Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

08 July 2009
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
T:03:12:00 Win2K-f 117.241.168.66 (-):
.
n/a CZ:qtas.net
CZ:t32.marund.net
CZ:82.114.87.44:2345
445 pcap raw alerts
ruleset
http
35 lines
Yeah : 0.8
profile
none summary
tarball
23 of 41 ba1647d9b9
NEW
e3aa6ee0ce [0] none:none
MingWin32| none trace
T:03:32:00 Win2K-f 172.130.157.79 (AOL.COM):
AMERICA ONLINE,
RESTON, VIRGINIA, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:04:23:00 WinXP 62.103.231.30 (OTENET.GR):
MULTIPROTOCOL SERVICE PROVIDER TO OTHER ISP'S AND END USERS,
ATHENS, ATTIKI, GR. (DIAL)
n/a   445 pcap raw alerts
ruleset
ftp
13 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 831f4ee0a7
NEW
none[0] ASM:Graph
none|none lines=61 trace
T:05:10:00 WinXP 77.54.152.94 (REV.VODAFONE.PT):
VODAFONE TELECEL COMUNICACOES PESSOAIS SA,
PT.
n/a RU:citi-bank.ru
RU:213.219.245.212:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
32 of 32 21cc05003b
NEW
6776bccc2d [0] none:none
PolyEnE| none trace
T:06:29:00 Win2K-f 65.161.116.101 (PINEBELT.NET):
PINE BELT TELEPHONE CO,
SWEET WATER, ALABAMA, US.
n/a   135 pcap raw alerts
ruleset
other
73 lines
Yeah : 1.3
profile
none summary
tarball
0 of 33 a08f3b74a4
NEW
none[0] none:none
Armadillo| lines=90 trace
06:41:00 Win2K-f 174.142.28.220 (-):
.
n/a US:www.maxmind.com
US:checkip.dyndns.org
US:67.15.94.80:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:08:18:00 WinXP 119.56.69.16 (-):
.
n/a CN:irc.zief.pl
RU:citi-bank.ru
RU:213.219.245.212:80
445 pcap raw alerts
ruleset
http
irc
3 lines
Yeah : 0.8
profile
none summary
tarball
36 of 41 e22c85789a
NEW
e067fb641c [0] none:none
PolyEnE| none trace
T:08:51:00 WinXP 99.191.230.152 (-):
.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 1a2c0e6130
NEW
none[0] none:none
none|none lines=60 trace
T:09:39:00 WinXP 116.58.157.246 (CCNETMIE.NE.JP):
C-TECH CORPORATION,
NAGOYA, AICHI, JP.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
0 of 32
33 of 33
07fabc79ef
NEW
53bfe15e91
NEW
none[0]
1473091351[0]
ASM:Graph
ASM:Graph
Armadillo|
tElock|
lines=81
lines=75
embedded dns
trace
trace
T:10:30:00 WinXP 82.249.60.34 (PROXAD.NET):
PROXAD / FREE SAS,
NICE, PROVENCE-ALPES-COTE D'AZUR, FR. (DSL)
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
39 of 41 44674d8336
NEW
db25d2301e [0] none:none
PolyEnE| none trace
T:11:40:00 WinXP 67.150.87.107 (MDSG-PACWEST.COM):
PAC-WEST MANAGED MODEM NAS POOL,
LOS ANGELES, CALIFORNIA, US.
n/a EU:siliconfireware.ru
US:searchportal.information.com
US:spi.domainsponsor.com
RU:www.bbin.ru
RU:www.binbank.ru
:wpad
445 pcap raw alerts
ruleset
http
http
http
27 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 a12cab51ef
NEW
none[0] none:none
ASPack| lines=281
embedded dns
trace
T:13:05:00 WinXP 70.241.96.38 (SWBELL.NET):
PPPOX POOL - RBACK21 HSTNTX,
HOUSTON, TEXAS, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
13:19:00 Win2K-f 150.101.191.12 (ON.NET):
TPA,
BRISBANE, QUEENSLAND, AU. (DSL)
n/a US:www.maxmind.com
US:getmyip.co.uk
EU:checkip.dyndns.org
US:www.getmyip.org
US:65.254.39.170:80
US:67.15.94.80:80
US:75.126.138.202:80
EU:91.198.22.70:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:14:01:00 WinXP 75.50.249.249 (SBCGLOBAL.NET):
PPPOX POOL - RBACK6.MILWWI,
MILWAUKEE, WISCONSIN, US. (DSL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
32 of 32 03f912899b
NEW
none[0] none:none
none|none lines=64 trace
T:14:10:00 WinXP 189.75.227.242 (-):
.
