Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

05 August 2009
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
T:00:26:00 WinXP 122.146.81.131 (SPARQNET.NET):
NEW CENTURY INFOCOMM TECH. CO. LTD,
TW.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:00:59:00 Win2K-f 99.153.105.204 (-):
.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
65 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
8 of 33
53bfe15e91
NEW
b7082104e4
NEW
1473091351 [0]
c5b49e7b82[0]
ASM:Graph
ASM:Graph
tElock|
tElock|
lines=75
embedded dns
lines=41
trace
trace
T:01:55:00 WinXP 71.14.40.248 (CHARTER.COM):
CHARTER COMMUNICATIONS,
LAGRANGE, GEORGIA, US. (100Mbps)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:03:29:00 Win2K-f 211.206.133.90 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:03:36:00 Win2K-f 76.198.237.93 (SBCGLOBAL.NET):
PPPOX POOL - BRAS6.STLSMO,
ST. LOUIS, MISSOURI, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
79 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:03:47:00 WinXP 70.117.157.9 (RR.COM):
ROAD RUNNER HOLDCO LLC,
BEAUMONT, TEXAS, US.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:04:21:00 WinXP 67.150.53.204 (MDSG-PACWEST.COM):
PAC-WEST MANAGED MODEM NAS POOL,
LOS ANGELES, CALIFORNIA, US.
n/a RU:citi-bank.ru
RU:213.219.245.212:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 d42c1cc7c0
NEW
none[0] ASM:Graph
PolyEnE| lines=54 trace
T:04:42:00 WinXP 4.178.235.242 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
US. (DIAL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
37 of 41
36 of 40
47d3548e36
NEW
d8722af110
NEW
ab13346633 [0]
ab30a55931[0]
none:none
none:none
Armadillo|
tElock|
none
none
trace
trace
T:07:26:00 Win2K-f 173.19.143.3 (-):
.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:07:45:00 WinXP 174.6.21.151 (-):
.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:08:02:00 WinXP 114.137.116.88 (-):
.
n/a :moscow-advokat.ru
SE:qis.md.us.dal.net
:brussels.be.eu.undernet.org
:washington.dc.us.undernet.org
SE:broadway.ny.us.dal.net
:los-angeles.ca.us.undernet.org
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
25 of 25 7f60162c2c
NEW
none[0] none:none
PolyEnE| lines=93
embedded dns
trace
T:08:17:00 WinXP 193.250.9.8 (ABO.WANADOO.FR):
WANADOO FRANCE,
LYON, RHONE-ALPES, FR.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
32 of 32 03f912899b
NEW
none[0] none:none
none|none lines=64 trace
T:08:21:00 WinXP 64.127.45.26 (RTOL.NET):
RAMCO TECHNOLOGIES,
GRANTSVILLE, WEST VIRGINIA, US.
n/a EU:siliconfireware.ru
US:searchportal.information.com
US:spi.domainsponsor.com
RU:www.bbin.ru
RU:www.binbank.ru
:wpad
EU:78.47.200.154:80
445 pcap raw alerts
ruleset
http
http
http
27 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 a12cab51ef
NEW
none[0] none:none
ASPack| lines=281
embedded dns
trace
T:08:45:00 WinXP 116.59.164.252 (-):
MOBILE BUSINESS GROUP CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
n/a :moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
NEW
none[0] none:none
PolyEnE| lines=93
embedded dns
trace
T:10:11:00 WinXP 89.36.205.191 (-):
S.C. EXPERTNET S.R.L,
RO.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41 15db4d1262
NEW
cf1b2629ef [0] none:none
none|none none trace
T:10:27:00 WinXP 69.193.74.22 (-):
.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:10:42:00 WinXP 92.115.168.31 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:10:51:00 WinXP 173.27.244.237 (-):
.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
57ce4acac2
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:11:02:00 Win2K-f 71.112.124.71 (VERIZON.NET):
VERIZON INTERNET SERVICES INC,
BOTHELL, WASHINGTON, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
1004 lines
Yeah : 1.3
profile
none summary
tarball
12 of 41 ca2753ba67
NEW
none[3] none:none
StarForce| none trace
T:11:39:00 WinXP 130.13.46.240 (QWEST.NET):
QWEST BROADBAND SERVICES INC,
PHOENIX, ARIZONA, US.
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
35 of 35 9716d7995a
NEW
c3a5354b6f [0] none:none
PolyEnE| none trace
T:12:58:00 WinXP 87.116.235.251 (TNP.PL):
NETWORK OF INTERNET SERVICE PROVIDER,
PL.
n/a RU:citi-bank.ru
RU:213.219.245.212:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
32 of 32 5818023061
NEW
none[0] ASM:Graph
PolyEnE| lines=68 trace
T:14:09:00 WinXP 78.30.137.7 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a RU:citi-bank.ru
RU:213.219.245.212:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
30 of 31 a4069dcad2
NEW
5cd3e92463 [0] none:none
PolyEnE| none trace
T:14:20:00 Win2K-f 130.13.7.124 (QWEST.NET):
QWEST BROADBAND SERVICES INC,
PHOENIX, ARIZONA, US.
