Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

17 August 2011
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
T:00:24:00 WinXP 174.42.145.22 (WINDSTREAM.NET):
ALLTEL MIP CUSTOMERS - WARRENSVILLE HEIGHTS,
CHARLOTTE, NORTH CAROLINA, US. (DSL)
n/a DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
41 of 43 fb486908b0
NEW
none[none] none:none
none|none none none
T:01:04:00 WinXP 79.133.159.92 (-):
ADSL USERS,
RU. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
39 of 41 d8040f84d4
NEW
d683995e84 [0] ASM:Graph
PolyEnE| lines=73 trace
01:38:00 WinXP 174.42.145.22 (WINDSTREAM.NET):
ALLTEL MIP CUSTOMERS - WARRENSVILLE HEIGHTS,
CHARLOTTE, NORTH CAROLINA, US. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
41 of 43 fb486908b0
NEW
none[none] none:none
none|none none none
T:01:43:00 WinXP 118.87.217.201 (HTOJ.J-CNET.JP):
JCN-HTMNET,
JP. (DSL)
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:01:48:00 WinXP 220.146.22.192 (INFOWEB.NE.JP):
INFOWEB(FUJITSU LTD.),
KYOTO, KYOTO, JP. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
40 of 41 eb33ccfff8
NEW
e732a43be0 [0] ASM:Graph
none|none lines=58 trace
T:03:36:00 WinXP 4.159.5.122 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
GRAND RAPIDS, MICHIGAN, US. (DIAL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
137 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:04:47:00 WinXP 188.237.94.28 (RIPE.NET):
EUROPEAN REGIONAL REGISTRY,
UK. (DSL)
n/a IR:cunts.no-ip.org
IR:91.98.146.3:6667
135 pcap raw alerts
ruleset
irc
420 lines
Yeah : 0.8
profile
none summary
tarball
0 of 34 a1db003660
NEW
none[none] none:none
none|none none none
T:04:47:00 WinXP 85.236.184.101 (SAMARALAN.RU):
TAHION,
MOSCOW, MOSCOW CITY, RU. (DSL)
91.98.146.3:6667 IR:cunts.no-ip.org
IR:91.98.146.3:6667
135 pcap raw alerts
ruleset
irc
615 lines
Yeah : 1.3
profile
none summary
tarball
41 of 44 7d2e5a0c76
NEW
none[none] none:none
none|none none none
T:04:55:00 WinXP 201.48.3.67 (STERLINGSTUDENTS.NET):
COMITE GESTOR DA INTERNET NO BRASIL,
BR. (DSL)
91.98.146.3:6667 IR:cunts.no-ip.org
IR:91.98.146.3:6667
135 pcap raw alerts
ruleset
irc
452 lines
Yeah : 1.3
profile
none summary
tarball
41 of 44 6a99d89ff5
NEW
none[none] none:none
none|none none none
T:04:57:00 Win2K-f 4.143.246.1 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
HARWOOD HEIGHTS, ILLINOIS, US. (DIAL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
60 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
8 of 33
53bfe15e91
NEW
b7082104e4
NEW
1473091351 [0]
c5b49e7b82[0]
ASM:Graph
ASM:Graph
tElock|
tElock|
lines=75
embedded dns
lines=41
trace
trace
06:10:00 WinXP 46.185.64.149 (-):
.
n/a DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
39 of 41 d8040f84d4
NEW
d683995e84 [0] ASM:Graph
PolyEnE| lines=73 trace
T:07:03:00 WinXP 83.242.200.242 (PERIODICALS.RU):
COMSTAR TELECOMMUNICATIONS LTD,
RU. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
41 of 43 fb486908b0
NEW
none[none] none:none
none|none none none
T:07:22:00 WinXP 137.118.142.126 (WILKES.NET):
NEONOVA NETWORK SERVICES,
NORTH WILKESBORO, NORTH CAROLINA, US. (DSL)
n/a DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
40 of 41 1d0ce31c6d
NEW
none[none] none:none
none|none none none
T:07:43:00 WinXP 186.48.107.219 (-):
.
91.98.146.3:6667 IR:sparkles.no-ip.org 445 pcap raw alerts
ruleset
ftp
irc
21 lines
Yeah : 1.3
profile
none summary
tarball
15 of 42 59b543ef34
NEW
none[none] none:none
none|none none none
T:07:46:00 Win2K-f 212.225.133.156 (PTVTELECOM.COM):
ES-PROCONO-AS,
CóRDOBA, ANDALUCIA, ES. (DSL)
91.98.146.3:6667 IR:sparkles.no-ip.org
IR:91.98.146.3:6667
445 pcap raw alerts
ruleset
ftp
irc
25 lines
Yeah : 1.3
profile
none summary
tarball
17 of 43 039e94f575
NEW
none[none] none:none
none|none none none
T:07:50:00 WinXP 186.23.159.147 (-):
.
