Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

20 January 2010
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
T:00:15:00 WinXP 87.97.236.142 (PL.EKK.BG):
EKK CATV PLOVDIV,
PLOVDIV, PLOVDIV, BG. (DSL)
n/a   445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
41 of 41 4c98856d0a
NEW
none[none] none:none
none|none none none
T:01:13:00 WinXP 188.192.49.180 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
DE. (DSL)
n/a DE:siliconfireware.ru
US:searchportal.information.com
US:spi.domainsponsor.com
:wpad
:www.proxy-socks.net
US:208.73.210.125:80
DE:217.11.54.126:80
EU:78.47.200.154:80
445 pcap raw alerts
ruleset
http
http
http
15 lines
Yeah : 0.8
profile
none summary
tarball
0 of 41
0 of 41
29 of 29
534d67ba88
NEW
932ec98166
NEW
df17a625ee
NEW
none[none]
none [none]
none [0]
none:none
none:none
none:none
none|none
none|none
ASPack|
none
none
lines=298
embedded dns
none
none
trace
T:02:03:00 Win2K-f 174.5.180.78 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
CA. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
39 of 41
39 of 41
15b89b9fda
NEW
631bd3e5f4
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
T:02:16:00 WinXP 72.190.117.30 (RR.COM):
ROAD RUNNER HOLDCO LLC,
DALLAS, TEXAS, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:02:44:00 Win2K-f 70.62.129.88 (RR.COM):
ROAD RUNNER HOLDCO LLC,
MARYSVILLE, OHIO, US. (DSL)
n/a DE:proxim.ircgalaxy.pl
US:microsoft.com
135 pcap raw alerts
ruleset
irc
467 lines
Yeah : 1.3
profile
none summary
tarball
34 of 36
33 of 36
644b2a1105
NEW
9c9ab20965
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
T:03:44:00 Win2K-f 61.105.4.242 (KRLINE.NET):
KRNIC,
SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL)
218.93.201.51:65520 US:microsoft.com
DE:proxim.ircgalaxy.pl
135 pcap raw alerts
ruleset
irc
149 lines
Yeah : 1.8
profile
none summary
tarball
39 of 41
38 of 41
0e927ffe94
NEW
70d9f45041
NEW
e9e756f828 [0]
b91fd75bfa[0]
none:none
none:none
Armadillo|
tElock|
none
none
trace
trace
T:03:58:00 WinXP 196.208.64.126 (TELKOMADSL.CO.ZA):
AFRINIC,
JOHANNESBURG, GAUTENG, ZA. (DSL)
n/a   135 pcap raw alerts
ruleset
other
58 lines
Yeah : 1.3
profile
none summary
tarball
0 of 32 73f1082158
NEW
none[0] none:none
Armadillo| lines=90 trace
T:05:36:00 Win2K-f 110.11.212.185 (-):
HANARO TELECOM,
SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
113 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41
5 of 41
14f47ffd1e
NEW
50437008d9
NEW
90bf4b99ff [0]
c1b09ac5d7[0]
none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
T:07:02:00 Win2K-f 222.223.194.28 (163DATA.COM.CN):
CHINANET HEBEI PROVINCE NETWORK,
BEIJING, BEIJING, CN. (DSL)
n/a NL:wow.blackirc.us 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:08:18:00 Win2K-f 174.1.81.145 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
VANCOUVER, BRITISH COLUMBIA, CA. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
111 lines
Yeah : 1.3
profile
none summary
tarball
37 of 41
38 of 41
3655e31f7f
NEW
66806feda7
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
09:10:00 WinXP 187.32.1.246 (VELOXZONE.COM.BR):
COMITE GESTOR DA INTERNET NO BRASIL,
SãO PAULO, SAO PAULO, BR. (DSL)
n/a RU:citi-bank.ru
RU:213.219.245.212:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
39 of 40 8fae42c0cc
NEW
none[none] none:none
none|none none none
T:09:42:00 Win2K-f 24.80.178.139 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
VANCOUVER, BRITISH COLUMBIA, CA. (DSL)
n/a CN:irc.zief.pl
CN:av.lometr.pl
:pozemle.cn
EU:pozeml.com
:commerceclick.co.uk
RU:ya.ru
CN:down1130.iwillhavesexygirls.com
FR:193.104.94.11:65520
CN:210.51.36.215:88
CN:61.235.117.71:80
EU:91.206.201.39:80
