Welcome to the Cyber-TA
Daily Malware Binary DIGEST Summary Page



05 October 2008

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.



Packed
MD5
UnPacket
MD5
Victim
OS
AntiVirus
Hit-Cnt
First
Encounter
Last
Encounter
Freq
Cnt
Behavioral
Clusters
Unpacked
Egg.asm
Packer
Fingerprint
API
Resolution
String
Cnt
Syscall
Trace
da00a8e7a1
[Firefox:23 hits: 08-05 to 10-01]
f685f8e027
[Firefox:27 hits: 06-18 to 10-01]
none[none]
f685f8e027[1]
WinXP 28 of 33 22:01:00 22:01:00 1 none none:none
ASM:Graph
none|none
Armadillo|
48% none
lines=82
none
trace
7ba9e53288
[Firefox: 7 hits: 07-11 to 09-25]
none[none] WinXP 31 of 33 07:45:21 07:45:21 1 none none:none
none|none none none
3b2958417b
[Firefox:10 hits: 07-09 to 09-19]
none[none] WinXP 33 of 33 16:16:50 16:16:50 1 none none:none
none|none none none
53bfe15e91
[Firefox:2819 hits: 06-17 to 10-04]
73f1082158
[Firefox:1394 hits: 06-18 to 10-04]
none[4]
73f1082158[1]
WinXP
Win2K-f
0 of 32 01:01:31 23:18:27 16 none none:none
ASM:Graph
tElock|
Armadillo|
47% none
lines=81
trace
trace
22999be88c
[Firefox:31 hits: 04-05 to 10-04]
eda2056971 [0] WinXP 31 of 32 16:50:18 18:48:56 2 none ASM:Graph
PolyEnE| 100% lines=154
embedded dns
trace
6007d28092
NEW
none[none] WinXP 35 of 36 08:29:06 08:29:30 2 none none:none
none|none none none
4e56b449dc
NEW
none[none] Win2K-f 32 of 36 16:14:45 16:14:45 1 none none:none
none|none none none
53bfe15e91
[Firefox:2819 hits: 06-17 to 10-04]
none[4] Win2K-f
WinXP
33 of 33 00:39:36 23:43:37 38 none none:none
tElock| none trace
91990df207
NEW
b5919931fe
[Firefox:749 hits: 06-20 to 10-04]
b737716fed
NEW
none[none]
b5919931fe[1]
none [none]
Win2K-f 33 of 36 03:34:42 03:34:42 1 none none:none
ASM:Graph
none:none
none|none
ASProtect|
none|none
none
lines=90
none
none
trace
none
bb7681eca8
[Firefox: 2 hits: 09-26 to 10-04]
none[none] WinXP 32 of 32 18:09:52 18:18:02 2 none none:none
none|none none none
03f64bb952
NEW
none[none] WinXP 35 of 36 17:39:34 17:39:34 1 none none:none
none|none none none
53bfe15e91
[Firefox:2819 hits: 06-17 to 10-04]
b7082104e4
[Firefox:174 hits: 06-18 to 10-04]
none[4]
none [4]
WinXP
Win2K-f
8 of 33 04:27:09 23:43:37 6 none none:none
none:none
tElock|
tElock|
none
none
trace
trace
4bc6ee3dbb
NEW
none[none] Win2K-f 32 of 36 05:26:03 05:26:03 1 none none:none
none|none none none
47f8cf336a
[Firefox: 2 hits: 09-22 to 10-02]
none[none] WinXP 0 of 0 11:58:00 11:58:00 1 none none:none
none|none none none
168aab35a3
[Firefox:155 hits: 06-17 to 10-04]
none[4] Win2K-f 31 of 33 12:19:55 12:19:55 1 none none:none
tElock| none trace
7dc7a28625
NEW
none[none] WinXP 35 of 36 11:38:18 11:38:18 1 none none:none
none|none none none
0c390db94d
NEW
none[none] WinXP 34 of 36 21:03:08 21:03:08 1 none none:none
none|none none none
e8d4d8cde1
