Welcome to the Cyber-TA
Daily Malware Binary DIGEST Summary Page



18 June 2009

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.



Packed
MD5
UnPacket
MD5
Victim
OS
AntiVirus
Hit-Cnt
First
Encounter
Last
Encounter
Freq
Cnt
Behavioral
Clusters
Unpacked
Egg.asm
Packer
Fingerprint
API
Resolution
String
Cnt
Syscall
Trace
d2b40c91a1
NEW
fbaa414397 [0] Win2K-f 37 of 41 17:21:58 17:21:58 1 none none:none
Armadillo| none trace
2778910f2e
NEW
c0081ab98f [0] Win2K-f 34 of 36 23:40:44 23:40:44 1 none none:none
PolyEnE| none trace
7bc8d57d8c
NEW
ca557e7460
NEW
def0132311
NEW
be025ab204 [0]
42d57774ef[0]
7a31307d90[0]
WinXP 25 of 41 05:59:10 05:59:10 1 none none:none
none:none
none:none
none|none
none|none
ASProtect|
none
none
none
trace
trace
trace
20f346512b
NEW
90419de3ae [0] Win2K-f
WinXP
2 of 41 02:29:21 13:10:55 4 none none:none
StarForce| none trace
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
Win2K-f
WinXP
0 of 32 05:23:46 18:21:38 5 none ASM:Graph
none:none
tElock|
Armadillo|
0% lines=75
embedded dns
lines=90
trace
trace
dc331fb791
NEW
none[3] Win2K-f 3 of 37 10:38:30 18:42:42 4 none none:none
UPX| none trace
0658d04f28
NEW
07f788a60e [0] WinXP 38 of 40 23:36:43 23:36:43 1 none none:none
PolyEnE| none trace
53bfe15e91
NEW
1473091351 [0] Win2K-f
WinXP
33 of 33 01:37:11 18:21:38 11 none ASM:Graph
tElock| 96% lines=75
embedded dns
trace
20f346512b
NEW
31a7f4355c
NEW
6bce6d0b9e
NEW
8f8299cae5
NEW
90419de3ae [0]
f311468a65[0]
9faaf38f58[0]
790d80ae6d[0]
WinXP 3 of 41 06:18:01 13:10:55 3 none none:none
none:none
none:none
none:none
StarForce|
StarForce|
StarForce|
StarForce|
none
none
none
none
trace
trace
trace
trace
917c085aca
NEW
none[3] Win2K-f 3 of 37 03:38:49 08:27:42 3 none none:none
Armadillo| none trace
c2755e5248
NEW
df17a625ee
NEW
none[4]
none [0]
WinXP 29 of 29 21:06:41 21:06:41 1 none none:none
none:none
none|none
ASPack|
72% none
lines=298
embedded dns
trace
trace
20f346512b
NEW
31a7f4355c
NEW
6bce6d0b9e
NEW
8f8299cae5
NEW
b3a8d7fa5a
NEW
90419de3ae [0]
f311468a65[0]
9faaf38f58[0]
790d80ae6d[0]
b5922da65f[0]
WinXP 39 of 41 13:10:55 13:10:55 1 none none:none
none:none
none:none
none:none
none:none
StarForce|
StarForce|
StarForce|
StarForce|
PolyEnE|
none
none
none
none
none
trace
trace
trace
trace
trace
20f346512b
NEW
533d15b5ce
NEW
58c343a8d8
NEW
d3305754f6
NEW
eefb6d217d
NEW
90419de3ae [0]
c67adf46e2[0]
none [0]
c692d7d45e[0]
230036ecf3[0]
Win2K-f 27 of 41 02:29:21 02:29:21 1 none none:none
ASM:Graph
none:none
none:none
ASM:Graph
StarForce|
tElock|
Armadillo|
Armadillo|
StarForce|
100% none
lines=126
embedded dns
lines=91
none
lines=6
trace
trace
trace
trace
trace
20f346512b
NEW
31a7f4355c
NEW
6bce6d0b9e
NEW
8f8299cae5
NEW
b3a8d7fa5a
NEW
bc8b9443ab
NEW
bfde2797a4
NEW
e0d9f6d426
NEW
90419de3ae [0]
f311468a65[0]
9faaf38f58[0]
790d80ae6d[0]
b5922da65f[0]
c692d7d45e[0]
none [4]
c7b6d8d1db[0]
WinXP 10 of 40 06:18:01 13:10:55 3 none none:none
none:none
none:none
none:none
none:none
none:none
none:none
none:none
StarForce|
StarForce|
StarForce|
StarForce|
PolyEnE|
Armadillo|
Mew|
ASPack|
none
none
none
none
none
none
none
none
trace
trace
trace
trace
trace
trace
trace
trace
2d16d63f91