135 pcap raw alerts
ruleset
http
http
http
http
340 lines
Yeah : 1.3
profile
none summary
tarball
24 of 41
34 of 40
5fd727d3c1
NEW
a72398081f
NEW
none[none]
3f0ad45d1c[0]
none:none
none:none
none|none
tElock|
none
none
none
trace
T:10:00:00 Win2K-f 188.114.205.16 (-):
MAKSIM,
RU. (DSL)
n/a CN:irc.zief.pl
EU:pozeml.com
CN:down1130.iwillhavesexygirls.com
:pozemle.cn
CN:1130.kfgrtjer.cn
:bfkq.com
:jsactivity.com
CN:ty.lnlycnc.cn
US:search.toptravellingtips.com
US:64.191.44.5:80
US:72.20.40.25:555
445 pcap raw alerts
ruleset
http
97 lines
Yeah : 0.8
profile
none summary
tarball
16 of 41
6 of 41
8 of 41
15 of 41
4 of 41
21 of 41
11 of 41
0 of 41
5 of 41
142c22a4dc
NEW
3123f1aef8
NEW
3763090149
NEW
4a0015b136
NEW
8e7cffa818
NEW
9361d3ae2a
NEW
a2ce42b73d
NEW
b35c8c66f1
NEW
d497c896df
NEW
none[none]
none [none]
none [none]
none [none]
none [none]
none [none]
none [none]
none [none]
none [none]
none:none
none:none
none:none
none:none
none:none
none:none
none:none
none:none
none:none
none|none
none|none
none|none
none|none
none|none
none|none
none|none
none|none
none|none
none
none
none
none
none
none
none
none
none
none
none
none
none
none
none
none
none
none
T:10:52:00 WinXP 98.28.177.7 (RR.COM):
ROAD RUNNER HOLDCO LLC,
MASON, OHIO, US. (100Mbps)
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 1a2c0e6130
NEW
none[0] none:none
none|none lines=60 trace
10:58:00 Win2K-f 213.21.36.107 (-):
RU-DDCOM,
RU. (DSL)
n/a US:www.maxmind.com
:checkip.dyndns.org
US:67.15.94.80:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:11:07:00 Win2K-f 213.21.36.107 (-):
RU-DDCOM,
RU. (DSL)
n/a US:www.maxmind.com
US:www.getmyip.org
:checkip.dyndns.org
DE:131.220.6.26:80
US:67.15.94.80:80
445 pcap raw alerts
ruleset
http
5 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:11:59:00 Win2K-f 4.248.216.68 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
LA PLATA, MARYLAND, US. (DIAL)
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:12:41:00 Win2K-f 70.183.164.197 (COX.NET):
COX COMMUNICATIONS,
PROVIDENCE, RHODE ISLAND, US. (100Mbps)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:13:09:00 Win2K-f 173.29.253.168 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
CHANHASSEN, MINNESOTA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
38 of 41
39 of 41
10759405e0
NEW
d08e00dfaf
NEW
292d343248 [0]
854c49d8c4[0]
none:none
none:none
Armadillo|
tElock|
none
none
trace
trace
T:13:56:00 WinXP 118.231.14.34 (FETNET.NET):
FAR EASTONE TELECOMMUNICATION CO. LTD,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a :moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
33 of 36 d61760f6a1
NEW
22542b9b5e [0] none:none
PolyEnE| none trace
15:32:00 Win2K-f 190.105.23.235 (NET.AR):
VER TV S.A,
BUENOS AIRES, BUENOS AIRES, AR. (DSL)
n/a US:www.maxmind.com
:checkip.dyndns.org
DE:131.220.6.26:80
445 pcap raw alerts
ruleset
http
5 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 dc331fb791
NEW
none[3] none:none
UPX| none trace
T:15:41:00 Win2K-f 190.105.23.235 (NET.AR):
VER TV S.A,
BUENOS AIRES, BUENOS AIRES, AR. (DSL)
n/a US:www.maxmind.com
EU:getmyip.co.uk
GB:www.vouchercodez.com
:checkip.dyndns.org
DE:131.220.6.26:80
445 pcap raw alerts
ruleset
http
6 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 dc331fb791
NEW
none[3] none:none
UPX| none trace
T:16:17:00 Win2K-f 125.58.124.242 (STARCAT.NE.JP):
KMN CORPORATION,
NAGOYA, TOKYO, JP. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:16:34:00 Win2K-f 125.4.9.242 (ZAQ.NE.JP):
J:COM WEST CO. LTD,
OSAKA, OSAKA, JP. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
0 of 32
33 of 33
07fabc79ef
NEW
53bfe15e91
NEW
none[0]
1473091351[0]