[Firefox:697 hits: 03-31 to 08-30]
fda109a6fd [0] WinXP
Win2K-f
13 of 31 20:27:55 21:19:25 11 none ASM:Graph
ASProtect| 64% lines=583
embedded dns
trace
9c1f1407f9
[Firefox: 4 hits: 09-30 to 10-04]
none[none] WinXP 25 of 36 12:08:06 14:59:58 2 none none:none
none|none none none
475d9a7753
[Firefox: 6 hits: 06-22 to 10-03]
none[4] WinXP 30 of 32 04:56:22 04:56:22 1 none none:none
tElock| none trace
bca9e0fb5f
[Firefox:34 hits: 06-18 to 10-02]
none[4] Win2K-f 31 of 32 18:24:40 18:24:40 1 none none:none
PolyEnE| none trace
5ea6495d3c
NEW
a12cab51ef
[Firefox:561 hits: 01-01 to 10-04]
none[none]
40f7f463c4[0]
WinXP 29 of 29 08:40:29 15:29:35 2 none none:none
ASM:Graph
none|none
ASPack|
54% none
lines=281
embedded dns
none
trace
b52d214d08
NEW
none[none] WinXP 35 of 36 07:47:08 07:47:08 1 none none:none
none|none none none
b18331c6d8
NEW
none[none] WinXP 34 of 36 04:46:47 04:46:47 1 none none:none
none|none none none
168aab35a3
[Firefox:155 hits: 06-17 to 10-04]
667f0c59f3
[Firefox:26 hits: 07-04 to 09-28]
none[4]
none [none]
Win2K-f 31 of 33 12:19:55 12:19:55 1 none none:none
none:none
tElock|
none|none
none
none
trace
none
4e56b449dc
NEW
b5919931fe
[Firefox:749 hits: 06-20 to 10-04]
cfbd74f042
NEW
none[none]
b5919931fe[1]
none [none]
Win2K-f 35 of 36 16:14:45 16:14:45 1 none none:none
ASM:Graph
none:none
none|none
ASProtect|
none|none
none
lines=90
none
none
trace
none
741e3b03b3
[Firefox:442 hits: 01-05 to 10-04]
e0197e8a64 [0] WinXP 31 of 32 08:06:17 08:06:17 1 none ASM:Graph
none|none 100% lines=62 trace
b632266bbd
[Firefox: 6 hits: 09-21 to 10-03]
none[none] WinXP 35 of 36 13:49:47 13:49:47 1 none none:none
none|none none none
831f4ee0a7
[Firefox:582 hits: 01-01 to 10-04]
eb7546c600 [0] WinXP 29 of 29 00:36:03 05:07:19 4 none ASM:Graph
none|none 100% lines=61 trace
bfdd984464
[Firefox: 2 hits: 09-13 to 09-20]
none[none] WinXP 34 of 36 17:50:54 17:50:54 1 none none:none
none|none none none
f5501ecc1c
[Firefox: 3 hits: 09-24 to 09-28]
none[none] WinXP 34 of 36 11:30:00 11:30:00 1 none none:none
none|none none none
05b1ed9c9c
[Firefox: 2 hits: 09-22 to 10-04]
0c87a74ebe
[Firefox: 2 hits: 09-22 to 10-04]
none[none]
none [none]
Win2K-f 0 of 0 01:20:40 01:20:40 1 none none:none
none:none
none|none
none|none
none
none
none
none
1513777af1
NEW
none[none] WinXP 35 of 36 10:25:40 10:25:40 1 none none:none
none|none none none
4575d9d4f6
[Firefox: 2 hits: 10-01 to 10-01]
b5919931fe
[Firefox:749 hits: 06-20 to 10-04]
none[none]
b5919931fe[1]
Win2K-f 0 of 32 01:07:36 20:18:48 11 none none:none
ASM:Graph
none|none
ASProtect|
48% none
lines=90
none
trace
53bfe15e91
[Firefox:2819 hits: 06-17 to 10-04]
57ce4acac2
[Firefox:233 hits: 06-17 to 10-04]
none[4]
57ce4acac2[1]
Win2K-f 0 of 33 00:52:38 14:02:32 2 none none:none
ASM:Graph
tElock|
Armadillo|
47% none