213.219.245.212:80 CN:irc.zief.pl
RU:citi-bank.ru
445 pcap raw alerts
ruleset
http
6 lines
Yeah : 1.3
profile
none summary
tarball
35 of 41 2f17035ddc
NEW
56039b0c0e [0] none:none
Mew| none trace
T:14:40:00 WinXP 115.82.231.85 (-):
.
n/a   135 pcap raw alerts
ruleset
other
337 lines
Yeah : 1.3
profile
none summary
tarball
32 of 36 963d5f92ac
NEW
b851ccde4f [0] none:none
FASM| none trace
14:47:00 Win2K-f 190.224.185.101 (-):
.
n/a US:www.maxmind.com
US:getmyip.co.uk
US:www.getmyip.org
:checkip.dyndns.org
US:65.254.39.170:80
US:67.15.94.80:80
EU:91.198.22.70:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
8 of 37 4f88618d4f
NEW
none[3] none:none
UPX| none trace
T:15:32:00 Win2K-f 63.25.29.148 (UU.NET):
UUNET TECHNOLOGIES INC,
US.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
184 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:16:33:00 WinXP 69.63.5.45 (SOUTHSLOPE.NET):
SOUTH SLOPE COOPERATIVE TELEPHONE,
NORTH LIBERTY, IOWA, US. (DSL)
n/a :moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
39 of 41 534ccf8cdb
NEW
4473c170f3 [0] none:none
PolyEnE| none trace
T:16:46:00 WinXP 96.48.246.20 (-):
.
n/a DE:siliconfireware.ru
US:searchportal.information.com
US:spi.domainsponsor.com
GB:new.egg.com
:wpad
445 pcap raw alerts
ruleset
http
http
http
29 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 a12cab51ef
NEW
none[0] none:none
ASPack| lines=281
embedded dns
trace
T:17:17:00 WinXP 200.227.133.184 (STERLINGSTUDENTS.NET):
COMITE GESTOR DA INTERNET NO BRASIL,
BR. (DSL)
n/a DE:siliconfireware.ru
US:searchportal.information.com
US:spi.domainsponsor.com
GB:welcome3.smile.co.uk
:wpad
GB:195.92.84.198:80
445 pcap raw alerts
ruleset
http
http
http
30 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 a12cab51ef
NEW
none[0] none:none
ASPack| lines=281
embedded dns
trace
T:17:24:00 Win2K-f 98.140.249.72 (-):
.
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:17:34:00 WinXP 4.138.50.51 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
WEAVERVILLE, NORTH CAROLINA, US. (DIAL)
n/a   135 pcap raw alerts
ruleset
other
147 lines
Yeah : 1.3
profile
none summary
tarball
36 of 41 dfb19bde14
NEW
7d7d4ab834 [0] none:none
Armadillo| none trace
T:18:02:00 WinXP 76.77.231.246 (MADISONTELCO.COM):
MADISON TELEPHONE COMPANY,
HAMEL, ILLINOIS, US.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:18:32:00 WinXP 67.246.224.167 (-):
.
n/a DE:siliconfireware.ru
US:searchportal.information.com
US:spi.domainsponsor.com
GB:new.egg.com
:wpad
DE:217.11.54.126:80
EU:78.47.200.154:80
445 pcap raw alerts
ruleset
http
http
http
38 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 a12cab51ef
NEW
none[0] none:none
ASPack| lines=281
embedded dns
trace
T:19:14:00 WinXP 202.125.63.222 (CTT.NE.JP):
CABLE TELEVISION TOYAMA INCORPORETED,
TOKYO, TOKYO, JP.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
32 of 32 03f912899b
NEW
none[0] none:none
none|none lines=64 trace
T:20:23:00 WinXP 67.10.221.190 (RR.COM):
ROAD RUNNER HOLDCO LLC,
SUGAR LAND, TEXAS, US.
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 d6df3972a0
NEW
none[0] ASM:Graph
PolyEnE| lines=65 trace
T:20:27:00 Win2K-f 61.89.230.204 (SENSYU.NE.JP):
SNS,
KISHIWADA, MIYAGI, JP.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
79 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
20:49:00 Win2K-f 218.91.232.68 (-):
NANTONG FIRE BRIGADE OF PUBLIC SECURITY BUREAU,
NANJING, JIANGSU, CN. (100Mbps)
n/a US:www.maxmind.com
:checkip.dyndns.org
US:getmyip.co.uk
US:www.getmyip.org
US:65.254.39.170:80
US:67.15.94.80:80
EU:91.198.22.70:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
7 of 37 bd35d4d98f
NEW
none[3] none:none
Armadillo| none trace
T:21:16:00 WinXP 71.111.12.252 (VERIZON.NET):
VERIZON INTERNET SERVICES INC,
GRESHAM, OREGON, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
1009 lines
Yeah : 1.3
profile
none summary
tarball
10 of 40 10ffaa9d33
NEW
none[3] none:none
none|none none trace
21:37:00 Win2K-f 85.21.30.238 (CORBINA.NET):
CORBINA-MORBEZ,
RU. (100Mbps)
n/a US:www.maxmind.com
US:getmyip.co.uk
US:www.getmyip.org
US:checkip.dyndns.org
US:65.254.39.170:80
US:67.15.94.80:80
US:75.126.138.202:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:22:01:00 WinXP 114.48.92.200 (-):
.
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
37 of 40 5285741560
NEW
60590b8b67 [0] ASM:Graph
none|none lines=59 trace
T:23:02:00 Win2K-f 24.103.196.250 (-):
.
67.43.236.66:10324 :xx.enterhere.biz
CA:xx.nadnadzz.info
:nadsamcabran12.com
67.215.1.206:80
135 pcap raw alerts
ruleset
irc
340 lines
Yeah : 1.8
profile
none summary
tarball
37 of 40 a0a15f5ebf
NEW
c506c7cc86 [0] none:none
Mew| none trace