ASM:Graph
ASM:Graph
Armadillo|
tElock|
lines=81
lines=75
embedded dns
trace
trace
T:16:35:00 Win2K-f 211.20.222.150 (HINET.NET):
XUN HANG TECHNOLOGY CO. LTD,
TAIPEI, T'AI-PEI, TW. (100Mbps)
n/a US:cx10man.weedns.com 135 pcap raw alerts
ruleset
irc
696 lines
Yeah : 1.3
profile
none summary
tarball
28 of 41 b8076e37ae
NEW
52953fed05 [0] none:none
StarForce| none trace
T:17:13:00 Win2K-f 63.23.15.139 (UU.NET):
UUNET TECHNOLOGIES INC,
GROVEPORT, OHIO, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
4 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
17:22:00 Win2K-f 200.123.80.177 (ALTERNATIVAGRATIS.COM):
ALTERNATIVA GRATIS,
BUENOS AIRES, BUENOS AIRES, AR. (DSL)
n/a US:www.maxmind.com
:checkip.dyndns.org
US:www.getmyip.org
EU:getmyip.co.uk
208.78.70.70:80
US:67.15.94.80:80
EU:78.40.35.134:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:17:31:00 Win2K-f 200.123.80.177 (ALTERNATIVAGRATIS.COM):
ALTERNATIVA GRATIS,
BUENOS AIRES, BUENOS AIRES, AR. (DSL)
n/a US:www.maxmind.com
US:www.getmyip.org
:checkip.dyndns.org
DE:131.220.6.26:80
445 pcap raw alerts
ruleset
http
6 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:18:04:00 Win2K-f 172.191.75.122 (AOL.COM):
AMERICA ONLINE,
RESTON, VIRGINIA, US. (DIAL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
141 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:18:36:00 Win2K-f 125.4.245.71 (ZAQ.NE.JP):
J:COM WEST CO. LTD,
TOKYO, TOKYO, JP. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
118 lines
Yeah : 1.3
profile
none summary
tarball
38 of 41
37 of 41
98d2778fd6
NEW
f676f3bf5b
NEW
9feea491cb [0]
0fba495fc4[0]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=91
trace
trace
T:19:32:00 Win2K-f 207.5.121.144 (MICROLNK.COM):
MICROLNK LLC,
OMAHA, NEBRASKA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:19:49:00 Win2K-f 70.62.129.88 (RR.COM):
ROAD RUNNER HOLDCO LLC,
MARYSVILLE, OHIO, US. (DSL)
n/a DE:proxim.ircgalaxy.pl
US:microsoft.com
CN:218.93.201.51:80
135 pcap raw alerts
ruleset
irc
461 lines
Yeah : 1.3
profile
none summary
tarball
34 of 36
33 of 36
644b2a1105
NEW
9c9ab20965
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
T:21:00:00 Win2K-f 76.188.181.214 (RR.COM):
ROAD RUNNER HOLDCO LLC,
AMHERST, OHIO, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
38 of 41
39 of 41
c40e0af1a7
NEW
ca24bacb31
NEW
3c325a47bc [0]
7444ca55f4[0]
none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
T:21:05:00 Win2K-f 4.160.111.56 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
LOUISVILLE, KENTUCKY, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
202 lines
Yeah : 1.3
profile
none summary
tarball
38 of 40
36 of 41
84ace068d1
NEW
c584af4fcd
NEW
c822a7d0e4 [0]
bdfcf0a930[0]
none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
T:21:45:00 Win2K-f 204.181.129.44 (UNINETS.NET):
OXFORD COUNTY TELEPHONE SERVICE / THE PHONE STORE/MEGALINK,
UNITY, MAINE, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
186 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41 fb66246b60
NEW
none[none] none:none
none|none none none
22:08:00 Win2K-f 140.113.18.2 (NTHU.EDU.TW):
TAIWAN ACADEMIC NETWORK,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a US:www.maxmind.com
US:www.getmyip.org
:checkip.dyndns.org
EU:getmyip.co.uk
DE:131.220.6.26:80
208.78.70.70:80
EU:78.40.35.134:80
445 pcap raw alerts
ruleset
http
5 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:22:15:00 Win2K-f 208.100.146.170 (BENDBROADBAND.COM):
BEND CABLE COMMUNICATIONS LLC,
BEND, OREGON, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
38 of 41
38 of 41
42a5385ed4
NEW
f287d03196
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none