinXP 92.40.30.209 (IKBCC.COM):
EU-ZZ,
UK.
85.114.137.60:80 DE:proxim.ircgalaxy.pl
DE:85.114.137.60:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
28 of 31 f58222344f
[Firefox:11 hits: 12-31 to 05-21]
2a56436a64 [0] ASM:Graph
PolyEnE| lines=265
embedded dns
trace
T:11:28:00 WinXP 66.50.89.40 (PRTC.NET):
PUERTO RICO TELEPHONE COMPANY,
SAN JUAN, PUERTO RICO, PR.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:3018 hits: 12-31 to 06-01]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
T:11:28:00 Win2K-f 89.174.123.250 (IPARTNERS.PL):
GTS POLSKA SP. Z O.O,
KRAKOW, MALOPOLSKIE, PL.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:51 hits: 05-29 to 06-02]
51c1525417 [0] none:none
Obsidium| none trace
11:40:00 Win2K-f 189.54.9.168 (BRASILTELECOM.NET.BR):
COMITE GESTOR DA INTERNET NO BRASIL,
BR.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:51 hits: 05-29 to 06-02]
51c1525417 [0] none:none
Obsidium| none trace
T:11:49:00 WinXP 83.93.179.220 (ADSL-DHCP.TELE.DK):
TDC-TELEDANMARK-BREDBAANDSADSL-NET,
DK. (DSL)
85.114.137.60:80 DE:proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
DE:85.114.137.60:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
30 of 32 2a0cd9d140
NEW
none[none] none:none
none|none none none
T:12:41:00 Win2K-f 78.54.135.136 (ALICEDSL.DE):
HANSENET TELEKOMMUNIKATION GMBH,
HAMBURG, HAMBURG, DE. (DSL)
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:51 hits: 05-29 to 06-02]
51c1525417 [0] none:none
Obsidium| none trace
T:13:09:00 WinXP 85.152.149.163 (CM-85-152-150-10.TELECABLE.ES):
TELECABLE,
GIJON, ASTURIAS, ES. (DSL)
n/a RU:moscow-advokat.ru 445 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 042774a2b7
[Firefox:137 hits: 05-01 to 05-09]
1c9a472cd7 [0] ASM:Graph
PolyEnE| lines=71
embedded dns
trace
13:10:00 WinXP 190.188.72.215 (NET.AR):
PRIMA S.A,
AR.
85.114.137.60:65520 DE:proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
DE:85.114.137.60:65520
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
31 of 32 028454d36b
NEW
none[none] none:none
none|none none none
13:10:00 WinXP 194.65.179.86 (DIAL-B1-178-10.TELEPAC.PT):
TELEPAC - COMUNICACOES INTERACTIVAS SA,
PORTO, PORTO, PT. (DIAL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 1a2c0e6130
[Firefox:399 hits: 12-31 to 06-01]
048df78048 [0] ASM:Graph
none|none lines=61 trace
13:10:00 WinXP 85.152.149.163 (CM-85-152-150-10.TELECABLE.ES):
TELECABLE,
GIJON, ASTURIAS, ES. (DSL)
n/a RU:moscow-advokat.ru
US:lia.zanet.net
:irc.kar.net
:gaspode.zanet.org.za
:caen.fr.eu.undernet.org
:washington.dc.us.undernet.org
RU:irc.tsk.ru
NO:london.uk.eu.undernet.org
RU:194.6.222.11:6667
445 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 042774a2b7
[Firefox:137 hits: 05-01 to 05-09]
1c9a472cd7 [0] ASM:Graph
PolyEnE| lines=71
embedded dns
trace
15:49:00 WinXP 24.162.133.232 (RR.COM):
ROAD RUNNER HOLDCO LLC,
WACO, TEXAS, US.
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 1a2c0e6130
[Firefox:399 hits: 12-31 to 06-01]
048df78048 [0] ASM:Graph
none|none lines=61 trace
T:15:51:00 WinXP 69.134.103.153 (RR.COM):
ROAD RUNNER HOLDCO LLC,
CONCORD, NORTH CAROLINA, US.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:3018 hits: 12-31 to 06-01]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
T:18:37:00 WinXP 190.137.123.33 (NET.AR):
TELECOM ARGENTINA S.A,
AR.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
31 of 33 bce12aa21f
[Firefox:12 hits: 05-12 to 06-01]
none[4] none:none
PolyEnE| none trace
19:25:00 WinXP 92.40.43.229 (IKBCC.COM):
EU-ZZ,
UK.
85.114.137.60:80 DE:proxim.ircgalaxy.pl
DE:85.114.137.60:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
27 of 32 9c037c69f6
[Firefox: 2 hits: 04-21 to 04-26]
none[3] none:none
ASPack| none trace
T:19:57:00 WinXP 64.48.134.40 (ALGX.NET):
XO COMMUNICATIONS,
CLEVELAND, OHIO, US.
n/a US:www.yahoo.com
US:www.altavista.com
:jbeegvia.ru
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
31 of 32 17028f1eda
[Firefox: 4 hits: 09-29 to 04-18]
none[3] none:none
tElock| none trace
T:20:24:00 WinXP 24.70.131.49 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
CALGARY, ALBERTA, CA. (DSL)
n/a   135 pcap raw alerts
ruleset
other
112 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:20:51:00 WinXP 98.140.251.237 (-):
.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 d42c1cc7c0
[Firefox:279 hits: 05-01 to 05-31]
af9ca5bed1 [0] ASM:Graph
PolyEnE| lines=54 trace
20:55:00 WinXP 98.140.251.237 (-):
.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 d42c1cc7c0
[Firefox:279 hits: 05-01 to 05-31]
af9ca5bed1 [0] ASM:Graph
PolyEnE| lines=54 trace
20:57:00 WinXP 4.226.0.125 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
DESOTO, TEXAS, US. (DIAL)
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 3ae357d17b
[Firefox:712 hits: 05-01 to 05-30]
462a7be171 [0] ASM:Graph
PolyEnE| lines=73 trace
T:23:39:00 Win2K-f 89.117.77.137 (ERDVES.LT):
SC LITHUANIAN RADIO AND TV CENTER,
VILNIUS, VILNIAUS APSKRITIS, LT.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
22 of 32 9a8996e51e
NEW
none[none] none:none
none|none none none