Welcome to the Cyber-TA
Daily Malware Binary DIGEST Summary Page



29 July 2009

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.



Packed
MD5
UnPacket
MD5
Victim
OS
AntiVirus
Hit-Cnt
First
Encounter
Last
Encounter
Freq
Cnt
Behavioral
Clusters
Unpacked
Egg.asm
Packer
Fingerprint
API
Resolution
String
Cnt
Syscall
Trace
176f4e0237
NEW
6648e7022b
NEW
66863cfb13
NEW
6f8772fb4c
NEW
971b66b4c6 [0]
0ad0f97bcc[0]
fca240f318[0]
72c4861af2[0]
Win2K-f 27 of 41 03:44:25 03:44:25 1 none none:none
none:none
none:none
none:none
none|none
UPX|
Armadillo|
UPX|
none
none
none
none
trace
trace
trace
trace
47d76e8dce
NEW
457779e597 [0] Win2K-f 25 of 41 02:15:59 08:23:43 2 none none:none
Neolite| none trace
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
WinXP 0 of 32 13:39:33 13:39:33 1 none ASM:Graph
none:none
tElock|
Armadillo|
0% lines=75
embedded dns
lines=90
trace
trace
176f4e0237
NEW
409536c6f3
NEW
852eec7620
NEW
bea8cb1865
NEW
e5176f95e0
NEW
fac78fde16
NEW
971b66b4c6 [0]
8dfee3b93a[0]
af9f5e5446[0]
154de51a66[0]
none [4]
882896ab05[0]
WinXP 35 of 36 23:25:51 23:25:51 1 none none:none
none:none
none:none
ASM:Graph
none:none
none:none
none|none
Armadillo|
none|none
Armadillo|
StarForce|
tElock|
none
none
none
lines=91
none
none
trace
trace
trace
trace
trace
trace
176f4e0237
NEW
409536c6f3
NEW
852eec7620
NEW
bea8cb1865
NEW
e5176f95e0
NEW
971b66b4c6 [0]
8dfee3b93a[0]
af9f5e5446[0]
154de51a66[0]
none [4]
WinXP 16 of 41 23:25:51 23:25:51 1 none none:none
none:none
none:none
ASM:Graph
none:none
none|none
Armadillo|
none|none
Armadillo|
StarForce|
none
none
none
lines=91
none
trace
trace
trace
trace
trace
176f4e0237
NEW
409536c6f3
NEW
852eec7620
NEW
971b66b4c6 [0]
8dfee3b93a[0]
af9f5e5446[0]
WinXP 12 of 40 23:25:51 23:25:51 1 none none:none
none:none
none:none
none|none
Armadillo|
none|none
none
none
none
trace
trace
trace
067917e07b
NEW
d764c1dcb2
NEW
dae35b319c [0]
3d2bc60c5d[0]
Win2K-f 38 of 40 23:23:11 23:23:11 1 none none:none
none:none
Armadillo|
tElock|
none
none
trace
trace
53bfe15e91
NEW
1473091351 [0] Win2K-f
WinXP
33 of 33 00:25:51 21:25:06 9 none ASM:Graph
tElock| 96% lines=75
embedded dns
trace
176f4e0237
NEW
1da3a4f356
NEW
971b66b4c6 [0]
1ef0af6554[0]
WinXP 9 of 41 07:08:23 07:08:23 1 none none:none
none:none
none|none
Armadillo|
none
none
trace
trace
b1f58ef783
NEW
none[3] Win2K-f 7 of 41 14:53:42 14:53:42 1 none none:none
none|none none trace
176f4e0237
NEW
409536c6f3
NEW
971b66b4c6 [0]
8dfee3b93a[0]
WinXP 15 of 41 23:25:51 23:25:51 1 none none:none
none:none
none|none
Armadillo|
none
none
trace
trace
176f4e0237
NEW
6648e7022b
NEW
66863cfb13
