Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

11 October 2009
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
T:00:19:00 Win2K-f 63.17.218.177 (UU.NET):
UUNET TECHNOLOGIES INC,
SMYRNA, GEORGIA, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
145 lines
Yeah : 1.3
profile
none summary
tarball
37 of 41 aa52a1cad3
NEW
822158a84f [0] none:none
Armadillo| none trace
T:00:34:00 WinXP 173.25.3.229 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
COLUMBIA, MISSOURI, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
39 of 41
38 of 41
b8f53b4800
NEW
e9ef6d378d
NEW
4208eb65f3 [0]
72080f1764[0]
none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
T:01:19:00 Win2K-f 219.114.249.200 (ZAQ.NE.JP):
J:COM WEST CO. LTD,
OSAKA, OSAKA, JP. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
76 lines
Yeah : 1.3
profile
none summary
tarball
0 of 33
33 of 33
2e45ae247e
NEW
53bfe15e91
NEW
36aa8cd03d [0]
1473091351[0]
none:none
ASM:Graph
Armadillo|
tElock|
none
lines=75
embedded dns
trace
trace
T:02:04:00 WinXP 64.144.35.70 (MEGAPATH.NET):
MEGAPATH NETWORKS INC,
JERSEY CITY, NEW JERSEY, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:02:09:00 Win2K-f 211.187.97.165 (SONICANT.CO.KR):
THRUNET CO. LTD,
SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL)
218.93.205.30:65520 EU:proxima.ircgalaxy.pl
US:microsoft.com
EU:gidromash.cn
:nenastiya.cn
CN:config1007.iwillhavesexygirls.com
:wws.mobiec.net
CN:maillist.iwillhavesexygirls.com
US:xz.ub9.net
:in.7cy.net
:in1.7cy.net
US:theglobegallery.com
:www.google-analytics.com
US:64.95.64.197:80
EU:91.206.201.39:80
135 pcap raw alerts
ruleset
irc
http
144 lines
Yeah : 1.8
profile
none summary
tarball
31 of 41
34 of 36
12 of 41
3 of 41
34 of 41
30 of 33
1fa41f09fc
NEW
24e59ab043
NEW
3c6b773d78
NEW
a62f6fc33b
NEW
ef5fd50f61
NEW
ff2150aa95
NEW
8267b23408 [0]
778da26bf3[0]
fb2dc717f9[0]
020eee55f3[0]
c932de5e59[0]
6e55004755[0]
none:none
none:none
none:none
none:none
none:none
none:none
Armadillo|
Armadillo|
Armadillo|
StarForce|
StarForce|
tElock|
none
none
none
none
none
none
trace
trace
trace
trace
trace
trace
T:02:12:00 WinXP 62.11.40.39 (DIALUP.TISCALI.IT):
TISCALI ITALIA SPA,
RIMINI, EMILIA-ROMAGNA, IT. (DIAL)
n/a EU:siliconfireware.ru
GB:new.egg.com
:wpad
US:searchportal.information.com
US:spi.domainsponsor.com
DE:212.227.111.29:80
DE:217.11.54.126:80
EU:78.47.200.154:80
445 pcap raw alerts
ruleset
http
http
http
37 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 a12cab51ef
NEW
none[0] none:none
ASPack| lines=281
embedded dns
trace
T:02:19:00 Win2K-f 74.222.107.27 (FTC-I.NET):
FARMERS TELEPHONE COOPERATIVE INC,
SUMTER, SOUTH CAROLINA, US. (DSL)
91.212.220.75:65520 US:microsoft.com
US:getrichquickbusiness.com
US:searchportal.information.com
US:spi.domainsponsor.com
US:ads1.revenue.net
US:as.casalemedia.com
US:activex.microsoft.com
US:codecs.microsoft.com
:xz.ub9.net
EU:proxima.ircgalaxy.pl
EU:gidromash.cn
EU:ottopay.cn
:nenastiya.cn
CN:config1007.iwillhavesexygirls.com
:wws.mobiec.net
CN:www.petdoso.com