lines=81
trace
trace
6df1b03604
[Firefox: 2 hits: 09-14 to 09-18]
none[none] WinXP
Win2K-f
33 of 36 01:56:29 03:46:16 2 none none:none
none|none none none
8b3bea4baf
[Firefox: 2 hits: 10-03 to 10-03]
none[none] WinXP 35 of 36 04:49:15 04:49:15 1 none none:none
none|none none none
269540d8b6
NEW
none[none] WinXP 33 of 36 19:46:10 19:46:10 1 none none:none
none|none none none
1a2c0e6130
[Firefox:448 hits: 12-31 to 10-04]
048df78048 [0] WinXP 29 of 29 01:13:10 01:13:10 1 none ASM:Graph
none|none 100% lines=61 trace
53bfe15e91
[Firefox:2819 hits: 06-17 to 10-04]
a08f3b74a4
[Firefox:989 hits: 06-18 to 10-04]
none[4]
a08f3b74a4[1]
Win2K-f
WinXP
0 of 33 00:39:36 23:11:05 17 none none:none
ASM:Graph
tElock|
Armadillo|
47% none
lines=81
trace
trace
1ad17171c2
NEW
none[none] WinXP 35 of 36 10:40:55 10:40:55 1 none none:none
none|none none none
91990df207
NEW
none[none] Win2K-f 35 of 36 03:34:42 03:34:42 1 none none:none
none|none none none
b872c76081
[Firefox:43 hits: 09-13 to 10-04]
none[none] WinXP 36 of 36 01:49:45 12:22:41 4 none none:none
none|none none none
4575d9d4f6
[Firefox: 2 hits: 10-01 to 10-01]
none[none] Win2K-f 33 of 36 20:18:48 20:18:48 1 none none:none
none|none none none
0e21c47e53
NEW
none[none] WinXP 32 of 36 04:33:11 04:33:11 1 none none:none
none|none none none
09c3d90250
[Firefox:11 hits: 08-04 to 10-04]
8f34a39070
[Firefox:11 hits: 08-04 to 10-04]
none[none]
none [none]
WinXP 34 of 36 12:16:00 12:16:00 1 none none:none
none:none
none|none
none|none
none
none
none
none
a0139d7ad8
[Firefox:135 hits: 01-03 to 10-04]
d9e9662db1 [0] WinXP 29 of 29 14:34:08 14:34:08 1 none ASM:Graph
PolyEnE| 99% lines=68 trace
12e484a198
[Firefox: 4 hits: 10-01 to 10-04]
none[none] WinXP 32 of 36 11:37:41 11:37:41 1 none none:none
none|none none none
a84ffdf670
[Firefox:12 hits: 09-14 to 09-27]
none[none] WinXP 36 of 36 13:22:35 13:22:42 2 none none:none
none|none none none
c6059fcbd5
[Firefox: 2 hits: 09-23 to 09-25]
none[none] WinXP 34 of 36 08:57:37 08:57:37 1 none none:none
none|none none none
4c24bfa0ab
NEW
55a1c0f96a
NEW
none[none]
none [none]
Win2K-f 32 of 36 14:06:22 14:06:22 1 none none:none
none:none
none|none
none|none
none
none
none
none
f1d556bf4b
NEW
none[none] WinXP 33 of 36 05:36:10 14:32:39 3 none none:none
none|none none none
9086fe4014
NEW
c337e5a5cd
NEW
none[none]
none [none]
WinXP 31 of 36 11:36:40 11:36:40 1 none none:none
none:none
none|none
none|none
none
none
none
none
8a75955033
[Firefox:38 hits: 06-20 to 09-30]
9276c8b36b
[Firefox:38 hits: 06-20 to 09-30]
none[4]
9276c8b36b[1]
Win2K-f 28 of 32 20:03:06 20:03:06 1 none none:none
ASM:Graph
tElock|
Armadillo|
47% none
lines=81
trace
trace
16874933ea
[Firefox:48 hits: 06-18 to 10-01]
76ee340669
[Firefox:48 hits: 06-18 to 10-01]
16874933ea [1]
none [4]
