Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

09 June 2008
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
T:01:52:00 WinXP 80.199.162.184 (ADSL-DHCP.TELE.DK):
TELEDANMARK,
COPENHAGEN, COPENHAGEN, DK. (DSL)
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
31 of 33 bce12aa21f
[Firefox:14 hits: 05-12 to 06-04]
none[4] none:none
PolyEnE| none trace
04:09:00 WinXP 219.105.120.187 (ADACHI.NE.JP):
CABLE TELEVISION ADACHI CORP,
JP.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
29 of 32 dd5b183a77
NEW
none[4] none:none
none|none none trace
05:12:00 WinXP 82.207.47.124 (UKRTEL.NET):
UKRTELECOM IP ACCESS NETWORK,
UA.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 986b59708d
[Firefox:291 hits: 05-03 to 06-08]
8a00217866 [0] ASM:Graph
PolyEnE| lines=57 trace
05:59:00 WinXP 61.207.160.149 (OCN.NE.JP):
OPEN COMPUTER NETWORK,
JP.
n/a   445 pcap raw alerts
ruleset
shell
ftp
13 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:629 hits: 07-11 to 06-08]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
T:07:08:00 WinXP 79.75.71.26 (AS9105.COM):
TELINCO,
UK.
n/a UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 986b59708d
[Firefox:291 hits: 05-03 to 06-08]
8a00217866 [0] ASM:Graph
PolyEnE| lines=57 trace
07:53:00 WinXP 74.141.72.198 (INSIGHTBB.COM):
INSIGHT COMMUNICATIONS COMPANY L.P,
LOUISVILLE, KENTUCKY, US.
n/a RU:moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
[Firefox:1317 hits: 12-31 to 06-07]
1aad8e4632 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
T:08:10:00 WinXP 74.141.72.198 (INSIGHTBB.COM):
INSIGHT COMMUNICATIONS COMPANY L.P,
LOUISVILLE, KENTUCKY, US.
n/a RU:moscow-advokat.ru
RU:194.6.222.11:6667
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
[Firefox:1317 hits: 12-31 to 06-07]
1aad8e4632 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
T:08:17:00 WinXP 122.147.96.8 (SPARQNET.NET):
NEW CENTURY INFOCOMM TECH. CO. LTD,
TAIPEI, T'AI-PEI, TW.
n/a   135 pcap raw alerts
ruleset
other
89 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
08:34:00 WinXP 79.75.112.168 (AS9105.COM):
TELINCO,
UK.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 986b59708d
[Firefox:291 hits: 05-03 to 06-08]
8a00217866 [0] ASM:Graph
PolyEnE| lines=57 trace
T:09:13:00 WinXP 202.123.10.238 (P10-10.INTNET.MU):
NATIONAL ISP,
QUATRE BORNES, PLAINES WILHEMS, MU.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 d42c1cc7c0
[Firefox:286 hits: 05-01 to 06-08]
af9ca5bed1 [0] ASM:Graph
PolyEnE| lines=54 trace
09:20:00 WinXP 81.154.188.232 (BTCENTRALPLUS.COM):
BT-CENTRAL-PLUS,
UK.
194.54.90.246:80 UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
29 of 32 a482c5c718
NEW
none[4] none:none
PolyEnE| none trace
T:10:12:00 WinXP 4.228.123.105 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
AURORA, COLORADO, US. (DIAL)
n/a   445 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
10:20:00 WinXP 93.120.128.81 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a RU:moscow-advokat.ru
RU:194.6.222.11:6667
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
[Firefox:1317 hits: 12-31 to 06-07]
1aad8e4632 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
T:10:20:00 WinXP 93.120.128.81 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a RU:moscow-advokat.ru
RU:194.6.222.11:6667
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
[Firefox:1317 hits: 12-31 to 06-07]
1aad8e4632 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
T:11:23:00 WinXP 79.138.180.49 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 a92e3f8fc8
[Firefox:114 hits: 05-03 to 05-30]
dfe02a1e52 [0] ASM:Graph
PolyEnE| lines=68 trace
11:49:00 WinXP 12.203.116.140 (MCHSI.COM):
AT&T WORLDNET SERVICES,
SPRINGFIELD, ILLINOIS, US.
194.54.90.246:80 UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 986b59708d
[Firefox:291 hits: 05-03 to 06-08]
8a00217866 [0] ASM:Graph
PolyEnE| lines=57 trace
T:12:40:00 WinXP 4.228.123.105 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
AURORA, COLORADO, US. (DIAL)
n/a   445 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:13:00:00 WinXP 78.130.93.183 (REV.OPTIMUS.PT):
OPTIMUS TELECOMUNICAGUES S.A,
PT.
