Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

21 July 2009
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
T:00:05:00 Win2K-f 216.74.194.90 (ILAND.NET):
IMAGINATION INC,
KNOB NOSTER, MISSOURI, US.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
39 of 41
38 of 41
c3940285fd
NEW
f69c164193
NEW
de206a939d [0]
404635142d[0]
none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
T:01:37:00 WinXP 124.66.248.249 (FCH.NE.JP):
FUREAI CHANNEL INC,
HIROSHIMA, HIROSHIMA, JP.
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
41 of 41 a769511504
NEW
7ecd054f18 [0] none:none
PolyEnE| none trace
T:01:48:00 Win2K-f 24.164.58.84 (RR.COM):
ROAD RUNNER HOLDCO LLC,
LAKELAND, FLORIDA, US.
n/a   135 pcap raw alerts
ruleset
other
10 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:01:57:00 WinXP 62.253.84.45 (NTLI.NET):
NTL INTERNET,
LONDON, ENGLAND, UK. (DIAL)
n/a   445 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 1a2c0e6130
NEW
none[0] none:none
none|none lines=60 trace
T:02:12:00 WinXP 66.63.109.240 (GWI.NET):
GREAT WORKS INTERNET,
SHAPLEIGH, MAINE, US.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
59 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
8 of 33
53bfe15e91
NEW
b7082104e4
NEW
1473091351 [0]
c5b49e7b82[0]
ASM:Graph
ASM:Graph
tElock|
tElock|
lines=75
embedded dns
lines=41
trace
trace
T:02:20:00 WinXP 93.81.205.64 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 1a2c0e6130
NEW
none[0] none:none
none|none lines=60 trace
T:02:43:00 WinXP 71.120.69.120 (VERIZON.NET):
VERIZON INTERNET SERVICES INC,
BLOOMINGTON, ILLINOIS, US.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
02:43:00 Win2K-f 195.22.21.71 (CLARA.NET):
VIA NET.WORKS PORTUGAL - TECNOLOGIAS DE INFORMA CAO SA,
PT.
n/a US:www.maxmind.com
US:getmyip.co.uk
US:www.getmyip.org
EU:checkip.dyndns.org
208.78.69.70:80
US:65.254.39.170:80
US:67.15.94.80:80
US:75.126.138.202:80
139 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:02:47:00 Win2K-f 195.22.21.71 (CLARA.NET):
VIA NET.WORKS PORTUGAL - TECNOLOGIAS DE INFORMA CAO SA,
PT.
n/a US:www.maxmind.com
US:www.getmyip.org
:checkip.dyndns.org
445 pcap raw alerts
ruleset
http
5 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:03:07:00 Win2K-f 4.152.159.31 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
NASHVILLE, TENNESSEE, US. (DIAL)
n/a   135 pcap raw alerts
ruleset
other
603 lines
Yeah : 1.3
profile
none summary
tarball
36 of 41 83f6cb959d
NEW
445f56b6dd [0] none:none
StarForce| none trace
T:04:45:00 WinXP 119.230.42.29 (-):
.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
32 of 32 03f912899b
NEW
none[0] none:none
none|none lines=64 trace
T:04:53:00 Win2K-f 70.187.6.37 (COX.NET):
COX COMMUNICATIONS,
OMAHA, NEBRASKA, US.
218.93.205.24:65520 US:microsoft.com
CN:proxim.ircgalaxy.pl
CN:put.ghura.pl
CN:brenz.pl
CN:211.95.79.6:80
135 pcap raw alerts
ruleset
irc
http
120 lines
Yeah : 1.8
profile
none summary
tarball
15 of 41
32 of 36
35 of 36
298243013a
NEW
bea8cb1865
NEW
fac78fde16
NEW
b8c969e769 [0]
154de51a66[0]
882896ab05[0]
none:none
ASM:Graph
none:none
PEQuake|
Armadillo|
tElock|
none
lines=91
none
trace
trace
trace
T:05:02:00 WinXP 41.202.180.20 (-):
.
n/a :moscow-advokat.ru
SE:vancouver.dal.net
SE:coins.dal.net
:brussels.be.eu.undernet.org
SE:broadway.ny.us.dal.net
:los-angeles.ca.us.undernet.org
SE:viking.dal.net
AT:graz.at.eu.undernet.org
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
39 of 41 7f7647d18e
NEW
a81fd64562 [0] none:none
PolyEnE| none trace
T:10:00:00 WinXP 24.175.157.178 (RR.COM):
ROAD RUNNER HOLDCO LLC,
DEATSVILLE, ALABAMA, US.
n/a :moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
NEW
none[0] none:none
PolyEnE| lines=93
embedded dns
trace
T:10:03:00 WinXP 4.177.18.252 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
SAN DIEGO, CALIFORNIA, US. (DIAL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
111 lines
Yeah : 1.3
profile
none summary
tarball
37 of 41
36 of 40
47d3548e36
NEW
d8722af110
NEW
ab13346633 [0]
ab30a55931[0]
none:none
none:none
Armadillo|
tElock|
none
none
trace
trace
10:27:00 Win2K-f 186.100.171.41 (-):
.
