Welcome to the Cyber-TA
Daily Malware Binary DIGEST Summary Page



23 September 2008

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.



Packed
MD5
UnPacket
MD5
Victim
OS
AntiVirus
Hit-Cnt
First
Encounter
Last
Encounter
Freq
Cnt
Behavioral
Clusters
Unpacked
Egg.asm
Packer
Fingerprint
API
Resolution
String
Cnt
Syscall
Trace
c3914afebc
NEW
none[none] WinXP 35 of 36 00:53:22 00:53:47 2 none none:none
none|none none none
53bfe15e91
[Firefox:2390 hits: 06-17 to 09-22]
73f1082158
[Firefox:1185 hits: 06-18 to 09-22]
none[4]
73f1082158[1]
Win2K-f
WinXP
0 of 32 03:18:00 21:06:16 10 none none:none
ASM:Graph
tElock|
Armadillo|
47% none
lines=81
trace
trace
d799133dd3
NEW
none[none] WinXP 33 of 36 00:48:43 00:48:43 1 none none:none
none|none none none
dd1174cc29
NEW
none[none] WinXP 33 of 36 00:16:55 00:16:55 1 none none:none
none|none none none
1fcc146d70
[Firefox:48 hits: 01-02 to 09-22]
258fafe892 [0] WinXP 29 of 29 23:58:57 23:58:57 1 none ASM:Graph
PolyEnE| 99% lines=68 trace
290e2cd1fc
[Firefox: 2 hits: 09-14 to 09-21]
none[none] WinXP 35 of 36 15:51:32 18:40:40 2 none none:none
none|none none none
53bfe15e91
[Firefox:2390 hits: 06-17 to 09-22]
none[4] WinXP
Win2K-f
33 of 33 02:10:27 23:42:28 25 none none:none
tElock| none trace
89e1f234f1
NEW
none[none] Win2K-f 31 of 36 10:31:50 10:31:50 1 none none:none
none|none none none
53bfe15e91
[Firefox:2390 hits: 06-17 to 09-22]
b7082104e4
[Firefox:145 hits: 06-18 to 09-22]
none[4]
none [4]
WinXP 8 of 33 02:36:55 02:36:55 1 none none:none
none:none
tElock|
tElock|
none
none
trace
trace
c20ca482e5
NEW
none[none] WinXP 34 of 36 14:18:27 14:18:27 1 none none:none
none|none none none
0965a28cb9
[Firefox: 2 hits: 07-19 to 07-22]
none[none] WinXP 29 of 33 07:42:46 07:42:46 1 none none:none
none|none none none
95db5533b0
NEW
none[none] WinXP 35 of 36 09:08:02 09:08:02 1 none none:none
none|none none none
168aab35a3
[Firefox:134 hits: 06-17 to 09-22]
none[4] Win2K-f 31 of 33 00:50:21 00:50:21 1 none none:none
tElock| none trace
73ce2b74da
[Firefox:13 hits: 06-18 to 09-21]
73ce2b74da [1] Win2K-f 3 of 33 15:24:06 15:24:06 1 none ASM:Graph
Armadillo| 47% lines=81 trace
bca9e0fb5f
[Firefox:28 hits: 06-18 to 09-20]
none[4] Win2K-f 31 of 32 17:44:25 17:44:25 1 none none:none
PolyEnE| none trace
a12cab51ef
[Firefox:527 hits: 01-01 to 09-21]
40f7f463c4 [0] WinXP 29 of 29 00:56:43 19:33:21 2 none ASM:Graph
ASPack| 54% lines=281
embedded dns
trace
2e99f5a69b
NEW
none[none] WinXP 34 of 36 19:28:04 19:28:04 1 none none:none
none|none none none
d99da8735e
[Firefox: 4 hits: 09-18 to 09-20]
none[none] WinXP 34 of 36 14:25:36 14:25:36 1 none none:none
none|none none none
03f912899b
[Firefox:136 hits: 01-08 to 09-22]
83893bd25d [0] WinXP 32 of 32 00:07:54 00:07:54 1 none ASM:Graph
none|none 100% lines=65 trace
95aa4a8220
NEW
none[none] Win2K-f 32 of 36 21:21:40 21:21:40 1 none none:none
