Welcome to the Cyber-TA
Daily Malware Binary DIGEST Summary Page



13 November 2009

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.



Packed
MD5
UnPacket
MD5
Victim
OS
AntiVirus
Hit-Cnt
First
Encounter
Last
Encounter
Freq
Cnt
Behavioral
Clusters
Unpacked
Egg.asm
Packer
Fingerprint
API
Resolution
String
Cnt
Syscall
Trace
6c4f8d0b05
NEW
c15495ec45 [0] Win2K-f 36 of 41 05:48:21 05:48:21 1 none none:none
Armadillo| none trace
10759405e0
NEW
292d343248 [0] Win2K-f 38 of 41 23:37:56 23:37:56 1 none none:none
Armadillo| none trace
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
WinXP
Win2K-f
0 of 32 01:00:26 03:27:06 2 none ASM:Graph
none:none
tElock|
Armadillo|
0% lines=75
embedded dns
lines=90
trace
trace
3633185e02
NEW
55d194738a [0] WinXP 39 of 41 01:08:59 01:08:59 1 none none:none
Armadillo| none trace
2fa130feec
NEW
83192a6119
NEW
8a06db2aef [0]
fdc95e1fab[0]
WinXP 15 of 41 13:31:13 13:31:13 1 none none:none
none:none
Armadillo|
none|none
none
none
trace
trace
bea8cb1865
NEW
fac78fde16
NEW
154de51a66 [0]
882896ab05[0]
Win2K-f 35 of 36 05:10:19 05:10:19 1 none ASM:Graph
none:none
Armadillo|
tElock|
lines=91
none
trace
trace
53bfe15e91
NEW
1473091351 [0] WinXP
Win2K-f
33 of 33 01:00:26 21:21:51 6 none ASM:Graph
tElock| 96% lines=75
embedded dns
trace
11cde67678
NEW
331145624c
NEW
7634ac1997
NEW
9af8e2f833 [0]
e7124c9b61[0]
9af8e2f833[0]
WinXP 10 of 41 02:16:17 02:16:17 1 none none:none
none:none
none:none
FSG|
Stranik|
FSG|
none
none
none
trace
trace
trace
53bfe15e91
NEW
b7082104e4
NEW
1473091351 [0]
c5b49e7b82[0]
Win2K-f 8 of 33 20:24:28 21:21:51 2 none ASM:Graph
ASM:Graph
tElock|
tElock|
100% lines=75
embedded dns
lines=41
trace
trace
75af48afe4
NEW
7a25f9e3cf [0] Win2K-f 22 of 41 07:32:28 07:32:28 1 none none:none
StarForce| none trace
7016d3fe8b
NEW
3a5ff804e9 [0] WinXP 39 of 41 04:17:09 04:17:09 1 none none:none
Armadillo| none trace
95308db598
NEW
afdd2b80c4 [0] WinXP 40 of 41 06:14:49 06:14:49 1 none none:none
PolyEnE| none trace
11cde67678
NEW
331145624c
NEW
9af8e2f833 [0]
e7124c9b61[0]
WinXP 38 of 40 02:16:17 02:16:17 1 none none:none
none:none
FSG|
Stranik|
none
none
trace
trace
be7f428663
NEW
0ee7526007 [0] WinXP 40 of 41 03:53:57 03:53:57 1 none none:none
Stranik| none trace
11cde67678
NEW
9af8e2f833 [0] WinXP 10 of 41 02:16:17 02:16:17 1 none none:none
FSG| none trace
912a073945
NEW
7874c7f21e [0] WinXP 39 of 41 15:03:41 15:03:41 1 none none:none
PolyEnE| none trace
2fa130feec
NEW
83192a6119
NEW
85c00cc118
NEW
9354673997
NEW
8a06db2aef [0]
fdc95e1fab[0]
none [3]
60e874b776[0]
WinXP 29 of 41 13:31:13 13:31:13 1 none none:none
none:none
none:none
none:none
Armadillo|
none|none
StarForce|
none|none
none
none
none
none
trace
trace
trace
trace
84ace068d1
NEW
c822a7d0e4 [0] Win2K-f 38 of 40 22:19:45 22:19:45 1 none none:none
tElock| none trace
a12cab51ef
NEW
none[0] WinXP 29 of 29 13:05:22 13:05:22 1 none none:none
ASPack| 54% lines=281
embedded dns
trace
522832a551
NEW
0c7f5442b0 [0] WinXP 40 of 41 22:21:21 22:21:21 1 none none:none
PolyEnE| none trace
3d5b054328
NEW
29e313e61c [0] Win2K-f 39 of 41 04:00:50 04:00:50 1 none none:none
Armadillo| none trace
55667c4a85
NEW
bac4cc6eec [0] Win2K-f 39 of 40 01:11:19 02:13:13 2 none none:none
Armadillo| none trace
2fa130feec
NEW
83192a6119
NEW
85c00cc118
NEW
8a06db2aef [0]
fdc95e1fab[0]
none [3]
WinXP 7 of 41 13:31:13 13:31:13 1 none none:none
none:none
none:none
Armadillo|
none|none
StarForce|
none
none
none
trace
trace
trace
166484192b
NEW
2a1e547005
NEW
0c886fcb7b [0]
5c75fa020a[0]
Win2K-f 37 of 39 16:18:35 16:18:35 1 none none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
2fa130feec
NEW
83192a6119
NEW
85c00cc118
NEW
9354673997
NEW
dab4da4e21
NEW
8a06db2aef [0]
fdc95e1fab[0]
none [3]
60e874b776[0]
e63b813015[0]
WinXP 37 of 39 13:31:13 13:31:13 1 none none:none
none:none
none:none
none:none
ASM:Graph
Armadillo|
none|none
StarForce|
none|none