91.98.146.3:6667 IR:sparkles.no-ip.org
IR:91.98.146.3:6667
445 pcap raw alerts
ruleset
ftp
irc
21 lines
Yeah : 1.3
profile
none summary
tarball
21 of 44 dda9ee22d5
NEW
none[none] none:none
none|none none none
T:07:52:00 Win2K-f 190.94.131.98 (-):
ETAPATELECOM S.A,
CUENCA, AZUAY, EC. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
10 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:08:02:00 WinXP 190.220.49.39 (TECHTELNET.NET):
TECHTEL LMDS COMUNICACIONES INTERACTIVAS S.A,
AR. (DSL)
91.98.146.3:6667 IR:sparkles.no-ip.org
IR:91.98.146.3:6667
445 pcap raw alerts
ruleset
ftp
irc
23 lines
Yeah : 1.3
profile
none summary
tarball
30 of 43 b8309214df
NEW
none[none] none:none
none|none none none
T:08:10:00 WinXP 186.18.146.210 (186.IN-ADDR.ARPA):
TELECENTRO S.A. - CLIENTES RESIDENCIALES,
BUENOS AIRES, BUENOS AIRES, AR. (DSL)
91.98.146.3:6667 IR:sparkles.no-ip.org 445 pcap raw alerts
ruleset
ftp
irc
23 lines
Yeah : 1.3
profile
none summary
tarball
30 of 43 b8309214df
NEW
none[none] none:none
none|none none none
T:08:22:00 WinXP 31.28.35.91 (-):
.
91.98.146.3:6667 IR:sparkles.no-ip.org
IR:91.98.146.3:6667
445 pcap raw alerts
ruleset
ftp
irc
21 lines
Yeah : 1.3
profile
none summary
tarball
31 of 43 4c388ca8ba
NEW
none[none] none:none
none|none none none
T:10:36:00 Win2K-f 72.45.61.112 (ATLANTICBB.NET):
ATLANTIC BROADBAND,
MIDDLETOWN, DELAWARE, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
38 of 41
38 of 41
d031b42d3f
NEW
fa14802705
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
T:10:36:00 WinXP 68.146.211.248 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
CALGARY, ALBERTA, CA. (DSL)
n/a   135 pcap raw alerts
ruleset
other
23 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:10:48:00 WinXP 91.64.117.81 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
HAMBURG, HAMBURG, DE. (DSL)
n/a DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
39 of 41 d8040f84d4
NEW
d683995e84 [0] ASM:Graph
PolyEnE| lines=73 trace
T:11:38:00 WinXP 178.137.17.252 (FINEBLANK.COM):
EU-ZZ,
UK. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
39 of 42 3977189133
NEW
none[none] none:none
none|none none none
T:11:54:00 WinXP 111.88.13.191 (HOSTS-WORLDCALL.NET.PK):
WORLDCALL TELECOM LTD,
PK. (DSL)
n/a DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
39 of 42 194a3a1b0f
NEW
none[none] none:none
none|none none none
T:12:35:00 WinXP 70.65.56.152 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
RED DEER, ALBERTA, CA. (DSL)
n/a :gg.arrancar.org 135 pcap raw alerts
ruleset
other
186 lines
Yeah : 1.3
profile
none summary
tarball
34 of 39 ce28648035
NEW
126d2f4655 [0] ASM:Graph
none|none lines=546 trace
T:13:03:00 WinXP 41.250.152.53 (IAM.NET.MA):
AFRINIC,
CASABLANCA, CASABLANCA, MA. (DSL)
91.98.146.3:6667 IR:cunts.no-ip.org
IR:91.98.146.3:6667
135 pcap raw alerts
ruleset
irc
428 lines
Yeah : 1.3
profile
none summary
tarball
0 of 34 a1db003660
NEW
none[none] none:none
none|none none none
T:13:04:00 WinXP 190.218.192.215 (CABLEONDA.NET):
CABLE ONDA,
PA. (DSL)
91.98.146.3:6667 IR:cunts.no-ip.org
IR:91.98.146.3:6667
135 pcap raw alerts
ruleset
irc
431 lines
Yeah : 1.3
profile
none summary
tarball
0 of 34 a1db003660
NEW
none[none] none:none
none|none none none
T:13:04:00 Win2K-f 189.214.131.212 (NIC-R2-R1-MTY.NIC.MX):
NETWORK INFORMATION CENTER MEXICO,
MX. (DSL)
91.98.146.3:6667 IR:cunts.no-ip.org
IR:91.98.146.3:6667
135 pcap raw alerts
ruleset
irc
456 lines
Yeah : 1.3
profile
none summary
tarball
41 of 44 84b5b25a27
NEW
none[none] none:none
none|none none none
T:13:15:00 Win2K-f 186.11.47.53 (-):
.