none|none none none
4c3df24b32
[Firefox:188 hits: 06-17 to 09-21]
4c3df24b32 [1] Win2K-f 0 of 33 00:50:21 07:48:29 3 none ASM:Graph
Armadillo| 47% lines=81 trace
741e3b03b3
[Firefox:391 hits: 01-05 to 09-22]
e0197e8a64 [0] WinXP 31 of 32 01:57:53 22:52:56 6 none ASM:Graph
none|none 100% lines=62 trace
f353d4eed9
[Firefox:11 hits: 09-17 to 09-22]
none[none] WinXP 35 of 36 13:45:50 13:45:50 1 none none:none
none|none none none
e1b693266c
NEW
none[none] WinXP 34 of 36 07:26:15 07:26:15 1 none none:none
none|none none none
53bfe15e91
[Firefox:2390 hits: 06-17 to 09-22]
b5919931fe
[Firefox:635 hits: 06-20 to 09-22]
bea8cb1865
[Firefox:14 hits: 08-11 to 09-22]
none[4]
b5919931fe[1]
none [none]
Win2K-f 32 of 36 22:21:04 22:21:04 1 none none:none
ASM:Graph
none:none
tElock|
ASProtect|
none|none
none
lines=90
none
trace
trace
none
35853b9158
NEW
none[none] Win2K-f 22 of 36 20:25:26 20:25:26 1 none none:none
none|none none none
831f4ee0a7
[Firefox:554 hits: 01-01 to 09-22]
eb7546c600 [0] WinXP 29 of 29 09:16:39 19:49:49 3 none ASM:Graph
none|none 100% lines=61 trace
53bfe15e91
[Firefox:2390 hits: 06-17 to 09-22]
b5919931fe
[Firefox:635 hits: 06-20 to 09-22]
none[4]
b5919931fe[1]
Win2K-f 0 of 32 03:22:25 22:21:04 7 none none:none
ASM:Graph
tElock|
ASProtect|
48% none
lines=90
trace
trace
2204fd4d17
[Firefox: 5 hits: 09-15 to 09-20]
none[none] WinXP 35 of 36 19:11:07 19:11:07 1 none none:none
none|none none none
57ce4acac2
[Firefox:196 hits: 06-17 to 09-22]
57ce4acac2 [1] WinXP 0 of 33 03:01:48 20:38:43 4 none ASM:Graph
Armadillo| 47% lines=81 trace
e1a16d858c
[Firefox: 4 hits: 09-20 to 09-21]
none[none] WinXP 35 of 36 05:43:02 08:13:47 4 none none:none
none|none none none
1a2c0e6130
[Firefox:410 hits: 12-31 to 09-22]
048df78048 [0] WinXP 29 of 29 01:37:08 23:42:44 7 none ASM:Graph
none|none 100% lines=61 trace
53bfe15e91
[Firefox:2390 hits: 06-17 to 09-22]
a08f3b74a4
[Firefox:834 hits: 06-18 to 09-22]
none[4]
a08f3b74a4[1]
WinXP
Win2K-f
0 of 33 02:10:27 23:42:28 11 none none:none
ASM:Graph
tElock|
Armadillo|
47% none
lines=81
trace
trace
b872c76081
[Firefox:16 hits: 09-13 to 09-22]
none[none] WinXP 36 of 36 11:37:29 11:37:29 1 none none:none
none|none none none
93a723b64a
NEW
none[none] WinXP 34 of 36 00:58:51 00:58:56 2 none none:none
none|none none none
c6059fcbd5
NEW
none[none] WinXP 34 of 36 07:29:55 07:29:55 1 none none:none
none|none none none
a84ffdf670
[Firefox: 6 hits: 09-14 to 09-21]
none[none] WinXP 36 of 36 10:08:08 13:47:30 3 none none:none
none|none none none
8a75955033
[Firefox:35 hits: 06-20 to 09-21]
9276c8b36b
[Firefox:35 hits: 06-20 to 09-21]
none[4]
9276c8b36b[1]
Win2K-f 28 of 32 05:06:58 05:06:58 1 none none:none
ASM:Graph
tElock|
Armadillo|
47% none
lines=81
trace
trace
df17a625ee
[Firefox:245 hits: 01-01 to 09-22]