Win2K-f 33 of 33 05:06:41 05:06:41 1 none ASM:Graph
none:none
Armadillo|
PolyEnE|
lines=82
none
trace
trace
3373948767
[Firefox:29 hits: 07-03 to 10-02]
c73f738c30
[Firefox:29 hits: 07-03 to 10-02]
none[none]
none [none]
WinXP 29 of 33 12:38:36 12:38:36 1 none none:none
none:none
none|none
none|none
none
none
none
none
df17a625ee
[Firefox:264 hits: 01-01 to 10-04]
9bbdd086c5 [0] WinXP 29 of 29 05:55:01 05:55:01 1 none ASM:Graph
ASPack| 49% lines=186
embedded dns
trace
986b59708d
[Firefox:91 hits: 01-14 to 10-04]
8a00217866 [0] WinXP 29 of 29 02:18:01 04:32:41 3 none ASM:Graph
PolyEnE| 100% lines=57 trace
c05385e600
[Firefox:20 hits: 01-20 to 10-02]
6a383b021d [0] WinXP 29 of 29 05:32:40 05:32:40 1 none ASM:Graph
PolyEnE| 99% lines=68 trace
58408136a4
[Firefox:20 hits: 06-28 to 09-30]
7655e4d162
NEW
none[none]
none [none]
WinXP 34 of 36 08:37:22 08:37:22 1 none none:none
none:none
none|none
none|none
none
none
none
none
27b945de66
[Firefox:28 hits: 06-20 to 10-04]
none[4] WinXP 31 of 32 09:04:54 09:04:54 1 none none:none
none|none none trace
12e484a198
[Firefox: 4 hits: 10-01 to 10-04]
2e43dc0077
[Firefox: 4 hits: 10-01 to 10-04]
none[none]
none [none]
WinXP 34 of 36 11:37:41 11:37:41 1 none none:none
none:none
none|none
none|none
none
none
none
none
bca9e0fb5f
[Firefox:34 hits: 06-18 to 10-02]
e53a9ea82e
[Firefox:34 hits: 06-18 to 10-02]
none[4]
e53a9ea82e[1]
Win2K-f 23 of 33 18:24:40 18:24:40 1 none none:none
ASM:Graph
PolyEnE|
Armadillo|
47% none
lines=81
trace
trace
16874933ea
[Firefox:48 hits: 06-18 to 10-01]
16874933ea [1] Win2K-f 29 of 33 05:06:41 05:06:41 1 none ASM:Graph
Armadillo| 48% lines=82 trace
6df1b03604
[Firefox: 2 hits: 09-14 to 09-18]
74fa06e356
[Firefox: 2 hits: 09-14 to 09-18]
none[none]
none [none]
WinXP
Win2K-f
34 of 36 01:56:29 03:46:16 2 none none:none
none:none
none|none
none|none
none
none
none
none
4c24bfa0ab
NEW
none[none] Win2K-f 35 of 36 14:06:22 14:06:22 1 none none:none
none|none none none
dec249f52e
NEW
none[none] Win2K-f 2 of 36 12:48:42 12:48:42 1 none none:none
none|none none none
3cd7958258
[Firefox:29 hits: 06-17 to 10-02]
41efedf70f
[Firefox:28 hits: 06-19 to 10-02]
e07c29c4ae
[Firefox:566 hits: 06-19 to 10-04]
none[4]
41efedf70f[1]
e07c29c4ae[1]
WinXP 0 of 33 01:01:31 15:49:34 5 none none:none
ASM:Graph
ASM:Graph
tElock|
Armadillo|
FSG|
48% none
lines=82
lines=92
trace
trace
trace
ef45192710
NEW
none[none] Win2K-f 12 of 36 06:23:33 06:23:33 1 none none:none
none|none none none
ca47a36342
[Firefox:13 hits: 02-16 to 10-04]
c3a58f69c6 [0] WinXP 26 of 28 13:22:46 13:22:46 1 none ASM:Graph
PolyEnE| 100% lines=89
embedded dns
trace
eca9a5fa95
[Firefox:33 hits: 08-09 to 10-04]
none[none] WinXP 36 of 36 16:13:28 16:13:28 1 none none:none
none|none none none
6e2eaa0359
[Firefox:12 hits: 07-10 to 10-03]
