Welcome to the Cyber-TA
Daily Malware Binary DIGEST Summary Page



14 April 2011

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.



Packed
MD5
UnPacket
MD5
Victim
OS
AntiVirus
Hit-Cnt
First
Encounter
Last
Encounter
Freq
Cnt
Behavioral
Clusters
Unpacked
Egg.asm
Packer
Fingerprint
API
Resolution
String
Cnt
Syscall
Trace
2b3f26d343
NEW
4474d82785
NEW
46db4a2874
NEW
564048b35d
NEW
5d6097956d
NEW
6dc0a90bf4
NEW
8c3a3b2ee7
NEW
d778629fbb
NEW
none[none]
none [none]
none [none]
none [none]
none [none]
none [none]
none [none]
none [none]
WinXP 13 of 39 03:40:49 03:40:49 1 none none:none
none:none
none:none
none:none
none:none
none:none
none:none
none:none
none|none
none|none
none|none
none|none
none|none
none|none
none|none
none|none
none
none
none
none
none
none
none
none
none
none
none
none
none
none
none
none
2b3f26d343
NEW
4474d82785
NEW
none[none]
none [none]
WinXP 6 of 40 03:40:49 03:40:49 1 none none:none
none:none
none|none
none|none
none
none
none
none
118b884494
NEW
none[none] WinXP 41 of 42 13:43:19 13:43:19 1 none none:none
none|none none none
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
Win2K-f
WinXP
0 of 32 05:59:19 18:07:40 3 none ASM:Graph
none:none
tElock|
Armadillo|
0% lines=75
embedded dns
lines=90
trace
trace
2b3f26d343
NEW
4474d82785
NEW
46db4a2874
NEW
none[none]
none [none]
none [none]
Win2K-f
WinXP
22 of 41 03:36:40 03:40:49 2 none none:none
none:none
none:none
none|none
none|none
none|none
none
none
none
none
none
none
2b3850931e
NEW
none[none] WinXP 41 of 42 07:15:38 07:15:38 1 none none:none
none|none none none
07fabc79ef
NEW
53bfe15e91
NEW
none[0]
1473091351[0]
WinXP
Win2K-f
33 of 33 01:17:34 21:55:29 7 none none:none
ASM:Graph
Armadillo|
tElock|
96% lines=90
lines=75
embedded dns
trace
trace
1511a3f219
NEW
none[none] WinXP 42 of 43 22:30:34 22:30:34 1 none none:none
none|none none none
b8e6f4caf7
NEW
fb92b91fe7
NEW
f81eac6379 [0]
fe88ab8768[0]
Win2K-f 39 of 39 06:23:06 06:23:06 1 none none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
0d1eb4df79
NEW
none[none] WinXP 38 of 42 04:56:23 04:56:23 1 none none:none
none|none none none
07fabc79ef
NEW
none[0] Win2K-f 0 of 32 21:55:29 21:55:29 1 none none:none
Armadillo| 0% lines=90 trace
5799ab6538
NEW
2713679411 [0] WinXP 40 of 41 10:46:35 10:46:35 1 none ASM:Graph
tElock| 96% lines=64
embedded dns
trace
2b3f26d343
NEW
4474d82785
NEW
46db4a2874
NEW
564048b35d
NEW
5d6097956d
NEW
6dc0a90bf4
NEW
none[none]
none [none]
none [none]
none [none]
none [none]
none [none]
WinXP 27 of 40 03:40:49 03:40:49 1 none none:none
none:none
none:none
none:none
none:none
none:none
none|none
none|none
none|none
none|none
none|none
none|none
none
none
none
none
none
none
none
none
none
none
none
none
b8e6f4caf7
NEW
f81eac6379 [0] Win2K-f 39 of 40 06:23:06 06:23:06 1 none none:none
tElock| none trace
9d38d43309
NEW
none[none] WinXP 41 of 41 23:40:51 23:40:51 1 none none:none
none|none none none
b502f83a7c
NEW
28f5be93b0 [0] WinXP 32 of 32 00:48:01 03:39:48 2 none ASM:Graph
PolyEnE| 99% lines=73 trace
5c6df5141d