91.98.146.3:6667 IR:cunts.no-ip.org
IR:91.98.146.3:6667
135 pcap raw alerts
ruleset
irc
430 lines
Yeah : 1.3
profile
none summary
tarball
0 of 34 a1db003660
NEW
none[none] none:none
none|none none none
T:13:24:00 WinXP 186.51.157.51 (-):
.
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
41 of 41 5c6df5141d
NEW
none[none] none:none
none|none none none
T:13:49:00 WinXP 46.185.28.187 (-):
.
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
41 of 43 fb486908b0
NEW
none[none] none:none
none|none none none
T:14:03:00 WinXP 93.102.73.32 (REV.OPTIMUS.PT):
OPTIMUS PORTUGAL,
AVEIRO, AVEIRO, PT. (DSL)
n/a :www.google.com.au
US:www.yahoo.com
:jbeegvia.ru
135 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
31 of 32 17028f1eda
NEW
none[3] none:none
tElock| none trace
16:55:00 Win2K-f 94.92.167.125 (BUSINESS.TELECOMITALIA.IT):
INTERBUSINESS,
ROME, LAZIO, IT. (DSL)
n/a US:www.maxmind.com
:getmyip.co.uk
:www.getmyip.org
US:checkip.dyndns.org
DE:131.220.6.26:80
EU:91.198.22.70:80
94.92.167.125:8850
445 pcap raw alerts
ruleset
http
4 lines
Yeah : 0.8
profile
none summary
tarball
4 of 37 8ce32ded17
NEW
none[3] none:none
Armadillo| none trace
T:17:22:00 Win2K-f 98.101.143.183 (RR.COM):
ROAD RUNNER HOLDCO LLC,
HERNDON, VIRGINIA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
17:52:00 Win2K-f 41.196.198.98 (LINK.COM.EG):
AFRINIC,
CAIRO, AL QAHIRAH, EG. (DSL)
n/a US:www.maxmind.com
:getmyip.co.uk
:www.getmyip.org
:checkip.dyndns.org
DE:131.220.6.26:80
EU:91.198.22.70:80
445 pcap raw alerts
ruleset
http
4 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:18:05:00 Win2K-f 41.196.198.98 (LINK.COM.EG):
AFRINIC,
CAIRO, AL QAHIRAH, EG. (DSL)
n/a US:www.maxmind.com
EU:checkip.dyndns.org
DE:131.220.6.26:80
445 pcap raw alerts
ruleset
http
5 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:18:45:00 Win2K-f 61.218.78.22 (HINET.NET):
DONG DIAN CO. LTD,
TAIPEI, T'AI-PEI, TW. (100Mbps)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
40 of 43
41 of 42
4f4bbf29ec
NEW
743e8678f4
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
T:18:57:00 WinXP 186.198.101.80 (-):
.
n/a DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
40 of 44 162ae078d0
NEW
none[none] none:none
none|none none none
T:20:21:00 WinXP 113.252.50.49 (HUTCHCITY.COM):
HUTCHISON GLOBAL COMMUNICATIONS,
HONG KONG, HONG KONG (SAR), HK. (DSL)
n/a DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
39 of 44 a02cf2137a
NEW
none[none] none:none
none|none none none
20:31:00 Win2K-f 41.196.198.98 (LINK.COM.EG):
AFRINIC,
CAIRO, AL QAHIRAH, EG. (DSL)
n/a US:www.maxmind.com
:getmyip.co.uk
:www.getmyip.org
US:checkip.dyndns.org
US:208.43.124.51:80
EU:91.198.22.70:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:20:33:00 WinXP 114.198.163.76 (-):
GLOBALVIEW CATV CO. LTD,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
38 of 42 8a2553433c
NEW
none[none] none:none
none|none none none
T:22:02:00 WinXP 119.160.172.159 (-):
BRUNET TELEKOM BRUNEI BERHAD (TELBRU),
JERUDONG, BRUNEI AND MUARA, BN. (DSL)
n/a :gg.arrancar.org 135 pcap raw alerts
ruleset
other
345 lines
Yeah : 1.3
profile
none summary
tarball
41 of 41 3ff6383287
NEW
none[none] none:none
none|none none none