740e3bffe0
[Firefox:13 hits: 06-25 to 10-03]
none[none]
none [none]
WinXP
Win2K-f
24 of 33 21:35:28 22:46:47 2 none none:none
none:none
none|none
none|none
none
none
none
none
8a75955033
[Firefox:38 hits: 06-20 to 09-30]
none[4] Win2K-f 29 of 32 20:03:06 20:03:06 1 none none:none
tElock| none trace
fe22b8315f
[Firefox: 9 hits: 06-19 to 09-28]
none[4] WinXP 32 of 33 07:03:54 07:03:54 1 none none:none
StarForce| none trace
bc980dec04
NEW
none[none] WinXP 36 of 36 07:04:12 07:04:12 1 none none:none
none|none none none
3cd7958258
[Firefox:29 hits: 06-17 to 10-02]
none[4] WinXP 30 of 33 15:49:34 15:49:34 1 none none:none
tElock| none trace
4575d9d4f6
[Firefox: 2 hits: 10-01 to 10-01]
b5919931fe
[Firefox:749 hits: 06-20 to 10-04]
ed570a2e4d
NEW
none[none]
b5919931fe[1]
none [none]
Win2K-f 35 of 36 20:18:48 20:18:48 1 none none:none
ASM:Graph
none:none
none|none
ASProtect|
none|none
none
lines=90
none
none
trace
none
269540d8b6
NEW
9b272b04ec
NEW
none[none]
none [none]
WinXP 34 of 36 19:46:10 19:46:10 1 none none:none
none:none
none|none
none|none
none
none
none
none
7f60162c2c
[Firefox:674 hits: 12-31 to 10-04]
1aad8e4632 [0] WinXP 25 of 25 02:46:07 14:52:50 5 none ASM:Graph
PolyEnE| 100% lines=93
embedded dns
trace
6e2eaa0359
[Firefox:12 hits: 07-10 to 10-03]
none[none] WinXP
Win2K-f
31 of 33 21:35:28 22:46:47 2 none none:none
none|none none none
dbbc586732
[Firefox:34 hits: 07-28 to 09-19]
none[none] WinXP 35 of 35 12:18:09 12:18:09 1 none none:none
none|none none none
eb8b3d7f91
NEW
none[none] WinXP 35 of 36 08:04:34 08:04:34 1 none none:none
none|none none none
5ea6495d3c
NEW
none[none] WinXP 0 of 36 15:29:35 15:29:35 1 none none:none
none|none none none
64c0656d5e
NEW
none[none] Win2K-f 2 of 36 07:45:05 07:45:05 1 none none:none
none|none none none
632e315db2
[Firefox: 2 hits: 10-03 to 10-04]
none[none] WinXP 35 of 36 18:20:46 18:20:46 1 none none:none
none|none none none
3cd7958258
[Firefox:29 hits: 06-17 to 10-02]
41efedf70f
[Firefox:28 hits: 06-19 to 10-02]
none[4]
41efedf70f[1]
WinXP 28 of 32 15:49:34 15:49:34 1 none none:none
ASM:Graph
tElock|
Armadillo|
47% none
lines=82
trace
trace
3373948767
[Firefox:29 hits: 07-03 to 10-02]
none[none] WinXP 30 of 33 12:38:36 12:38:36 1 none none:none
none|none none none
7ba9e53288
[Firefox: 7 hits: 07-11 to 09-25]
d2e7fab9c3
[Firefox: 7 hits: 07-11 to 09-25]
none[none]
none [none]
WinXP 29 of 33 07:45:21 07:45:21 1 none none:none
none:none
none|none
none|none
none
none
none
none
82573923df
NEW
none[none] WinXP 35 of 36 10:09:49 10:10:14 2 none none:none
none|none none none
7354ff7015
NEW
none[none] WinXP 35 of 36 03:25:34 03:25:36 2 none none:none
none|none none none
da00a8e7a1
[Firefox:23 hits: 08-05 to 10-01]
none[none] WinXP 34 of 36 22:01:00 22:01:00 1 none none:none