:jnmr.com
:hf.davinci.com
CN:maillist.iwillhavesexygirls.com
US:faxwelt.com
:www.statcounter.com
:c.statcounter.com
US:www.themakecash.com
:datingpopular.com
US:emphasisi.com
:incometaxliabilities.com
:sqltop.net
CA:bestgamingoffers.com
US:dealandplay.com
US:freeonly.net
US:shopmastersdegree.info
US:cellphonesdish.info
174.36.176.242:81
US:208.109.98.106:80
445 pcap raw alerts
ruleset
http
irc
84 lines
Yeah : 1.3
profile
none summary
tarball
17 of 41
31 of 41
12 of 41
0 of 41
3 of 41
0 of 41
7 of 41
34 of 41
1c5e79f5f4
NEW
1fa41f09fc
NEW
3c6b773d78
NEW
8b9732ded9
NEW
a62f6fc33b
NEW
c3c12f9578
NEW
c7830331fc
NEW
ef5fd50f61
NEW
none[4]
8267b23408[0]
fb2dc717f9[0]
none [4]
020eee55f3[0]
none [4]
7953649664[0]
c932de5e59[0]
none:none
none:none
none:none
none:none
none:none
none:none
none:none
none:none
FSG|
Armadillo|
Armadillo|
none|none
StarForce|
none|none
tElock|
StarForce|
none
none
none
none
none
none
none
none
trace
trace
trace
trace
trace
trace
trace
trace
T:04:11:00 Win2K-f 196.208.67.52 (TELKOMADSL.CO.ZA):
AFRINIC,
JOHANNESBURG, GAUTENG, ZA. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
149 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41
39 of 41
1bc51bf964
NEW
e33c8e30b9
NEW
4ab7eeaf6c [0]
95caa6a57d[0]
none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
T:04:16:00 WinXP 85.176.240.238 (ALICEDSL.DE):
HANSENET-ADSL,
WURZBURG, BAYERN, DE. (DSL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32 741e3b03b3
NEW
none[0] none:none
none|none lines=61 trace
T:04:52:00 WinXP 74.65.164.131 (RR.COM):
ROAD RUNNER HOLDCO LLC,
SOUTH PORTLAND, MAINE, US. (DSL)
n/a RU:citi-bank.ru
RU:213.219.245.212:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:04:58:00 Win2K-f 173.29.130.232 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
CHANHASSEN, MINNESOTA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
36 of 41
38 of 40
067917e07b
NEW
d764c1dcb2
NEW
dae35b319c [0]
3d2bc60c5d[0]
none:none
none:none
Armadillo|
tElock|
none
none
trace
trace
T:05:47:00 Win2K-f 195.137.30.127 (FREEDOM2SURF.NET):
FREEDOM TO SURF LTD,
LONDON, ENGLAND, UK. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
39 of 41
40 of 41
99c07c4fd6
NEW
bc43f0abc4
NEW
bbf30ef165 [0]
67bede154c[0]
none:none
none:none
Armadillo|
tElock|
none
none
trace
trace
T:07:16:00 WinXP 98.141.9.117 (CAVTEL.NET):
CAVALIER TELEPHONE,
VIRGINIA BEACH, VIRGINIA, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:07:42:00 WinXP 69.4.99.185 (AIRSTREAMCOMM.NET):
AMERY TELEPHONE COMPANY,
RICE LAKE, WISCONSIN, US. (DSL)
n/a RU:citi-bank.ru
RU:213.219.245.212:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 0cfab99612
NEW
none[0] ASM:Graph
PolyEnE| lines=68 trace
T:08:27:00 Win2K-f 4.231.158.81 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
HUMBLE, TEXAS, US. (DIAL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
77 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:10:07:00 WinXP 203.180.17.238 (BMOBILE.NE.JP):
JAPAN COMMUNICATION INC,
TOKYO, TOKYO, JP. (DSL)
82.98.86.170:80 DE:siliconfireware.ru