NEW
6f8772fb4c
NEW
d06d0f7c93
NEW
e8dfca0741
NEW
971b66b4c6 [0]
0ad0f97bcc[0]
fca240f318[0]
72c4861af2[0]
5ab57bf0dc[0]
20dfd2147c[0]
Win2K-f 38 of 40 03:44:25 03:44:25 1 none none:none
none:none
none:none
none:none
none:none
none:none
none|none
UPX|
Armadillo|
UPX|
Xtreme-Pr|
tElock|
none
none
none
none
none
none
trace
trace
trace
trace
trace
trace
86c31a45fe
NEW
8663930785 [0] Win2K-f 39 of 41 09:30:55 09:30:55 1 none none:none
none|none none trace
176f4e0237
NEW
6648e7022b
NEW
66863cfb13
NEW
6f8772fb4c
NEW
d06d0f7c93
NEW
971b66b4c6 [0]
0ad0f97bcc[0]
fca240f318[0]
72c4861af2[0]
5ab57bf0dc[0]
Win2K-f 5 of 41 03:44:25 03:44:25 1 none none:none
none:none
none:none
none:none
none:none
none|none
UPX|
Armadillo|
UPX|
Xtreme-Pr|
none
none
none
none
none
trace
trace
trace
trace
trace
067917e07b
NEW
dae35b319c [0] Win2K-f 36 of 41 23:23:11 23:23:11 1 none none:none
Armadillo| none trace
0b951c2832
NEW
5fe761661a [0] WinXP 32 of 36 01:46:52 01:46:52 1 none none:none
Armadillo| none trace
77f827fe3d
NEW
0450c8318a [0] WinXP 39 of 41 01:05:01 01:05:01 1 none none:none
PolyEnE| none trace
9716d7995a
NEW
c3a5354b6f [0] WinXP 35 of 35 20:31:26 20:31:26 1 none none:none
PolyEnE| none trace
47d76e8dce
NEW
524bc0f75c
NEW
457779e597 [0]
d3e9510bb3[0]
Win2K-f 32 of 38 02:15:59 08:23:43 2 none none:none
none:none
Neolite|
PENinja S|
none
none
trace
trace
176f4e0237
NEW
1da3a4f356
NEW
a036b3aec2
NEW
971b66b4c6 [0]
1ef0af6554[0]
none [4]
WinXP 14 of 41 07:08:23 07:08:23 1 none none:none
none:none
none:none
none|none
Armadillo|
none|none
none
none
none
trace
trace
trace
29546fd87c
NEW
2665d1ed69 [0] WinXP 39 of 41 07:06:03 07:06:03 1 none none:none
tElock| none trace
dab4da4e21
NEW
e63b813015 [0] WinXP 37 of 39 07:08:23 08:48:38 2 none ASM:Graph
PolyEnE| 100% lines=134 trace
29546fd87c
NEW
e17e2834ac
NEW
2665d1ed69 [0]
abf684db50[0]
WinXP 3 of 41 07:06:03 07:06:03 1 none none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
47d76e8dce
NEW
524bc0f75c
NEW
954a98c971
NEW
457779e597 [0]
d3e9510bb3[0]
cdd769f7a4[0]
Win2K-f 31 of 33 08:23:43 08:23:43 1 none none:none
none:none
none:none
Neolite|
PENinja S|
FSG|
none
none
none
trace
trace
trace
176f4e0237
NEW
7fd7475c63
NEW
b28099b772
NEW
971b66b4c6 [0]
8dcf239714[0]
d43389c576[0]
WinXP 8 of 39 11:18:21 11:18:21 1 none none:none
none:none
none:none
none|none
PolyEnE|
Armadillo|
none
none
none
trace
trace
trace
824d6a706e
NEW
a66fd13bcb [0] WinXP 40 of 40 12:26:39 12:26:39 1 none none:none
PolyEnE| none trace
176f4e0237
NEW
409536c6f3
NEW
852eec7620
NEW
bea8cb1865
NEW
971b66b4c6 [0]
8dfee3b93a[0]
af9f5e5446[0]
154de51a66[0]