none|none none none
790dcb2cfc
[Firefox: 3 hits: 08-06 to 09-12]
none[none] WinXP 35 of 36 23:56:42 23:56:42 1 none none:none
none|none none none
73f1082158
[Firefox:1394 hits: 06-18 to 10-04]
79c01ec060
[Firefox:50 hits: 06-18 to 10-01]
73f1082158 [1]
none [4]
WinXP 33 of 33 15:31:15 15:31:15 1 none ASM:Graph
none:none
Armadillo|
tElock|
lines=81
none
trace
trace
7d99b0e910
[Firefox:1244 hits: 12-31 to 10-04]
7a70e1b592 [0] WinXP 26 of 28 02:23:10 23:53:57 7 none ASM:Graph
PolyEnE| 99% lines=68 trace
7e8bfa9b49
NEW
none[none] WinXP 35 of 36 09:33:22 13:02:21 2 none none:none
none|none none none
470d935476
NEW
none[none] WinXP 32 of 36 19:12:25 19:12:25 1 none none:none
none|none none none
03c06c736c
NEW
none[none] WinXP 35 of 36 07:19:13 23:11:59 2 none none:none
none|none none none
a5dfa6f948
NEW
none[none] WinXP 35 of 36 12:59:28 12:59:28 1 none none:none
none|none none none
1509c8d024
[Firefox:33 hits: 06-17 to 09-28]
f23b040440
[Firefox:22 hits: 06-22 to 09-28]
none[4]
f23b040440[1]
Win2K-f 30 of 32 01:41:24 01:41:24 1 none none:none
ASM:Graph
tElock|
Armadillo|
47% none
lines=82
trace
trace
131351dd21
[Firefox:11 hits: 05-22 to 08-14]
none[4] Win2K-f 20 of 32 09:14:37 09:14:37 1 none none:none
none|none none trace
05b1ed9c9c
[Firefox: 2 hits: 09-22 to 10-04]
none[none] Win2K-f 0 of 0 01:20:40 01:20:40 1 none none:none
none|none none none
d9a4f2f314
[Firefox: 3 hits: 09-29 to 10-04]
none[none] WinXP 35 of 36 00:25:28 00:25:52 2 none none:none
none|none none none
1509c8d024
[Firefox:33 hits: 06-17 to 09-28]
none[4] Win2K-f 31 of 33 01:41:24 01:41:24 1 none none:none
tElock| none trace
09c3d90250
[Firefox:11 hits: 08-04 to 10-04]
none[none] WinXP 32 of 36 12:16:00 12:16:00 1 none none:none
none|none none none
cdf8cd94a9
[Firefox:19 hits: 09-14 to 10-04]
none[none] WinXP 35 of 36 11:30:38 11:30:38 1 none none:none
none|none none none
63ad1757f8
NEW
none[none] WinXP 35 of 36 12:32:56 12:35:38 2 none none:none
none|none none none
0e21c47e53
NEW
607b60ad51
[Firefox:40 hits: 06-20 to 10-03]
none[none]
none [4]
WinXP 31 of 32 04:33:11 04:33:11 1 none none:none
none:none
none|none
tElock|
none
none
none
trace
58408136a4
[Firefox:20 hits: 06-28 to 09-30]
none[none] WinXP 32 of 33 08:37:22 08:37:22 1 none none:none
none|none none none
e98a5fa83f
NEW
none[none] WinXP 36 of 36 14:51:01 14:51:01 1 none none:none
none|none none none
9086fe4014
NEW
none[none] WinXP 21 of 36 11:36:40 11:36:40 1 none none:none
none|none none none
475d9a7753
[Firefox: 6 hits: 06-22 to 10-03]
e9a7fa27d5
[Firefox: 6 hits: 06-22 to 10-03]
none[4]
e9a7fa27d5[1]
WinXP 30 of 32 04:56:22 04:56:22 1 none none:none
ASM:Graph
tElock|
Armadillo|
47% none
lines=82
trace
trace
7bff4f7b36
NEW
none[none] WinXP 36 of 36 09:29:03 09:29:03 1 none none:none
none|none none none