Welcome to the Cyber-TA
Daily Malware Binary DIGEST Summary Page



09 December 2009

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.



Packed
MD5
UnPacket
MD5
Victim
OS
AntiVirus
Hit-Cnt
First
Encounter
Last
Encounter
Freq
Cnt
Behavioral
Clusters
Unpacked
Egg.asm
Packer
Fingerprint
API
Resolution
String
Cnt
Syscall
Trace
ee4c5c80ea
NEW
28944e2541 [0] WinXP 35 of 39 07:03:03 07:03:03 1 none ASM:Graph
tElock| 100% lines=42 trace
093fe30898
NEW
358dcb5ee9
NEW
6724d42b18
NEW
785e86954f
NEW
a2f35954d8
NEW
none[none]
56844d37cb[none]
94a1eb4d51[none]
c6edee8e8b[0]
none [none]
Win2K-f 31 of 41 06:10:12 06:10:12 1 none none:none
none:none
none:none
none:none
none:none
none|none
none|none
UPX|
PeStubOEP|
FSG|
none
none
none
none
none
none
none
none
trace
none
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
Win2K-f
WinXP
0 of 32 11:49:49 22:07:18 3 none ASM:Graph
none:none
tElock|
Armadillo|
0% lines=75
embedded dns
lines=90
trace
trace
14f47ffd1e
NEW
90bf4b99ff [0] Win2K-f 40 of 41 22:44:54 22:44:54 1 none none:none
tElock| none trace
53bfe15e91
NEW
1473091351 [0] Win2K-f
WinXP
33 of 33 01:24:45 22:07:18 6 none ASM:Graph
tElock| 96% lines=75
embedded dns
trace
533d15b5ce
NEW
58c343a8d8
NEW
785e86954f
NEW
fc390a4f44
NEW
c67adf46e2 [0]
none [0]
c6edee8e8b[0]
none [none]
WinXP 31 of 41 16:56:37 16:56:37 1 none ASM:Graph
none:none
none:none
none:none
tElock|
Armadillo|
PeStubOEP|
FSG|
lines=126
embedded dns
lines=91
none
none
trace
trace
trace
none
df17a625ee
NEW
none[0] WinXP 29 of 29 01:15:06 01:15:06 1 none none:none
ASPack| 72% lines=298
embedded dns
trace
8b41cb7a41
NEW
ef18d720f3 [0] Win2K-f 3 of 41 21:12:11 21:12:11 1 none none:none
Armadillo| none trace
093fe30898
NEW
none[none] Win2K-f 0 of 41 06:10:12 06:10:12 1 none none:none
none|none none none
cc88f4f016
NEW
3d17903825 [0] Win2K-f 31 of 41 13:29:40 13:29:40 1 none none:none
StarForce| none trace
093fe30898
NEW
358dcb5ee9
NEW
none[none]
56844d37cb[none]
Win2K-f 38 of 41 06:10:12 06:10:12 1 none none:none
none:none
none|none
none|none
none
none
none
none
c1918274c2
NEW
c71803882e [none] WinXP 39 of 41 19:32:00 19:32:00 1 none none:none
PolyEnE| none none
0e927ffe94
NEW
e9e756f828 [none] Win2K-f 39 of 41 23:56:27 23:56:27 1 none none:none
Armadillo| none none
093fe30898
NEW
358dcb5ee9
NEW
6724d42b18
NEW
785e86954f
NEW
a2f35954d8
NEW
c285951e81
NEW
cc91564fec
NEW
none[none]
56844d37cb[none]
94a1eb4d51[none]
c6edee8e8b[0]
none [none]
fe138a693a[none]
2677ae881c[none]
Win2K-f 9 of 41 06:10:12 06:10:12 1 none none:none
none:none
none:none
none:none
none:none
none:none
none:none
none|none
none|none
UPX|
PeStubOEP|
FSG|
StarForce|
PeCompact|
none
none
none
none
none
none
none
none
none
none
trace
none
none
none
8b41cb7a41
NEW
97fef473b9
NEW
ef18d720f3 [0]
ff4e7d6992[0]
Win2K-f 33 of 33 21:12:11 21:12:11 1 none none:none
none:none
Armadillo|
tElock|
none
none
trace
trace
5d445c59d8
NEW
892e12db7b [0] Win2K-f 39 of 41 05:33:24 05:33:24 1 none none:none
tElock| none trace
f3932b94a6
NEW
910494cc45 [0] Win2K-f 40 of 41 23:11:45 23:11:45 1 none none:none
none|none none trace
533d15b5ce
NEW
c67adf46e2 [0] WinXP 30 of 33 16:56:37 16:56:37 1 none ASM:Graph
tElock| 96% lines=126
embedded dns
trace
a12cab51ef
NEW
none[0] WinXP 29 of 29 11:44:02 12:06:26 2 none none:none
ASPack| 54% lines=281
embedded dns
trace
0e927ffe94
NEW
70d9f45041
NEW
aa109808e5
NEW
e9e756f828 [none]
b91fd75bfa[none]
169a6e454c[none]
Win2K-f 5 of 41 23:56:27 23:56:27 1 none none:none
none:none
none:none
Armadillo|
tElock|
ASPack|
none
none
none
none
none
none
03f912899b
NEW
none[0] WinXP 32 of 32 00:08:11 00:08:11 1 none none:none
none|none 32% lines=64 trace
0e927ffe94
NEW
70d9f45041
NEW
e9e756f828 [none]
b91fd75bfa[none]
