Welcome to the Cyber-TA
Daily Malware Binary DIGEST Summary Page



15 December 2008

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.



Packed
MD5
UnPacket
MD5
Victim
OS
AntiVirus
Hit-Cnt
First
Encounter
Last
Encounter
Freq
Cnt
Behavioral
Clusters
Unpacked
Egg.asm
Packer
Fingerprint
API
Resolution
String
Cnt
Syscall
Trace
409ef22885
[Firefox:512 hits: 11-22 to 12-14]
none[3] Win2K-f 2 of 37 00:12:31 22:48:31 21 none none:none
UPX| none trace
7f60162c2c
[Firefox:710 hits: 05-01 to 11-25]
none[0] WinXP 25 of 25 19:10:07 19:14:02 2 none none:none
PolyEnE| 100% lines=93
embedded dns
trace
3862324588
[Firefox:41 hits: 11-29 to 12-14]
none[3] Win2K-f 7 of 37 05:07:31 23:38:34 7 none none:none
UPX| none trace
776985f561
[Firefox:24 hits: 06-24 to 11-16]
none[0] WinXP 31 of 33 00:13:07 00:13:07 1 none none:none
Armadillo| 0% lines=91 trace
fcb4920986
[Firefox:21 hits: 11-21 to 12-14]
none[3] Win2K-f 2 of 37 11:11:42 22:01:34 4 none none:none
UPX| none trace
dc331fb791
[Firefox:557 hits: 11-24 to 12-14]
none[3] Win2K-f 3 of 37 00:07:29 21:51:56 42 none none:none
UPX| none trace
53bfe15e91
[Firefox:4105 hits: 06-17 to 12-10]
1473091351 [0] Win2K-f 33 of 33 11:01:36 11:01:36 1 none ASM:Graph
tElock| 96% lines=75
embedded dns
trace
bd35d4d98f
[Firefox:21 hits: 11-27 to 12-14]
none[3] Win2K-f 7 of 37 23:54:52 23:54:52 1 none none:none
Armadillo| none trace
917c085aca
[Firefox:168 hits: 11-25 to 12-14]
none[3] Win2K-f 3 of 37 01:03:17 21:57:15 8 none none:none
Armadillo| none trace
53bfe15e91
[Firefox:4105 hits: 06-17 to 12-10]
b7082104e4
[Firefox:276 hits: 06-18 to 11-19]
1473091351 [0]
c5b49e7b82[0]
Win2K-f 8 of 33 11:01:36 11:01:36 1 none ASM:Graph
ASM:Graph
tElock|
tElock|
100% lines=75
embedded dns
lines=41
trace
trace
06a5e31b47
[Firefox:17 hits: 10-28 to 11-19]
25e6e52787 [0] WinXP 35 of 36 09:17:09 09:17:09 1 none ASM:Graph
PolyEnE| 100% lines=68 trace
786c3bb507
NEW
94be146dcd [0] WinXP 34 of 36 22:04:41 22:04:41 1 none ASM:Graph
PolyEnE| 100% lines=68 trace
c50e298b27
[Firefox:21 hits: 10-26 to 11-16]
d4f96746b1 [0] WinXP 33 of 34 01:36:57 01:36:57 1 none ASM:Graph
NsPacK| 80% lines=3137
embedded dns
trace
8ce32ded17
[Firefox:74 hits: 11-26 to 12-14]
none[3] Win2K-f 4 of 37 04:45:31 13:11:17 6 none none:none
Armadillo| none trace
96d089e522
[Firefox:88 hits: 10-08 to 12-05]
b9dd25bdfb [0] WinXP 34 of 36 12:07:50 12:07:50 1 none ASM:Graph
PolyEnE| 100% lines=93
embedded dns
trace
4f88618d4f
[Firefox:40 hits: 11-29 to 12-14]
none[3] Win2K-f 8 of 37 07:38:07 19:16:40 4 none none:none
UPX| none trace
776985f561
[Firefox:24 hits: 06-24 to 11-16]
8ec6129efe
[Firefox:29 hits: 06-24 to 11-16]
none[0]
d3b0e700c7[0]
WinXP 31 of 33 00:13:07 00:13:07 1 none none:none
ASM:Graph
Armadillo|
tElock|
95% lines=91
lines=120
embedded dns
trace
trace
7587773eea
[Firefox:291 hits: 11-30 to 12-14]
none[3] Win2K-f 7 of 37 02:29:36 23:44:48 34 none none:none
StarForce| none trace
223d8089f8
[Firefox:371 hits: 11-21 to 12-14]
none[3] Win2K-f 2 of 37 00:18:26 16:03:38 9 none none:none
StarForce| none trace
216ec67841
[Firefox:93 hits: 11-20 to 12-14]
none[3] Win2K-f 2 of 37 07:44:20 21:00:15 4 none none:none
StarForce| none trace
d60e538e72
[Firefox:1063 hits: 11-22 to 12-14]
none[3] Win2K-f 2 of 37 00:41:41 23:19:48 31 none none:none
UPX| none trace
13e15a653e
[Firefox:30 hits: 11-21 to 12-12]
none[3] Win2K-f 6 of 37 00:20:36 09:12:31 2 none none:none
UPX| none trace
d9cb288f31
[Firefox:8422 hits: 11-20 to 12-14]
45603a001c [0] Win2K-f 3 of 37 00:11:41 23:59:49 343 none ASM:Graph
UPX| 92% lines=174
embedded dns
trace