NEW
none[none] WinXP 41 of 41 14:57:31 14:57:31 1 none none:none
none|none none none
d031b42d3f
NEW
none[none] Win2K-f 38 of 41 08:54:41 08:54:41 1 none none:none
none|none none none
c6c87a9a70
NEW
none[none] WinXP 16 of 41 15:26:07 15:26:07 1 none none:none
none|none none none
38ed850a0e
NEW
46990f37cd [0] WinXP 34 of 38 06:35:27 06:35:27 1 none ASM:Graph
Armadillo| 0% lines=91 trace
fb486908b0
NEW
none[none] WinXP 41 of 43 07:20:00 22:21:32 8 none none:none
none|none none none
10c560fc02
NEW
none[none] Win2K-f 40 of 41 03:35:25 03:35:25 1 none none:none
none|none none none
3895c7304a
NEW
46db4a2874
NEW
51c413f474
NEW
564048b35d
NEW
b34e640329
NEW
none[none]
none [none]
none [none]
none [none]
none [none]
Win2K-f 29 of 43 03:36:40 03:36:40 1 none none:none
none:none
none:none
none:none
none:none
none|none
none|none
none|none
none|none
none|none
none
none
none
none
none
none
none
none
none
none
0f77d6439f
NEW
none[none] WinXP 41 of 43 05:43:32 07:25:14 2 none none:none
none|none none none
3895c7304a
NEW
46db4a2874
NEW
51c413f474
NEW
none[none]
none [none]
none [none]
Win2K-f 18 of 41 03:36:40 03:36:40 1 none none:none
none:none
none:none
none|none
none|none
none|none
none
none
none
none
none
none
2b3f26d343
NEW
4474d82785
NEW
46db4a2874
NEW
564048b35d
NEW
none[none]
none [none]
none [none]
none [none]
Win2K-f
WinXP
29 of 43 03:36:40 03:40:49 2 none none:none
none:none
none:none
none:none
none|none
none|none
none|none
none|none
none
none
none
none
none
none
none
none
0b951c2832
NEW
5fe761661a [0] Win2K-f 32 of 36 01:03:09 01:03:09 1 none ASM:Graph
Armadillo| 0% lines=91 trace
d11b1f56f9
NEW
none[none] WinXP 40 of 41 11:03:43 23:21:27 3 none none:none
none|none none none
420b1a76c4
NEW
none[none] WinXP 42 of 43 14:42:11 14:42:11 1 none none:none
none|none none none
514ce898a3
NEW
none[none] WinXP 35 of 40 03:57:35 03:57:35 1 none none:none
none|none none none
10c560fc02
NEW
1b8d146832
NEW
none[none]
none [none]
Win2K-f 40 of 41 03:35:25 03:35:25 1 none none:none
none:none
none|none
none|none
none
none
none
none
3895c7304a
NEW
46db4a2874
NEW
51c413f474
NEW
564048b35d
NEW
b34e640329
NEW
e4240d7958
NEW
ff7a9d9404
NEW
none[none]
none [none]
none [none]
none [none]
none [none]
none [none]
none [none]
Win2K-f 21 of 42 03:36:40 03:36:40 1 none none:none
none:none
none:none
none:none
none:none
none:none
none:none
none|none
none|none
none|none
none|none
none|none
none|none
none|none
none
none
none
none
none
none
none
none
none
none
none
none
none
none
ae4bd44962
NEW
none[none] WinXP 37 of 40 17:02:09 17:02:09 1 none none:none
none|none none none
2bc8f15054
NEW
none[none] WinXP 40 of 41 04:01:51 04:01:51 1 none none:none
none|none none none
7d99b0e910
NEW
none[0] WinXP 26 of 28 00:31:28 18:24:45 6 none none:none
PolyEnE| 99% lines=68 trace
2205443cc8
NEW
04ce1ed773 [none] Win2K-f 38 of 39 05:18:35 05:18:35 1 none none:none
none|none none none
2b3f26d343
NEW
4474d82785
NEW
46db4a2874
NEW
564048b35d
NEW
5d6097956d
NEW
6dc0a90bf4
NEW
8c3a3b2ee7
NEW
none[none]
none [none]
none [none]