NEW
27cb26ee14 [0] WinXP 38 of 41 06:02:22 06:02:22 1 none none:none
PolyEnE| none trace
20f346512b
NEW
8ce5938195
NEW
8f8299cae5
NEW
c2eecd2b27
NEW
90419de3ae [0]
1e1dbc3230[0]
790d80ae6d[0]
9faaf38f58[0]
WinXP 13 of 40 06:18:01 06:18:01 1 none none:none
none:none
none:none
none:none
StarForce|
none|none
StarForce|
StarForce|
none
none
none
none
trace
trace
trace
trace
1987904b12
NEW
9fd17c99f9 [0] WinXP 35 of 37 05:39:57 05:39:57 1 none ASM:Graph
PolyEnE| 100% lines=68 trace
38ed850a0e
NEW
46990f37cd [0] Win2K-f 34 of 38 17:14:26 17:14:26 1 none ASM:Graph
Armadillo| 0% lines=91 trace
20f346512b
NEW
533d15b5ce
NEW
90419de3ae [0]
c67adf46e2[0]
Win2K-f 30 of 33 02:29:21 02:29:21 1 none none:none
ASM:Graph
StarForce|
tElock|
96% none
lines=126
embedded dns
trace
trace
a12cab51ef
NEW
none[0] WinXP 29 of 29 13:44:57 13:44:57 1 none none:none
ASPack| 54% lines=281
embedded dns
trace
f502585714
NEW
none[0] WinXP 29 of 29 15:06:21 15:06:21 1 none none:none
PolyEnE| 100% lines=63 trace
d60e538e72
NEW
none[3] Win2K-f 2 of 37 04:32:54 22:33:43 2 none none:none
UPX| none trace
f5114d3371
NEW
330af0d74b [0] Win2K-f 36 of 39 20:23:32 20:23:32 1 none none:none
StarForce| none trace
c392067a90
NEW
d83160e550 [0] WinXP 35 of 36 19:41:25 19:41:25 1 none none:none
PolyEnE| none trace
20f346512b
NEW
31a7f4355c
NEW
6bce6d0b9e
NEW
8f8299cae5
NEW
bf52cc656a
NEW
bfde2797a4
NEW
dab4da4e21
NEW
90419de3ae [0]
f311468a65[0]
9faaf38f58[0]
790d80ae6d[0]
c692d7d45e[0]
none [4]
e63b813015[0]
WinXP 37 of 39 11:39:27 11:39:27 1 none none:none
none:none
none:none
none:none
none:none
none:none
ASM:Graph
StarForce|
StarForce|
StarForce|
StarForce|
Armadillo|
Mew|
PolyEnE|
100% none
none
none
none
none
none
lines=134
trace
trace
trace
trace
trace
trace
trace
4c3df24b32
NEW
none[0] Win2K-f 0 of 33 01:37:11 01:37:11 1 none ASM:Graph
Armadillo| 47% lines=81 trace
741e3b03b3
NEW
none[0] WinXP 31 of 32 03:24:34 03:24:34 1 none none:none
none|none 32% lines=61 trace
20f346512b
NEW
31a7f4355c
NEW
90419de3ae [0]
f311468a65[0]
WinXP 11 of 39 11:39:27 13:10:55 2 none none:none
none:none
StarForce|
StarForce|
none
none
trace
trace
20f346512b
NEW
31a7f4355c
NEW
6bce6d0b9e
NEW
8f8299cae5
NEW
bf52cc656a
NEW
90419de3ae [0]
f311468a65[0]
9faaf38f58[0]
790d80ae6d[0]
c692d7d45e[0]
WinXP 7 of 41 11:39:27 11:39:27 1 none none:none
none:none
none:none
none:none
none:none
StarForce|
StarForce|
StarForce|
StarForce|
Armadillo|
none
none
none
none
none
trace
trace
trace
trace
trace
7bc8d57d8c
NEW
be025ab204 [0] WinXP 38 of 40 05:59:10 05:59:10 1 none none:none
none|none none trace
20f346512b
NEW
533d15b5ce
NEW
58c343a8d8
NEW
90419de3ae [0]
c67adf46e2[0]
none [0]
Win2K-f 28 of 33 02:29:21 02:29:21 1 none none:none
ASM:Graph
none:none
StarForce|
tElock|
Armadillo|
0% none
lines=126
embedded dns
lines=91
trace
trace
trace
20f346512b
NEW
533d15b5ce
NEW
58c343a8d8
NEW
d3305754f6
NEW
eefb6d217d
NEW
f1bb8174e3
NEW
90419de3ae [0]
c67adf46e2[0]
none [0]
c692d7d45e[0]
230036ecf3[0]
ff7d442dd1[0]
Win2K-f 24 of 40 02:29:21 02:29:21 1 none none:none
ASM:Graph
none:none
none:none
ASM:Graph
none:none
StarForce|
tElock|
Armadillo|
Armadillo|
StarForce|
none|none
none
lines=126