194.54.90.246:80 :proxim.ircgalaxy.pl
UA:citi-bank.ru
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
29 of 32 4e05133c5e
NEW
none[4] none:none
PolyEnE| none trace
13:26:00 WinXP 208.83.217.222 (-):
.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 986b59708d
[Firefox:291 hits: 05-03 to 06-08]
8a00217866 [0] ASM:Graph
PolyEnE| lines=57 trace
13:32:00 WinXP 66.50.89.25 (PRTC.NET):
PUERTO RICO TELEPHONE COMPANY,
SAN JUAN, PUERTO RICO, PR.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:3038 hits: 12-31 to 06-08]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
T:13:38:00 WinXP 87.253.196.155 (VOLOGDA.RU):
OJSC NORTH-WEST TELECOM BRANCH ELECTROSVYAS OF VOLOGDA REGION,
RU.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:3038 hits: 12-31 to 06-08]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
T:13:47:00 WinXP 64.139.104.242 (RCABLETV.COM):
NCI DATA.COM INC,
REPUBLIC, WASHINGTON, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
93 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:14:20:00 WinXP 70.60.4.218 (RR.COM):
ROAD RUNNER HOLDCO LLC,
COLUMBUS, OHIO, US.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
31 of 32 1e5df7ba74
[Firefox:21 hits: 03-24 to 06-01]
a5331b711f [0] ASM:Graph
PolyEnE| lines=68 trace
T:14:32:00 Win2K-f 24.234.201.231 (COX.NET):
COX COMMUNICATIONS INC,
LAS VEGAS, NEVADA, US.
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
15:52:00 WinXP 72.174.65.227 (BRESNAN.NET):
BRESNAN COMMUNICATIONS LLC,
PURCHASE, NEW YORK, US.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
31 of 32 f2668b51f1
[Firefox: 5 hits: 08-10 to 01-04]
none[4] none:none
PolyEnE| none trace
T:16:04:00 Win2K-f 71.98.81.62 (VERIZON.NET):
VERIZON INTERNET SERVICES INC,
LAFAYETTE, INDIANA, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
111 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:17:07:00 WinXP 24.84.196.153 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
SURREY, BRITISH COLUMBIA, CA. (DSL)
n/a RU:moscow-advokat.ru 445 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 32a0d7d0e0
[Firefox:43 hits: 05-04 to 06-04]
d791762796 [0] ASM:Graph
tElock| lines=81
embedded dns
trace
17:18:00 WinXP 208.28.222.127 (KIMBANET.COM):
SPRINT,
MARTINSVILLE, VIRGINIA, US.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:3038 hits: 12-31 to 06-08]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
T:17:54:00 WinXP 4.154.82.165 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
SUWANEE, GEORGIA, US. (DIAL)
n/a   135 pcap raw alerts
ruleset
other
88 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:17:55:00 WinXP 63.26.118.57 (UU.NET):
UUNET TECHNOLOGIES INC,
US.
n/a   135 pcap raw alerts
ruleset
other
4 lines
Argh : 0.3
profile
none summary
tarball
none none none none none none none
T:18:48:00 WinXP 98.140.130.18 (-):
.
n/a UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
31 of 33 bce12aa21f
[Firefox:14 hits: 05-12 to 06-04]
none[4] none:none
PolyEnE| none trace
18:51:00 WinXP 98.140.130.18 (-):
.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
31 of 33 bce12aa21f
[Firefox:14 hits: 05-12 to 06-04]
none[4] none:none
PolyEnE| none trace
T:19:07:00 WinXP 24.77.205.226 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
KELOWNA, BRITISH COLUMBIA, CA. (DSL)
67.43.236.98:10324 CA:xx.nadnadzz.info
CA:nadsam0.info
US:130.107.163.157:18509
135 pcap raw alerts
ruleset
irc
http
292 lines
Yeah : 1.3
profile
none summary
tarball
13 of 32
13 of 32
19 of 32
31 of 33
24 of 32
2b9c32bee9
NEW
2c11ff8e99
NEW
797863ab19
NEW
954a98c971
NEW
e8f2f5bfe0
NEW
2b9c32bee9 [1]
none [4]
none [4]
none [4]
none [4]
ASM:Graph
none:none
none:none
none:none
none:none
none|none
none|none
Mew|
FSG|
none|none
lines=37
none
none
none
none
trace
trace
trace
trace
trace
T:19:22:00 WinXP 4.228.123.105 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
AURORA, COLORADO, US. (DIAL)
n/a   445 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:20:30:00 Win2K-f 61.17.221.73 (VSNL.NET.IN):
VIDESH SANCHAR NIGAM LTD - INDIA,
COCHIN, KERALA, IN. (DSL)
84.244.5.183:2345 66.29.31.3:80 US:wow.blackirc.us
SE:tap.radioprishtina.net
445 pcap raw alerts
ruleset
http
irc
81 lines
Yeah : 1.3
profile
none summary
tarball
4 of 31
12 of 32
3e69c64639
NEW
a224cce2a7
NEW
3e69c64639 [1]
a224cce2a7[1]
ASM:Graph
ASM:Graph
none|none
StarForce|
lines=32
lines=37
trace
trace
T:20:47:00 WinXP 61.218.193.218 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
n/a   135 pcap raw alerts
ruleset
other
111 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:20:58:00 WinXP 68.145.83.221 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
CALGARY, ALBERTA, CA. (DSL)
n/a   135 pcap raw alerts
ruleset
other
111 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none