n/a US:www.maxmind.com
US:www.getmyip.org
US:getmyip.co.uk
:checkip.dyndns.org
DE:131.220.6.26:80
US:65.254.39.170:80
EU:91.198.22.70:80
445 pcap raw alerts
ruleset
http
5 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:10:36:00 Win2K-f 186.100.171.41 (-):
.
n/a US:www.maxmind.com
US:www.getmyip.org
US:checkip.dyndns.org
US:getmyip.co.uk
208.78.69.70:80
US:67.15.94.80:80
US:75.126.138.202:80
445 pcap raw alerts
ruleset
http
3 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:11:41:00 Win2K-f 63.246.121.32 (SPEAKEASY.NET):
US.
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:11:53:00 Win2K-f 208.113.27.206 (NTDAPPAREL.COM):
ACCELERATED CONNECTIONS,
ONTARIO, CA.
n/a   135 pcap raw alerts
ruleset
other
1001 lines
Yeah : 1.3
profile
none summary
tarball
12 of 40 7adb0e118d
NEW
none[3] none:none
StarForce| none trace
T:13:44:00 Win2K-f 68.144.29.181 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
CALGARY, ALBERTA, CA.
n/a   135 pcap raw alerts
ruleset
other
1014 lines
Yeah : 1.3
profile
none summary
tarball
26 of 35 f2cfdc83a8
NEW
none[3] none:none
none|none none trace
T:14:28:00 WinXP 211.211.153.167 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
221.5.74.39:65520 CN:proxim.ircgalaxy.pl
US:microsoft.com
CN:put.ghura.pl
CN:brenz.pl
CN:211.95.79.6:80
135 pcap raw alerts
ruleset
irc
http
135 lines
Yeah : 1.8
profile
none summary
tarball
15 of 41
30 of 33
28 of 33
298243013a
NEW
533d15b5ce
NEW
58c343a8d8
NEW
b8c969e769 [0]
c67adf46e2[0]
none [0]
none:none
ASM:Graph
none:none
PEQuake|
tElock|
Armadillo|
none
lines=126
embedded dns
lines=91
trace
trace
trace
T:15:07:00 Win2K-f 124.241.190.162 (STARCAT.NE.JP):
KMN CORPORATION,
NAGOYA, AICHI, JP.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
15:15:00 WinXP 83.97.237.246 (CM-83-97-128-10.TELECABLE.ES):
TELECABLE,
GIJON, ASTURIAS, ES. (DSL)
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 1fcc146d70
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:15:35:00 WinXP 82.24.29.200 (NTL.COM):
NTL INFRASTRUCTURE - LEWISHAM,
LONDON, ENGLAND, UK. (DSL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
21 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32 741e3b03b3
NEW
none[0] none:none
none|none lines=61 trace
T:15:35:00 WinXP 93.102.53.100 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a :www.google.com.au
US:www.yahoo.com
:jbeegvia.ru
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
31 of 32 17028f1eda
NEW
none[3] none:none
tElock| none trace
T:15:35:00 Win2K-f 4.231.148.27 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
DEER PARK, TEXAS, US. (DIAL)
n/a   135 pcap raw alerts
ruleset
other
675 lines
Yeah : 1.3
profile
none summary
tarball
7 of 41 f5dd9f1f9d
NEW
none[3] none:none
none|none none trace
17:14:00 Win2K-f 190.220.223.143 (-):
.
n/a US:www.maxmind.com
US:www.getmyip.org
EU:checkip.dyndns.org
US:getmyip.co.uk
DE:131.220.6.26:80
US:65.254.39.170:80
US:75.126.138.202:80
EU:91.198.22.70:80
445 pcap raw alerts
ruleset
http
4 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 dc331fb791
NEW
none[3] none:none
UPX| none trace
T:17:28:00 WinXP 4.155.33.111 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
OWINGS MILLS, MARYLAND, US. (DIAL)
n/a   135 pcap raw alerts
ruleset
other
1020 lines
Yeah : 1.3
profile
none summary
tarball
5 of 41 148b3ff351
NEW
none[3] none:none
StarForce| none trace
T:18:31:00 Win2K-f 210.244.13.51 (SEED.NET.TW):
DIGITAL UNITED INC,
TAINAN, KAO-HSIUNG, TW. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
112 lines
Yeah : 1.3
profile
none summary
tarball
39 of 41
36 of 41
2294edfc36
NEW
3959e0ddf3
NEW
1b0799e7b2 [0]
60ba459f82[0]
none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
T:20:02:00 Win2K-f 63.17.130.6 (UU.NET):
UUNET TECHNOLOGIES INC,
NEW YORK, NEW YORK, US.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:21:04:00 WinXP 122.18.28.108 (OCN.NE.JP):
OPEN COMPUTER NETWORK,
JP.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32 741e3b03b3
NEW
none[0] none:none
none|none lines=61 trace
T:21:51:00 WinXP 61.218.193.250 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
81 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
57ce4acac2
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace