Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

04 October 2009
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
T:00:23:00 WinXP 125.103.232.248 (UCOM.NE.JP):
G-TK0024N,
TOKYO, TOKYO, JP. (DSL)
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 aa298099d5
NEW
none[0] ASM:Graph
PolyEnE| lines=68 trace
T:00:39:00 Win2K-f 173.28.201.188 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
CHANHASSEN, MINNESOTA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
36 of 41
38 of 40
067917e07b
NEW
d764c1dcb2
NEW
dae35b319c [0]
3d2bc60c5d[0]
none:none
none:none
Armadillo|
tElock|
none
none
trace
trace
T:01:20:00 Win2K-f 173.19.210.223 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
IOWA CITY, IOWA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
38 of 41
39 of 41
10759405e0
NEW
d08e00dfaf
NEW
292d343248 [0]
854c49d8c4[0]
none:none
none:none
Armadillo|
tElock|
none
none
trace
trace
T:02:41:00 WinXP 119.228.212.26 (EONET.NE.JP):
K-OPTICOM CORPORATION,
OSAKA, OSAKA, JP. (DSL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
38 of 41 7b313206a2
NEW
0c866c8cce [0] none:none
none|none none trace
T:03:16:00 Win2K-f 70.60.117.169 (RR.COM):
ROAD RUNNER HOLDCO LLC,
CHARLOTTE, NORTH CAROLINA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:03:34:00 WinXP 87.173.65.54 (T-DIALIN.NET):
DEUTSCHE TELEKOM AG,
BERLIN, BERLIN, DE. (DSL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32 741e3b03b3
NEW
none[0] none:none
none|none lines=61 trace
T:04:53:00 WinXP 83.2.21.13 (-):
AUTO HIT ANNA OLESZCZUK,
WARSAW, WARSZAWA, PL. (DSL)
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
35 of 36 6b3beaea1a
NEW
154f174df6 [0] none:none
PolyEnE| none trace
T:05:43:00 WinXP 118.7.7.146 (OCN.NE.JP):
OPEN COMPUTER NETWORK,
JP. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
13 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 831f4ee0a7
NEW
none[0] ASM:Graph
none|none lines=61 trace
T:06:06:00 WinXP 124.8.113.65 (TFN.NET.TW):
TAIWAN FIXED NETWORK CO. LTD,
TAIPEI, T'AI-PEI, TW. (DSL)
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:06:07:00 WinXP 67.242.136.24 (RR.COM):
ROAD RUNNER HOLDCO LLC,
WELLSVILLE, NEW YORK, US. (DSL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32 741e3b03b3
NEW
none[0] none:none
none|none lines=61 trace
T:07:42:00 WinXP 109.87.116.86 (JWS.COM):
EU-ZZ,
UK. (DSL)
n/a RU:citi-bank.ru
RU:213.219.245.212:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
41 of 41 b26ed6eeac
NEW
97c1157bf8 [0] none:none
PolyEnE| none trace
T:08:21:00 WinXP 75.43.199.128 (SBCGLOBAL.NET):
AT&T INTERNET SERVICES,
LOS ANGELES, CALIFORNIA, US. (DSL)
n/a EU:siliconfireware.ru
US:searchportal.information.com
:www.proxy-socks.net
:wpad
US:spi.domainsponsor.com
US:208.73.210.125:80
445 pcap raw alerts
ruleset
http
http
http
15 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 a12cab51ef
NEW
none[0] none:none
ASPack| lines=281
embedded dns
trace
T:09:24:00 WinXP 87.62.253.62 (DSL.TELE.DK):
TDC-TELEDANMARK-BREDBAANDSADSL-NET,
HERNING, RINGKOBING, DK. (DSL)
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
41 of 41 b26ed6eeac
NEW
97c1157bf8 [0] none:none
PolyEnE| none trace
T:09:32:00 WinXP 189.64.216.211 (TIMBRASIL.COM.BR):
COMITE GESTOR DA INTERNET NO BRASIL,
SãO PAULO, SAO PAULO, BR. (DSL)
n/a :moscow-advokat.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
NEW
none[0] none:none
PolyEnE| lines=93
embedded dns
trace
T:10:37:00 WinXP 114.201.62.212 (-):
HANARO TELECOM,
SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL)
218.93.205.30:65520 CN:proxima.ircgalaxy.pl
US:microsoft.com
CN:dl.guarddog2009.com
EU:gidromash.cn
EU:ottopay.cn
US:64.235.53.208:80
EU:91.212.220.75:65520
135 pcap raw alerts
ruleset
irc
http
120 lines
Yeah : 1.8
profile
none summary
tarball
31 of 33
31 of 33
15 of 41
7 of 41
168aab35a3
NEW
667f0c59f3
NEW
83192a6119
NEW
c7830331fc
NEW
60b730b97e [0]
8fe2be2095[0]
fdc95e1fab[0]
7953649664[0]
ASM:Graph
ASM:Graph
none:none
none:none
tElock|
Armadillo|
none|none
tElock|
lines=120
embedded dns
lines=91
none
none
trace
trace
trace
trace
T:10:51:00 Win2K-f 113.254.43.160 (HUTCHCITY.COM):
HUTCHISON GLOBAL COMMUNICATIONS,
HONG KONG, HONG KONG (SAR), HK. (DSL)
n/a CN:italian.swiifatecihno.com 135 pcap raw alerts
ruleset
irc
http
730 lines
Yeah : 1.3
profile
none summary
tarball
25 of 41
36 of 41
65ab01055a
NEW
cfc1d2f1e6
NEW
8af090abd4 [0]
8e35d85b6b[0]
none:none
none:none
StarForce|
ASPack|
none
none
trace
trace
T:11:20:00 WinXP 212.225.148.87 (PTVTELECOM.COM):
ES-PROCONO-AS,
CóRDOBA, ANDALUCIA, ES. (DSL)
n/a :moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
38 of 39 e1cc0f1f8d
NEW
edeeb27e4a [0] none:none
PolyEnE| none trace
11:32:00 WinXP 76.177.111.13 (RR.COM):
ROAD RUNNER HOLDCO LLC,
WINCHESTER, KENTUCKY, US. (DSL)
n/a :moscow-advokat.ru
:lia.zanet.net
SE:ced.dal.net
SE:ozbytes.dal.net
AT:graz.at.eu.undernet.org
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
25 of 25 7f60162c2c
NEW
none[0] none:none
PolyEnE| lines=93
embedded dns
trace
T:12:07:00 WinXP 76.171.146.5 (RR.COM):
ROAD RUNNER HOLDCO LLC,
LOS ANGELES, CALIFORNIA, US. (DSL)
n/a RU:citi-bank.ru
RU:213.219.245.212:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 a0139d7ad8
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:13:13:00 WinXP 81.9.191.114 (CM-81-9-237-10.TELECABLE.ES):
TELECABLE,
OVIEDO, ASTURIAS, ES. (DSL)
n/a RU:citi-bank.ru
RU:213.219.245.212:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
32 of 32 b502f83a7c
NEW
28f5be93b0 [0] none:none
PolyEnE| none trace
13:26:00 Win2K-f 114.38.190.31 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a US:www.maxmind.com
:checkip.dyndns.org
US:www.getmyip.org
US:getmyip.co.uk
208.78.70.70:80
US:67.15.94.80:80
US:75.126.138.202:80
445 pcap raw alerts
ruleset
http
3 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:13:28:00 WinXP 80.253.147.240 (AZADNET.NET):
RANGE FOR COUNTRYWISE DSL INFRASTRUCTURE,
TEHRAN, ESFAHAN, IR. (DSL)
n/a DE:siliconfireware.ru
US:searchportal.information.com
US:spi.domainsponsor.com
:vit.ln.ua
RU:www.bbin.ru
RU:www.binbank.ru
:wpad
RU:195.200.213.54:80
445 pcap raw alerts
ruleset
http
http
http
http
39 lines
Yeah : 0.8
profile
none summary
tarball
30 of 39 aaf763d687
NEW
9ca935dd78 [0] none:none
ASPack| none trace
T:13:35:00 Win2K-f 114.38.190.31 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a US:www.maxmind.com
:checkip.dyndns.org
US:www.getmyip.org
US:getmyip.co.uk
DE:131.220.6.26:80
208.78.70.70:80
US:67.15.94.80:80
US:75.126.138.202:80
445 pcap raw alerts
ruleset
http
5 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:14:08:00 WinXP 83.97.247.80 (CM-93-156-61-10.TELECABLE.ES):
TELECABLE,
BARCELONA, CATALONIA, ES. (DSL)
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
32 of 32 b502f83a7c
NEW
28f5be93b0 [0] none:none
PolyEnE| none trace
T:14:17:00 WinXP 92.230.96.24 (ALICEDSL.DE):
HANSENET-ADSL,
BIELEFELD, NORDRHEIN-WESTFALEN, DE. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
18 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:14:17:00 WinXP 95.91.201.173 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
BERLIN, BERLIN, DE. (DSL)
66.252.13.214:2081 US:s.unicat.org 445 pcap raw alerts
ruleset
ftp
irc
27 lines
Yeah : 1.3
profile
none summary
tarball
39 of 41 453e0d6f52
NEW
f024cb64bb [0] none:none
none|none none trace
14:20:00 WinXP 114.137.65.248 (HINET.NET):
MOBILE BUSINESS GROUP CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a :moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
NEW
none[0] none:none
PolyEnE| lines=93
embedded dns
trace
T:14:23:00 WinXP 94.251.153.203 (-):
CUSTOMERS IN BYTOM,
PL. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
40 of 41 e585bb1e8e
NEW
bdddd170de [0] none:none
StarForce| none trace
T:16:27:00 WinXP 187.47.236.125 (VELOXZONE.COM.BR):
COMITE GESTOR DA INTERNET NO BRASIL,
BR. (DSL)
n/a :moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
NEW
none[0] none:none
PolyEnE| lines=93
embedded dns
trace
16:38:00 WinXP 187.47.236.125 (VELOXZONE.COM.BR):
COMITE GESTOR DA INTERNET NO BRASIL,
BR. (DSL)
n/a :moscow-advokat.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
NEW
none[0] none:none
PolyEnE| lines=93
embedded dns
trace
T:18:14:00 WinXP 125.4.229.201 (ZAQ.NE.JP):
J:COM WEST CO. LTD,
TOKYO, TOKYO, JP. (DSL)
n/a :teek.ihshsd8.com
:japan.youngpeyatech.info
CN:done.blacktiehsbdcs.com
135 pcap raw alerts
ruleset
irc
http
616 lines
Yeah : 1.3
profile
none summary
tarball
25 of 41
40 of 41
65ab01055a
NEW
8ca2204d15
NEW
8af090abd4 [0]
b4b671eb52[0]
none:none
none:none
StarForce|
ASPack|
none
none
trace
trace
T:18:29:00 WinXP 74.214.47.11 (METROCAST.NET):
METROCAST COMMUNICATIONS,
KING GEORGE, VIRGINIA, US. (100Mbps)
194.109.11.65:6556 :0x80.my-secure.name
NL:0x80.my1x1.com
NL:0x80.martiansong.com
NL:0x80.goingformars.com
NL:194.109.11.65:6556
135 pcap raw alerts
ruleset
other
229 lines
Yeah : 1.8
profile
none summary
tarball
32 of 33 fe22b8315f
NEW
bb25603f41 [0] none:none
StarForce| none trace
T:19:02:00 WinXP 78.226.17.128 (PROXAD.NET):
PROXAD / FREE SAS,
AMIENS, PICARDIE, FR. (DSL)
66.252.13.214:2081 US:s.unicat.org
US:66.252.13.214:2081
445 pcap raw alerts
ruleset
ftp
irc
34 lines
Yeah : 1.3
profile
none summary
tarball
37 of 41 67a66839f7
NEW
7b1fc808a3 [0] none:none
none|none none trace
19:27:00 WinXP 66.217.240.119 (MCLEODUSA.NET):
PAETEC COMMUNICATIONS INC,
BIRMINGHAM, ALABAMA, US. (DSL)
n/a :moscow-advokat.ru
SE:qis.md.us.dal.net
:washington.dc.us.undernet.org
:brussels.be.eu.undernet.org
:caen.fr.eu.undernet.org
BE:london.uk.eu.undernet.org
SE:broadway.ny.us.dal.net
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
25 of 25 7f60162c2c
NEW
none[0] none:none
PolyEnE| lines=93
embedded dns
trace
T:20:56:00 Win2K-f 207.5.155.42 (SUSCOM-MAINE.NET):
GREAT WORKS INTERNET,
BRUNSWICK, MAINE, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
59 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
8 of 33
53bfe15e91
NEW
b7082104e4
NEW
1473091351 [0]
c5b49e7b82[0]
ASM:Graph
ASM:Graph
tElock|
tElock|
lines=75
embedded dns
lines=41
trace
trace
T:21:00:00 Win2K-f 113.255.111.101 (HUTCHCITY.COM):
HUTCHISON GLOBAL COMMUNICATIONS,
HONG KONG, HONG KONG (SAR), HK. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
59 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
8 of 33
53bfe15e91
NEW
b7082104e4
NEW
1473091351 [0]
c5b49e7b82[0]
ASM:Graph
ASM:Graph
tElock|
tElock|
lines=75
embedded dns
lines=41
trace
trace