none [none]
none [none]
none [none]
none [none]
WinXP 6 of 42 03:40:49 03:40:49 1 none none:none
none:none
none:none
none:none
none:none
none:none
none:none
none|none
none|none
none|none
none|none
none|none
none|none
none|none
none
none
none
none
none
none
none
none
none
none
none
none
none
none
e169a143be
NEW
none[none] Win2K-f 6 of 42 03:44:15 03:44:15 1 none none:none
none|none none none
ae4bd44962
NEW
c48d5a281d
NEW
none[none]
none [none]
WinXP 38 of 41 17:02:09 17:02:09 1 none none:none
none:none
none|none
none|none
none
none
none
none
3895c7304a
NEW
46db4a2874
NEW
51c413f474
NEW
564048b35d
NEW
b34e640329
NEW
e4240d7958
NEW
none[none]
none [none]
none [none]
none [none]
none [none]
none [none]
Win2K-f 9 of 42 03:36:40 03:36:40 1 none none:none
none:none
none:none
none:none
none:none
none:none
none|none
none|none
none|none
none|none
none|none
none|none
none
none
none
none
none
none
none
none
none
none
none
none
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
WinXP
Win2K-f
0 of 33 01:17:34 15:20:41 3 none ASM:Graph
none:none
tElock|
Armadillo|
0% lines=75
embedded dns
lines=90
trace
trace
7587773eea
NEW
none[3] Win2K-f 7 of 37 09:36:46 09:36:46 1 none none:none
StarForce| none trace
d8040f84d4
NEW
d683995e84 [0] WinXP 39 of 41 15:04:24 15:04:24 1 none ASM:Graph
PolyEnE| 100% lines=73 trace
3895c7304a
NEW
none[none] Win2K-f 42 of 42 03:36:40 03:36:40 1 none none:none
none|none none none
4c86ff87f5
NEW
none[none] Win2K-f 31 of 41 02:51:41 03:00:28 2 none none:none
none|none none none
2b3f26d343
NEW
4474d82785
NEW
46db4a2874
NEW
564048b35d
NEW
5d6097956d
NEW
none[none]
none [none]
none [none]
none [none]
none [none]
WinXP 33 of 42 03:40:49 03:40:49 1 none none:none
none:none
none:none
none:none
none:none
none|none
none|none
none|none
none|none
none|none
none
none
none
none
none
none
none
none
none
none
38ed850a0e
NEW
b9297745a1
NEW
46990f37cd [0]
4294884d84[0]
Win2K-f
WinXP
35 of 38 05:18:35 06:35:27 2 none ASM:Graph
ASM:Graph
Armadillo|
tElock|
96% lines=91
lines=64
embedded dns
trace
trace
2b3f26d343
NEW
none[none] WinXP 9 of 41 03:40:49 03:40:49 1 none none:none
none|none none none
5e8ccc4190
NEW
8d5f86583f [0] WinXP 39 of 40 05:35:00 05:35:00 1 none ASM:Graph
PolyEnE| 100% lines=68 trace
0b951c2832
NEW
e4ed4df0f0
NEW
5fe761661a [0]
de471fc380[0]
Win2K-f 34 of 36 01:03:09 01:03:09 1 none ASM:Graph
ASM:Graph
Armadillo|
tElock|
96% lines=91
lines=64
embedded dns
trace
trace
5799ab6538
NEW
f38e8d97da
NEW
2713679411 [0]
83f1400243[0]
WinXP 39 of 41 10:46:35 10:46:35 1 none ASM:Graph
ASM:Graph
tElock|
Armadillo|
0% lines=64
embedded dns
lines=91
trace
trace
d031b42d3f
NEW
fa14802705
NEW
none[none]
none [none]
Win2K-f 38 of 41 08:54:41 08:54:41 1 none none:none
none:none
none|none
none|none
none
none
none
none
d9cb288f31
NEW
45603a001c [0] Win2K-f 3 of 37 02:40:06 18:23:00 3 none ASM:Graph
UPX| 92% lines=174
embedded dns
trace
2bc8f15054
NEW
964911406f
NEW
none[none]
none [none]
WinXP 0 of 0 04:01:51 04:01:51 1 none none:none
none:none
none|none
none|none
none
none
none
none