61.120.62.28:3305 GB:cx10man.weedns.com 135 pcap raw alerts
ruleset
shell
shell
ftp
irc
38 lines
Yeah : 1.8
profile
none summary
tarball
28 of 41 1bb4b25c0e
NEW
9293a2c3db [0] none:none
StarForce| none trace
T:14:35:00 WinXP 69.85.112.201 (SPEAKEASY.NET):
US.
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
35 of 35 9716d7995a
NEW
c3a5354b6f [0] none:none
PolyEnE| none trace
T:15:23:00 WinXP 159.134.219.136 (EIRCOM.NET):
EIRCOM GROUP PLC,
CORK, CORK, IE.
n/a   445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 1a2c0e6130
NEW
none[0] none:none
none|none lines=60 trace
16:10:00 WinXP 78.30.137.7 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a RU:citi-bank.ru
RU:213.219.245.212:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
30 of 31 a4069dcad2
NEW
5cd3e92463 [0] none:none
PolyEnE| none trace
T:16:19:00 WinXP 71.121.172.129 (VERIZON.NET):
VERIZON INTERNET SERVICES INC,
FERNDALE, WASHINGTON, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:16:33:00 WinXP 99.230.43.106 (ROGERS.COM):
ROGERS CABLE COMMUNICATIONS INC,
TORONTO, ONTARIO, CA.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
113 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32
23 of 33
bca9e0fb5f
NEW
e53a9ea82e
NEW
1d6b20137d [0]
none [0]
none:none
ASM:Graph
PolyEnE|
Armadillo|
none
lines=81
trace
trace
T:16:33:00 WinXP 89.111.226.250 (TEOL.NET):
TELEKOMSRPSKE,
BA. (DIAL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
37 of 40 f54691063f
NEW
6039c698cd [0] ASM:Graph
none|none lines=59 trace
T:17:06:00 Win2K-f 67.8.56.42 (RR.COM):
ROAD RUNNER HOLDCO LLC,
NAPLES, FLORIDA, US.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:17:35:00 WinXP 114.149.95.117 (-):
.
n/a   445 pcap raw alerts
ruleset
shell
ftp
16 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32 741e3b03b3
NEW
none[0] none:none
none|none lines=61 trace
T:18:54:00 WinXP 211.207.110.195 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
218.93.205.24:65520 CN:proxim.ircgalaxy.pl
US:microsoft.com
CN:dretis.cn
CN:kritq.cn
135 pcap raw alerts
ruleset
irc
http
140 lines
Yeah : 1.8
profile
none summary
tarball
7 of 41
29 of 32
28 of 32
10 of 41
5354e986cd
NEW
8a75955033
NEW
9276c8b36b
NEW
938fa818d8
NEW
55eb7e6494 [0]
2bf3e548b9[0]
none [0]
none [4]
none:none
ASM:Graph
ASM:Graph
none:none
PENinja|
tElock|
Armadillo|
Mew|
none
lines=126
embedded dns
lines=81
none
trace
trace
trace
trace
21:08:00 Win2K-f 190.225.235.6 (-):
.
n/a US:www.maxmind.com
:checkip.dyndns.org
US:67.15.94.80:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
7 of 37 7587773eea
NEW
none[3] none:none
StarForce| none trace
T:21:18:00 Win2K-f 190.225.235.6 (-):
.
n/a US:www.maxmind.com
US:www.getmyip.org
US:getmyip.co.uk
:checkip.dyndns.org
445 pcap raw alerts
ruleset
http
7 lines
Yeah : 0.8
profile
none summary
tarball
7 of 37 7587773eea
NEW
none[3] none:none
StarForce| none trace
T:22:04:00 WinXP 66.212.211.144 (METROCAST.NET):
METROCAST COMMUNICATIONS,
WATERFORD, CONNECTICUT, US.
n/a CA:xx.ka3ek.com 135 pcap raw alerts
ruleset
irc
185 lines
Yeah : 1.3
profile
none summary
tarball
38 of 41 a894e6640a
NEW
2a62540340 [0] none:none
PolyEnE| none trace
T:22:13:00 Win2K-f 71.77.208.118 (RR.COM):
ROAD RUNNER HOLDCO LLC,
JACKSONVILLE, NORTH CAROLINA, US.
n/a   135 pcap raw alerts
ruleset
other
54 lines
Yeah : 1.3
profile
none summary
tarball
0 of 32 73f1082158
NEW
none[0] none:none
Armadillo| lines=90 trace