embedded dns
lines=91
none
lines=6
none
trace
trace
trace
trace
trace
trace
cdbb312d0a
NEW
8050e5ba3e [0] WinXP 38 of 40 01:25:15 02:00:18 2 none none:none
PolyEnE| none trace
20f346512b
NEW
31a7f4355c
NEW
6bce6d0b9e
NEW
90419de3ae [0]
f311468a65[0]
9faaf38f58[0]
WinXP 9 of 40 11:39:27 13:10:55 2 none none:none
none:none
none:none
StarForce|
StarForce|
StarForce|
none
none
none
trace
trace
trace
0658d04f28
NEW
bfde2797a4
NEW
f37b5a8f0c
NEW
07f788a60e [0]
none [4]
dce19a471e[0]
Win2K-f
WinXP
19 of 40 02:29:21 23:36:43 7 none none:none
none:none
none:none
PolyEnE|
Mew|
none|none
none
none
none
trace
trace
trace
47689cd2e0
NEW
349cf82a2d [0] WinXP 38 of 41 14:45:37 14:45:37 1 none none:none
PolyEnE| none trace
20f346512b
NEW
31a7f4355c
NEW
6bce6d0b9e
NEW
8f8299cae5
NEW
b3a8d7fa5a
NEW
bc8b9443ab
NEW
90419de3ae [0]
f311468a65[0]
9faaf38f58[0]
790d80ae6d[0]
b5922da65f[0]
c692d7d45e[0]
WinXP 7 of 40 13:10:55 13:10:55 1 none none:none
none:none
none:none
none:none
none:none
none:none
StarForce|
StarForce|
StarForce|
StarForce|
PolyEnE|
Armadillo|
none
none
none
none
none
none
trace
trace
trace
trace
trace
trace
20f346512b
NEW
8ce5938195
NEW
90419de3ae [0]
1e1dbc3230[0]
WinXP 27 of 41 06:18:01 06:18:01 1 none none:none
none:none
StarForce|
none|none
none
none
trace
trace
1a2c0e6130
NEW
none[0] WinXP 29 of 29 10:04:48 11:58:34 2 none none:none
none|none 33% lines=60 trace
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
WinXP
Win2K-f
0 of 33 05:26:52 17:53:08 5 none ASM:Graph
none:none
tElock|
Armadillo|
0% lines=75
embedded dns
lines=90
trace
trace
b27d73bfcb
NEW
473c6454ce [0] WinXP 35 of 36 04:40:03 21:13:20 3 none ASM:Graph
PolyEnE| 100% lines=68 trace
7bc8d57d8c
NEW
ca557e7460
NEW
be025ab204 [0]
42d57774ef[0]
WinXP 12 of 30 05:59:10 05:59:10 1 none none:none
none:none
none|none
none|none
none
none
trace
trace
10980f4df2
NEW
1fd3385a95 [0] WinXP 39 of 40 12:10:40 12:10:40 1 none ASM:Graph
none|none 97% lines=556 trace
223d8089f8
NEW
none[3] Win2K-f 2 of 37 06:28:32 06:28:32 1 none none:none
StarForce| none trace
38ed850a0e
NEW
b9297745a1
NEW
46990f37cd [0]
4294884d84[0]
Win2K-f 35 of 38 17:14:26 17:14:26 1 none ASM:Graph
ASM:Graph
Armadillo|
tElock|
96% lines=91
lines=64
embedded dns
trace
trace
0658d04f28
NEW
bfde2797a4
NEW
07f788a60e [0]
none [4]
WinXP 10 of 41 11:39:27 23:36:43 3 none none:none
none:none
PolyEnE|
Mew|
none
none
trace
trace
20f346512b
NEW
533d15b5ce
NEW
58c343a8d8
NEW
d3305754f6
NEW
90419de3ae [0]
c67adf46e2[0]
none [0]
c692d7d45e[0]
Win2K-f 11 of 41 02:29:21 02:29:21 1 none none:none
ASM:Graph
none:none
none:none
StarForce|
tElock|
Armadillo|
Armadillo|
none
lines=126
embedded dns
lines=91
none
trace
trace
trace
trace
2778910f2e
NEW
7f3f6fd066
NEW
c0081ab98f [0]
b493126b1e[0]
Win2K-f 32 of 36 23:40:44 23:40:44 1 none none:none
none:none
PolyEnE|
Armadillo|
none
none
trace
trace
c2755e5248
NEW
none[4] WinXP 0 of 41 21:06:41 21:06:41 1 none none:none
none|none none trace
330eaa2da2
NEW
none[3] WinXP 28 of 29 03:05:27 03:05:27 1 none none:none
ASPack| none trace
d9cb288f31
NEW
45603a001c [0] Win2K-f 3 of 37 01:22:56 19:19:32 10 none ASM:Graph
UPX| 92% lines=174
embedded dns
trace