9bbdd086c5 [0] WinXP 29 of 29 08:50:13 16:56:55 4 none ASM:Graph
ASPack| 49% lines=186
embedded dns
trace
2204fd4d17
[Firefox: 5 hits: 09-15 to 09-20]
eb0857e1b1
[Firefox: 5 hits: 09-15 to 09-20]
none[none]
none [none]
WinXP 32 of 36 19:11:07 19:11:07 1 none none:none
none:none
none|none
none|none
none
none
none
none
35853b9158
NEW
8e5af24569
NEW
none[none]
none [none]
Win2K-f 34 of 36 20:25:26 20:25:26 1 none none:none
none:none
none|none
none|none
none
none
none
none
986b59708d
[Firefox:81 hits: 01-14 to 09-21]
8a00217866 [0] WinXP 29 of 29 05:36:15 05:36:15 1 none ASM:Graph
PolyEnE| 100% lines=57 trace
c05385e600
[Firefox:16 hits: 01-20 to 09-19]
6a383b021d [0] WinXP 29 of 29 15:06:31 15:06:31 1 none ASM:Graph
PolyEnE| 99% lines=68 trace
b9e6a0c882
[Firefox: 3 hits: 09-12 to 09-13]
none[none] WinXP 35 of 35 13:19:30 13:19:53 2 none none:none
none|none none none
fb1fa52455
NEW
none[none] Win2K-f 6 of 36 03:33:39 03:33:39 1 none none:none
none|none none none
0347304e75
NEW
none[none] WinXP 0 of 0 17:38:35 17:38:35 1 none none:none
none|none none none
bca9e0fb5f
[Firefox:28 hits: 06-18 to 09-20]
e53a9ea82e
[Firefox:28 hits: 06-18 to 09-20]
none[4]
e53a9ea82e[1]
Win2K-f 23 of 33 17:44:25 17:44:25 1 none none:none
ASM:Graph
PolyEnE|
Armadillo|
47% none
lines=81
trace
trace
4c3df24b32
[Firefox:188 hits: 06-17 to 09-21]
b5919931fe
[Firefox:635 hits: 06-20 to 09-22]
e2e45762bf
NEW
4c3df24b32 [1]
b5919931fe[1]
none [none]
Win2K-f 34 of 36 03:37:04 03:37:04 1 none ASM:Graph
ASM:Graph
none:none
Armadillo|
ASProtect|
none|none
lines=81
lines=90
none
trace
trace
none
d6158c8ce9
[Firefox: 3 hits: 09-21 to 09-22]
none[none] WinXP 36 of 36 08:07:01 08:07:01 1 none none:none
none|none none none
03d7e3a0df
NEW
none[none] WinXP 34 of 36 11:50:36 11:50:59 2 none none:none
none|none none none
53bfe15e91
[Firefox:2390 hits: 06-17 to 09-22]
a08f3b74a4
[Firefox:834 hits: 06-18 to 09-22]
e07c29c4ae
[Firefox:485 hits: 06-19 to 09-22]
none[4]
a08f3b74a4[1]
e07c29c4ae[1]
WinXP 0 of 33 02:36:55 22:31:03 6 none none:none
ASM:Graph
ASM:Graph
tElock|
Armadillo|
FSG|
48% none
lines=81
lines=92
trace
trace
trace
cf2dccf188
[Firefox: 2 hits: 09-16 to 09-21]
none[none] WinXP 35 of 36 08:49:19 08:49:19 1 none none:none
none|none none none
0381578ce5
NEW
none[none] Win2K-f 35 of 36 18:25:27 18:25:27 1 none none:none
none|none none none
75537c16ed
NEW
none[none] WinXP 35 of 36 04:08:24 04:08:24 1 none none:none
none|none none none
8a75955033
[Firefox:35 hits: 06-20 to 09-21]
none[4] Win2K-f 29 of 32 05:06:58 05:06:58 1 none none:none
tElock| none trace
6e2eaa0359
[Firefox: 9 hits: 07-10 to 09-18]
740e3bffe0
[Firefox:10 hits: 06-25 to 09-18]
none[none]
none [none]
WinXP 24 of 33 08:02:39 08:02:39 1 none none:none
none:none
none|none
none|none
none
none
none
none
0b951c2832
NEW
none[none] Win2K-f 32 of 36 18:14:42 18:14:42 1 none none:none