WinXP 32 of 36 23:25:51 23:25:51 1 none none:none
none:none
none:none
ASM:Graph
none|none
Armadillo|
none|none
Armadillo|
0% none
none
none
lines=91
trace
trace
trace
trace
2d5fe9850a
NEW
2233a191b2 [0] WinXP 39 of 41 02:16:52 02:16:52 1 none none:none
tElock| none trace
176f4e0237
NEW
971b66b4c6 [0] Win2K-f
WinXP
19 of 41 03:44:25 23:25:51 4 none none:none
none|none none trace
a0a15f5ebf
NEW
c506c7cc86 [0] WinXP 37 of 40 16:36:37 16:36:37 1 none none:none
Mew| none trace
176f4e0237
NEW
6648e7022b
NEW
971b66b4c6 [0]
0ad0f97bcc[0]
Win2K-f 28 of 41 03:44:25 03:44:25 1 none none:none
none:none
none|none
UPX|
none
none
trace
trace
119ec42aa0
NEW
fd3c61c261 [0] WinXP 40 of 41 03:28:23 03:28:23 1 none none:none
PolyEnE| none trace
7d99b0e910
NEW
none[0] WinXP 26 of 28 09:10:24 09:10:24 1 none none:none
PolyEnE| 99% lines=68 trace
a769511504
NEW
7ecd054f18 [0] WinXP 41 of 41 06:41:05 06:41:05 1 none none:none
PolyEnE| none trace
176f4e0237
NEW
7fd7475c63
NEW
971b66b4c6 [0]
8dcf239714[0]
WinXP 35 of 36 11:18:21 11:18:21 1 none none:none
none:none
none|none
PolyEnE|
none
none
trace
trace
176f4e0237
NEW
6648e7022b
NEW
66863cfb13
NEW
971b66b4c6 [0]
0ad0f97bcc[0]
fca240f318[0]
Win2K-f 38 of 40 03:44:25 03:44:25 1 none none:none
none:none
none:none
none|none
UPX|
Armadillo|
none
none
none
trace
trace
trace
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
Win2K-f
WinXP
0 of 33 00:25:51 21:25:06 9 none ASM:Graph
none:none
tElock|
Armadillo|
0% lines=75
embedded dns
lines=90
trace
trace
b8076e37ae
NEW
52953fed05 [0] Win2K-f 28 of 41 08:53:21 08:53:21 1 none none:none
StarForce| none trace
47d76e8dce
NEW
524bc0f75c
NEW
d00b0ae77c
NEW
457779e597 [0]
d3e9510bb3[0]
423a668612[0]
Win2K-f 27 of 32 02:15:59 02:15:59 1 none none:none
none:none
none:none
Neolite|
PENinja S|
Armadillo|
none
none
none
trace
trace
trace
0b951c2832
NEW
e4ed4df0f0
NEW
5fe761661a [0]
de471fc380[0]
WinXP 34 of 36 01:46:52 01:46:52 1 none none:none
none:none
Armadillo|
tElock|
none
none
trace
trace
176f4e0237
NEW
6648e7022b
NEW
66863cfb13
NEW
6f8772fb4c
NEW
d06d0f7c93
NEW
e8dfca0741
NEW
fd2814ef63
NEW
971b66b4c6 [0]
0ad0f97bcc[0]
fca240f318[0]
72c4861af2[0]
5ab57bf0dc[0]
20dfd2147c[0]
53d312e1c4[0]
Win2K-f 30 of 41 03:44:25 03:44:25 1 none none:none
none:none
none:none
none:none
none:none
none:none
none:none
none|none
UPX|
Armadillo|
UPX|
Xtreme-Pr|
tElock|
none|none
none
none
none
none
none
none
none
trace
trace
trace
trace
trace
trace
trace
2d5fe9850a
NEW
63b64adf8b
NEW
2233a191b2 [0]
b4e67ccf8a[0]
WinXP 38 of 41 02:16:52 02:16:52 1 none none:none
none:none
tElock|
Armadillo|
none
none
trace
trace