Win2K-f 38 of 41 23:56:27 23:56:27 1 none none:none
none:none
Armadillo|
tElock|
none
none
none
none
7f60162c2c
NEW
none[0] WinXP 25 of 25 06:19:47 19:18:22 2 none none:none
PolyEnE| 100% lines=93
embedded dns
trace
ee4c5c80ea
NEW
f37bd4ab26
NEW
28944e2541 [0]
c78cfe6339[0]
WinXP 36 of 39 07:03:03 07:03:03 1 none ASM:Graph
ASM:Graph
tElock|
tElock|
96% lines=42
lines=64
embedded dns
trace
trace
741e3b03b3
NEW
none[0] WinXP 31 of 32 02:16:21 02:16:21 1 none none:none
none|none 32% lines=61 trace
aad01ff2b9
NEW
719867f96c [0] Win2K-f 39 of 40 21:31:30 21:31:30 1 none none:none
StarForce| none trace
093fe30898
NEW
358dcb5ee9
NEW
6724d42b18
NEW
none[none]
56844d37cb[none]
94a1eb4d51[none]
Win2K-f 14 of 41 06:10:12 06:10:12 1 none none:none
none:none
none:none
none|none
none|none
UPX|
none
none
none
none
none
none
5d445c59d8
NEW
8a54950abb
NEW
892e12db7b [0]
f6b9e43917[0]
Win2K-f 37 of 40 05:33:24 05:33:24 1 none none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
0e927ffe94
NEW
70d9f45041
NEW
aa109808e5
NEW
c285951e81
NEW
e9e756f828 [none]
b91fd75bfa[none]
169a6e454c[none]
fe138a693a[none]
Win2K-f 11 of 41 06:10:12 23:56:27 2 none none:none
none:none
none:none
none:none
Armadillo|
tElock|
ASPack|
StarForce|
none
none
none
none
none
none
none
none
533d15b5ce
NEW
58c343a8d8
NEW
c67adf46e2 [0]
none [0]
WinXP 28 of 33 16:56:37 16:56:37 1 none ASM:Graph
none:none
tElock|
Armadillo|
0% lines=126
embedded dns
lines=91
trace
trace
9865c6b08a
NEW
74a4d89dcb [none] WinXP 39 of 41 12:53:29 12:53:29 1 none none:none
PolyEnE| none none
785e86954f
NEW
95e0bce7d1
NEW
9b6ea363eb
NEW
c6edee8e8b [0]
none [none]
7a32f7a54f[none]
Win2K-f 23 of 41 06:19:36 06:19:36 1 none none:none
none:none
none:none
PeStubOEP|
FSG|
UPX|
none
none
none
trace
none
none
7d99b0e910
NEW
none[0] WinXP 26 of 28 02:02:32 19:42:28 2 none none:none
PolyEnE| 99% lines=68 trace
533d15b5ce
NEW
58c343a8d8
NEW
785e86954f
NEW
c67adf46e2 [0]
none [0]
c6edee8e8b[0]
Win2K-f
WinXP
29 of 41 06:10:12 16:56:37 3 none ASM:Graph
none:none
none:none
tElock|
Armadillo|
PeStubOEP|
lines=126
embedded dns
lines=91
none
trace
trace
trace
785e86954f
NEW
95e0bce7d1
NEW
c6edee8e8b [0]
none [none]
Win2K-f 31 of 41 06:19:36 06:19:36 1 none none:none
none:none
PeStubOEP|
FSG|
none
none
trace
none
53bfe15e91
NEW
57ce4acac2
NEW
1473091351 [0]
none [0]
Win2K-f 0 of 33 08:23:59 08:23:59 1 none ASM:Graph
none:none
tElock|
Armadillo|
0% lines=75
embedded dns
lines=90
trace
trace
14f47ffd1e
NEW
50437008d9
NEW
90bf4b99ff [0]
c1b09ac5d7[0]
Win2K-f 5 of 41 22:44:54 22:44:54 1 none none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
093fe30898
NEW
358dcb5ee9
NEW
6724d42b18
NEW
785e86954f
NEW
a2f35954d8
NEW
c285951e81
NEW
cc91564fec
NEW
f261981059
NEW
none[none]
56844d37cb[none]
94a1eb4d51[none]
c6edee8e8b[0]
none [none]
fe138a693a[none]
2677ae881c[none]
269dcd9909[none]
Win2K-f 11 of 41 06:10:12 06:10:12 1 none none:none
none:none
none:none
none:none
none:none
none:none
none:none
none:none
none|none
none|none
UPX|
PeStubOEP|
FSG|
StarForce|
PeCompact|
Mew|
none
none
none
none
none
none
none
none
none
none
none
trace
none
none
none
none
1a2c0e6130
NEW
none[0] WinXP 29 of 29 08:31:33 08:31:33 1 none none:none
none|none 33% lines=60 trace
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
Win2K-f 0 of 33 01:24:45 17:04:35 2 none ASM:Graph
none:none
tElock|
Armadillo|
0% lines=75
embedded dns
lines=90
trace
trace
b8076e37ae
NEW
52953fed05 [0] Win2K-f 28 of 41 22:35:12 22:35:12 1 none none:none
StarForce| none trace
5285741560
NEW
60590b8b67 [0] WinXP 37 of 40 19:02:09 19:02:09 1 none ASM:Graph
none|none 55% lines=59 trace
d9cb288f31
NEW
45603a001c [0] Win2K-f 3 of 37 05:15:31 05:25:05 2 none ASM:Graph
UPX| 92% lines=174
embedded dns
trace