none|none none none
49d6cdaab4
[Firefox: 3 hits: 09-13 to 09-20]
none[none] WinXP 34 of 36 18:50:14 18:50:14 1 none none:none
none|none none none
3cd7958258
[Firefox:26 hits: 06-17 to 09-21]
none[4] WinXP 30 of 33 21:09:29 21:09:29 1 none none:none
tElock| none trace
c26fc3c9a3
[Firefox: 2 hits: 09-21 to 09-21]
none[none] WinXP 36 of 36 23:59:30 23:59:30 1 none none:none
none|none none none
7f60162c2c
[Firefox:611 hits: 12-31 to 09-22]
1aad8e4632 [0] WinXP 25 of 25 04:37:30 21:20:08 6 none ASM:Graph
PolyEnE| 100% lines=93
embedded dns
trace
6e2eaa0359
[Firefox: 9 hits: 07-10 to 09-18]
none[none] WinXP 31 of 33 08:02:39 08:02:39 1 none none:none
none|none none none
3cd7958258
[Firefox:26 hits: 06-17 to 09-21]
41efedf70f
[Firefox:25 hits: 06-19 to 09-21]
none[4]
41efedf70f[1]
WinXP 28 of 32 21:09:29 21:09:29 1 none none:none
ASM:Graph
tElock|
Armadillo|
47% none
lines=82
trace
trace
2e99f5a69b
NEW
ec16941838
NEW
none[none]
none [none]
WinXP 31 of 36 19:28:04 19:28:04 1 none none:none
none:none
none|none
none|none
none
none
none
none
3ae357d17b
[Firefox:174 hits: 01-01 to 09-22]
462a7be171 [0] WinXP 29 of 29 09:07:09 09:07:09 1 none ASM:Graph
PolyEnE| 99% lines=73 trace
42cd06418e
NEW
none[none] WinXP 35 of 36 13:38:20 13:38:20 1 none none:none
none|none none none
7d99b0e910
[Firefox:1141 hits: 12-31 to 09-22]
7a70e1b592 [0] WinXP 26 of 28 10:33:24 20:33:09 6 none ASM:Graph
PolyEnE| 99% lines=68 trace
73ce2b74da
[Firefox:13 hits: 06-18 to 09-21]
79c01ec060
[Firefox:40 hits: 06-18 to 09-21]
73ce2b74da [1]
none [4]
Win2K-f 33 of 33 15:24:06 15:24:06 1 none ASM:Graph
none:none
Armadillo|
tElock|
lines=81
none
trace
trace
0381578ce5
NEW
f83a14ca37
NEW
none[none]
none [none]
Win2K-f 5 of 36 18:25:27 18:25:27 1 none none:none
none:none
none|none
none|none
none
none
none
none
f48648a951
NEW
none[none] WinXP 35 of 36 19:50:02 19:50:02 1 none none:none
none|none none none
1509c8d024
[Firefox:30 hits: 06-17 to 09-22]
b5919931fe
[Firefox:635 hits: 06-20 to 09-22]
f23b040440
[Firefox:20 hits: 06-22 to 09-22]
none[4]
b5919931fe[1]
f23b040440[1]
Win2K-f 30 of 32 03:22:25 03:22:25 1 none none:none
ASM:Graph
ASM:Graph
tElock|
ASProtect|
Armadillo|
47% none
lines=90
lines=82
trace
trace
trace
ab5e47bf8d
[Firefox:39 hits: 01-02 to 09-12]
none[3] WinXP 29 of 29 20:06:52 20:06:52 1 none none:none
ASPack| none trace
1509c8d024
[Firefox:30 hits: 06-17 to 09-22]
none[4] Win2K-f 31 of 33 03:22:25 03:22:25 1 none none:none
tElock| none trace
4c3df24b32
[Firefox:188 hits: 06-17 to 09-21]
58408136a4
[Firefox:18 hits: 06-28 to 09-15]
4c3df24b32 [1]
none [none]
Win2K-f 32 of 33 07:48:29 07:48:29 1 none ASM:Graph
none:none
Armadillo|
none|none
lines=81
none
trace
none
0b951c2832
NEW
e4ed4df0f0
NEW
none[none]
none [none]
Win2K-f 34 of 36 18:14:42 18:14:42 1 none none:none
none:none
none|none
none|none
none
none
none
none