US:searchportal.information.com
US:spi.domainsponsor.com
DE:ebookfinaltrash.ru
:wpad
445 pcap raw alerts
ruleset
http
http
http
http
http
29 lines
Yeah : 1.3
profile
none summary
tarball
31 of 41 e49826ceaa
NEW
none[4] none:none
ASPack| none trace
T:10:08:00 WinXP 70.235.77.227 (SBCGLOBAL.NET):
AT&T INTERNET SERVICES,
WEST HARTFORD, CONNECTICUT, US. (DSL)
n/a US:www.yahoo.com
:www.google.com.au
:jbeegvia.ru
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
32 of 32 bb7681eca8
NEW
none[3] none:none
tElock| none trace
T:10:26:00 WinXP 76.172.181.154 (RR.COM):
ROAD RUNNER HOLDCO LLC,
NORTH HOLLYWOOD, CALIFORNIA, US. (100Mbps)
213.219.245.212:80 RU:citi-bank.ru
RU:213.219.245.212:80
445 pcap raw alerts
ruleset
http
3 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 3ae357d17b
NEW
none[0] ASM:Graph
PolyEnE| lines=73 trace
T:10:27:00 WinXP 4.253.119.11 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
KNOX, INDIANA, US. (DIAL)
n/a :moscow-advokat.ru
SE:coins.dal.net
:gaspode.zanet.org.za
:flanders.be.eu.undernet.org
:los-angeles.ca.us.undernet.org
AT:graz.at.eu.undernet.org
SE:broadway.ny.us.dal.net
:washington.dc.us.undernet.org
:caen.fr.eu.undernet.org
SE:vancouver.dal.net
NL:diemen.nl.eu.undernet.org
:brussels.be.eu.undernet.org
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
25 of 25 7f60162c2c
NEW
none[0] none:none
PolyEnE| lines=93
embedded dns
trace
T:11:00:00 WinXP 4.236.15.13 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
NEW YORK, NEW YORK, US. (DIAL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:11:15:00 WinXP 95.84.167.222 (NATIONALCABLENETWORKS.RU):
NCNET BROADBAND CUSTOMERS,
MOSCOW, MOSCOW CITY, RU. (DSL)
n/a DE:siliconfireware.ru
US:searchportal.information.com
US:spi.domainsponsor.com
:wpad
445 pcap raw alerts
ruleset
http
http
http
19 lines
Yeah : 0.8
profile
none summary
tarball
41 of 41 2949a0ad17
NEW
0b5f65174a [0] none:none
ASPack| none trace
T:11:36:00 Win2K-f 173.29.252.46 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
CHANHASSEN, MINNESOTA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
36 of 41
38 of 40
067917e07b
NEW
d764c1dcb2
NEW
dae35b319c [0]
3d2bc60c5d[0]
none:none
none:none
Armadillo|
tElock|
none
none
trace
trace
T:13:34:00 WinXP 87.173.76.3 (T-DIALIN.NET):
DEUTSCHE TELEKOM AG,
MAGDEBURG, SACHSEN-ANHALT, DE. (DIAL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32 741e3b03b3
NEW
none[0] none:none
none|none lines=61 trace
T:14:32:00 Win2K-f 173.171.247.163 (RR.COM):
ROAD RUNNER HOLDCO LLC,
TAMPA, FLORIDA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:14:45:00 WinXP 209.143.37.21 (BRIGHT.NET):
WABASH COMMUNICATIONS,
CELINA, OHIO, US. (DIAL)
n/a EU:siliconfireware.ru
US:searchportal.information.com
US:spi.domainsponsor.com
:www.proxy-socks.net
:wpad
445 pcap raw alerts
ruleset
http
http
24 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 a12cab51ef
NEW
none[0] none:none
ASPack| lines=281
embedded dns
trace
T:15:04:00 WinXP 71.108.47.7 (VERIZON.NET):
VERIZON INTERNET SERVICES INC,