PolyEnE|
100% none
none
none
none
lines=134
trace
trace
trace
trace
trace
ca8da15194
NEW
b6fc2a1593 [0] WinXP 39 of 41 01:26:36 01:26:36 1 none none:none
Armadillo| none trace
f4a8e6a51e
NEW
acd8693185 [0] Win2K-f 39 of 41 02:27:37 02:27:37 1 none none:none
Armadillo| none trace
84ace068d1
NEW
c584af4fcd
NEW
c822a7d0e4 [0]
bdfcf0a930[0]
Win2K-f 36 of 41 22:19:45 22:19:45 1 none none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
dd02947289
NEW
none[0] WinXP 29 of 29 18:37:11 18:37:11 1 none ASM:Graph
PolyEnE| 99% lines=68 trace
2fa130feec
NEW
8a06db2aef [0] WinXP 10 of 41 13:31:13 13:31:13 1 none none:none
Armadillo| none trace
5d31fa2adf
NEW
8992c05119 [0] WinXP 38 of 41 03:16:14 03:16:14 1 none none:none
Armadillo| none trace
b0c46107a6
NEW
bac4cc6eec [0] Win2K-f 33 of 41 01:54:25 01:54:25 1 none none:none
Armadillo| none trace
024410ad21
NEW
b0cedd71bb
NEW
96d0267b80 [0]
f6e156bdca[0]
Win2K-f 38 of 40 14:43:57 14:43:57 1 none none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
c34d3ada53
NEW
9b9b17a286 [0] WinXP 37 of 41 04:13:14 04:13:14 1 none none:none
Armadillo| none trace
8ab0fb88b8
NEW
968cc91789 [0] WinXP 39 of 40 20:06:09 20:06:09 1 none none:none
none|none none trace
ec8ab501b3
NEW
bac4cc6eec [0] Win2K-f
WinXP
40 of 41 01:29:47 05:08:19 4 none none:none
Armadillo| none trace
bea8cb1865
NEW
154de51a66 [0] Win2K-f 32 of 36 05:10:19 05:10:19 1 none ASM:Graph
Armadillo| 0% lines=91 trace
4180c19d91
NEW
b6e91e001c
NEW
9f3f2de385 [0]
d2275a6cf5[0]
Win2K-f 38 of 41 15:57:53 15:57:53 1 none none:none
none:none
Armadillo|
PolyEnE|
none
none
trace
trace
166484192b
NEW
0c886fcb7b [0] Win2K-f 37 of 39 16:18:35 16:18:35 1 none none:none
tElock| none trace
0cfab99612
NEW
none[0] WinXP 29 of 29 15:27:31 15:27:31 1 none ASM:Graph
PolyEnE| 99% lines=68 trace
da9e21ae21
NEW
d3271206dd [0] WinXP 40 of 41 13:31:46 13:31:46 1 none none:none
ASPack| none trace
7d99b0e910
NEW
none[0] WinXP 26 of 28 09:23:22 23:51:07 3 none none:none
PolyEnE| 99% lines=68 trace
10759405e0
NEW
d08e00dfaf
NEW
292d343248 [0]
854c49d8c4[0]
Win2K-f 39 of 41 23:37:56 23:37:56 1 none none:none
none:none
Armadillo|
tElock|
none
none
trace
trace
ffda37e02b
NEW
2669ff2865 [0] Win2K-f 39 of 41 02:42:35 02:42:35 1 none none:none
Armadillo| none trace
73d9e10cba
NEW
de3bdf7b4e
NEW
15076d5de4 [0]
ff08fc71e3[0]
WinXP 39 of 41 12:10:26 12:10:26 1 none none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
024410ad21
NEW
96d0267b80 [0] Win2K-f 40 of 41 14:43:57 14:43:57 1 none none:none
tElock| none trace
ac24fa21de
NEW
374bf86707 [0] WinXP 39 of 40 07:39:30 07:39:30 1 none none:none
Stranik| none trace
7793daa779
NEW
5dac538fbc [0] Win2K-f 39 of 41 01:43:00 01:43:00 1 none none:none
Armadillo| none trace
73d9e10cba
NEW
15076d5de4 [0] WinXP 40 of 41 12:10:26 12:10:26 1 none none:none
tElock| none trace
8ab6e70b64
NEW
72feb43272 [0] Win2K-f 39 of 41 03:19:37 03:19:37 1 none none:none
Armadillo| none trace
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
WinXP
Win2K-f
0 of 33 06:51:15 14:23:37 3 none ASM:Graph
none:none
tElock|
Armadillo|
0% lines=75
embedded dns
lines=90
trace
trace
de37f2fc47
NEW
bac4cc6eec [0] WinXP 33 of 41 01:44:53 04:56:18 2 none none:none
Armadillo| none trace
3bff218b8f
NEW
7eaf7b4470
NEW
b570b734be [0]
8e0b194526[0]
WinXP 39 of 41 16:38:17 16:38:17 1 none none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
3bff218b8f
NEW
b570b734be [0] WinXP 40 of 41 16:38:17 16:38:17 1 none none:none
tElock| none trace
f2a8dafb30
NEW
1d0f660523 [0] WinXP 39 of 41 18:20:26 18:20:26 1 none none:none
PolyEnE| none trace
4180c19d91
NEW
9f3f2de385 [0] Win2K-f 37 of 41 15:57:53 15:57:53 1 none none:none
Armadillo| none trace
5285741560
NEW
60590b8b67 [0] WinXP 37 of 40 05:32:22 22:33:03 2 none ASM:Graph
none|none 55% lines=59 trace
a55778ac1c
NEW
97e2f1618d [0] Win2K-f 37 of 40 03:12:47 03:12:47 1 none none:none
Armadillo| none trace