Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

05 June 2008
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
T:00:21:00 WinXP 80.191.186.131 (-):
AREA NO 1-5 PARTITION,
TEHRAN, TEHRAN, IR. (100Mbps)
n/a   445 pcap raw alerts
ruleset
http
6 lines
Argh : 0.3
profile
none summary
tarball
none none none none none none none
01:16:00 WinXP 122.2.152.92 (PLDT.NET):
IPG,
PH.
n/a   445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 d42c1cc7c0
[Firefox:282 hits: 05-01 to 06-04]
af9ca5bed1 [0] ASM:Graph
PolyEnE| lines=54 trace
T:01:16:00 WinXP 122.2.152.92 (PLDT.NET):
IPG,
PH.
n/a   445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 d42c1cc7c0
[Firefox:282 hits: 05-01 to 06-04]
af9ca5bed1 [0] ASM:Graph
PolyEnE| lines=54 trace
T:01:17:00 WinXP 4.242.108.114 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
CENTRAL POINT, OREGON, US. (DIAL)
n/a :proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 32 677536d92f
NEW
none[none] none:none
none|none none none
04:09:00 WinXP 77.197.201.180 (GAOLAND.NET):
DYNAMIC POOLS,
FR.
n/a DE:siliconfireware.ru
GB:welcome3.smile.co.uk
:wpad
GB:195.92.84.198:80
DE:212.227.111.29:80
DE:217.11.54.126:80
EU:78.47.200.154:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 a12cab51ef
[Firefox:1034 hits: 05-01 to 06-04]
40f7f463c4 [0] ASM:Graph
ASPack| lines=281
embedded dns
trace
04:41:00 Win2K-f 91.142.20.64 (KABELSPEED.AT):
KABELSPEED,
AT.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
28 of 32 7cafcda796
NEW
none[none] none:none
none|none none none
T:04:51:00 WinXP 222.5.234.231 (DION.NE.JP):
DION (KDDI CORPORATION),
JP. (DIAL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 1a2c0e6130
[Firefox:402 hits: 12-31 to 06-04]
048df78048 [0] ASM:Graph
none|none lines=61 trace
05:36:00 Win2K-f 122.52.21.57 (PLDT.NET):
IPG,
PH.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
15 of 31 6c4c3242ba
[Firefox: 7 hits: 05-31 to 06-04]
47300e90ee [0] none:none
none|none none trace
06:33:00 WinXP 41.214.174.30 (-):
.
n/a   445 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:06:34:00 WinXP 41.214.174.30 (-):
.
n/a   445 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:08:09:00 WinXP 62.215.53.122 (-):
FAST TELCO INFRA STRUCTURE WEB ACCESS USERS,
KUWAIT, AL KUWAYT, KW.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
30 of 32 a636f5ce05
NEW
none[none] none:none
none|none none none
T:12:36:00 Win2K-f 92.112.181.123 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:61 hits: 05-29 to 06-04]
51c1525417 [0] none:none
Obsidium| none trace
12:52:00 WinXP 210.139.205.56 (SO-NET.NE.JP):
SO-NET ENTERTAINMENT CORPORATION,
JP.
n/a UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:3022 hits: 12-31 to 06-04]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
T:14:34:00 Win2K-f 89.124.86.12 (IRISHBROADBAND.IE):
ESB ORANMORE CUSTOMER EXPANSION,
IE.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
15 of 31 6c4c3242ba
[Firefox: 7 hits: 05-31 to 06-04]
47300e90ee [0] none:none
none|none none trace
16:08:00 WinXP 78.49.37.47 (ALICEDSL.DE):
HANSENET TELEKOMMUNIKATION GMBH,
HAMBURG, HAMBURG, DE. (DSL)
217.170.244.2:443   445 pcap raw alerts
ruleset
shell
ftp
irc
29 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2633 hits: 12-31 to 05-19]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
16:16:00 WinXP 170.51.111.236 (COM.AR):
CTI COMPANIA DE TELEFONAS DEL INTERIOR S.A,
AR.
n/a RU:moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
[Firefox:1314 hits: 12-31 to 06-04]
1aad8e4632 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
T:17:08:00 Win2K-f 4.243.53.79 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
SEATTLE, WASHINGTON, US. (DIAL)
n/a   445 pcap raw alerts
ruleset
shell
11 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
17:14:00 WinXP 207.177.46.246 (WCCTA.NET):
WEBSTER CALHOUN TELEPHONE CO,
FT. DODGE, IOWA, US. (DSL)
n/a   445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:20:02:00 Win2K-f 96.15.86.221 (-):
.
217.170.244.2:443   445 pcap raw alerts
ruleset
shell
ftp
irc
28 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2633 hits: 12-31 to 05-19]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
T:20:12:00 Win2K-f 219.255.214.101 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a   135 pcap raw alerts
ruleset
other
111 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:20:43:00 WinXP 66.27.180.44 (RR.COM):
ROAD RUNNER HOLDCO LLC,
CANOGA PARK, CALIFORNIA, US.
n/a  
CZ:217.170.244.2:443
CZ:82.114.90.2:443
445 pcap raw alerts
ruleset
shell
ftp
110 lines
Yeah : 0.8
profile
none summary
tarball
16 of 31 23c32fbd78
[Firefox: 2 hits: 05-03 to 05-11]
none[4] none:none
PeCompact| none trace
21:13:00 Win2K-f 116.206.54.180 (-):
MOBIF WIRELESS BROADBAND SDN. BHD,
KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:61 hits: 05-29 to 06-04]
51c1525417 [0] none:none
Obsidium| none trace
22:33:00 WinXP 170.51.136.20 (COM.AR):
CTI COMPANIA DE TELEFONAS DEL INTERIOR S.A,
AR.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:3022 hits: 12-31 to 06-04]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
T:23:58:00 WinXP 79.81.10.216 (G-M-I.NET):
EU-ZZ,
UK.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
20 lines
Yeah : 0.8
profile
none summary
tarball
29 of 32 5708dc9e50
NEW
none[none] none:none
none|none none none