LONG BEACH, CALIFORNIA, US. (DSL)
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
39 of 41 2f6afffda4
NEW
ede9ae4e6d [0] none:none
PolyEnE| none trace
T:16:07:00 Win2K-f 72.67.206.75 (VERIZON.NET):
VERIZON INTERNET SERVICES INC,
LOS ANGELES, CALIFORNIA, US. (DSL)
92.240.234.164:3305 FI:cx10man.weedns.com 135 pcap raw alerts
ruleset
irc
607 lines
Yeah : 1.8
profile
none summary
tarball
38 of 41 69f8ccc92e
NEW
e9613e6868 [0] none:none
StarForce| none trace
T:16:51:00 WinXP 76.177.107.0 (RR.COM):
ROAD RUNNER HOLDCO LLC,
WINCHESTER, KENTUCKY, US. (DSL)
n/a :moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
NEW
none[0] none:none
PolyEnE| lines=93
embedded dns
trace
17:11:00 WinXP 76.177.107.0 (RR.COM):
ROAD RUNNER HOLDCO LLC,
WINCHESTER, KENTUCKY, US. (DSL)
n/a :moscow-advokat.ru
NO:london.uk.eu.undernet.org
:los-angeles.ca.us.undernet.org
SE:qis.md.us.dal.net
SE:ozbytes.dal.net
:washington.dc.us.undernet.org
SE:ced.dal.net
:caen.fr.eu.undernet.org
SE:coins.dal.net
:gaspode.zanet.org.za
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
25 of 25 7f60162c2c
NEW
none[0] none:none
PolyEnE| lines=93
embedded dns
trace
T:17:33:00 WinXP 96.49.4.72 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
RICHMOND, BRITISH COLUMBIA, CA. (DSL)
92.240.234.164:3305 JP:cx10man.weedns.com 135 pcap raw alerts
ruleset
irc
609 lines
Yeah : 1.8
profile
none summary
tarball
39 of 41 616f21b486
NEW
348063e1c2 [0] none:none
StarForce| none trace
T:18:04:00 Win2K-f 211.244.63.98 (SONICANT.CO.KR):
THRUNET CO. LTD,
SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL)
91.212.220.75:65520 CN:proxim.ircgalaxy.pl
US:microsoft.com
EU:gidromash.cn
EU:ottopay.cn
CN:www.petdoso.com
174.36.176.242:81
EU:91.212.220.75:65520
135 pcap raw alerts
ruleset
irc
http
137 lines
Yeah : 1.8
profile
none summary
tarball
17 of 41
29 of 32
28 of 32
7 of 41
1c5e79f5f4
NEW
8a75955033
NEW
9276c8b36b
NEW
c7830331fc
NEW
none[4]
2bf3e548b9[0]
none [0]
7953649664[0]
none:none
ASM:Graph
ASM:Graph
none:none
FSG|
tElock|
Armadillo|
tElock|
none
lines=126
embedded dns
lines=81
none
trace
trace
trace
trace
T:18:27:00 WinXP 63.27.188.214 (UU.NET):
UUNET TECHNOLOGIES INC,
RICHLAND, MICHIGAN, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
197 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:18:29:00 Win2K-f 124.169.197.151 (IINET.NET.AU):
IINET LIMITED,
PERTH, WESTERN AUSTRALIA, AU. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
165 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:18:32:00 WinXP 4.231.154.77 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
HUMBLE, TEXAS, US. (DIAL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
99 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:22:28:00 WinXP 96.53.218.131 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
SHERWOOD PARK, ALBERTA, CA. (DSL)
n/a :gg.arrancar.org 135 pcap raw alerts
ruleset
other
188 lines
Yeah : 1.3
profile
none summary
tarball
34 of 39 ce28648035
NEW
126d2f4655 [0] ASM:Graph
none|none lines=546 trace