Malware Report - Results

This report shows all the different areas TAZER analyzes for the sample: Host, Network Activity, and Detection.

Malware Search Criteria:
  • MD5 =13154ea8c5d0016e8cec361304ff4f20

  • Malware Report - Results

    File MD5SumSHA1SUMSHA256SUMFUZZY HASHFile Size
    13154ea8c5d0016e8cec361304ff4f20c88d792688a3fde73060d75485dd1ad4e28d89b8bb01563076dd0a0d447cb6414a31d62d1132b468d2c231af55bdfc1bbde10f4812288:JfetfDj6qzQNfdKprp/farwpPVSNOKyuoDOYa:0lj66QxgRFlpPVpuxL488761

    File Results

    File Name
    exerev.exe

    SNORT Results

    Snort ClassSnort AlertCount
    N/ANo snort alerts generated0

    AV Results

    AV AlertAV Vendor

    Folders (Added) - ICC Results

    PathFolder Name
    c:/Documents and Settings/dmc73144/Local Settings/Tempnsc3.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C

    Files (Added) - ICC Results

    PathFile Name
    c:/Documents and Settings/dmc73144/Application Datab2l0zj6.exe
    c:/Documents and Settings/dmc73144/Application Datajdv50pd.log
    c:/Documents and Settings/dmc73144/Application DataMouseDriver.bat
    c:/Documents and Settings/dmc73144/Local Settings/Temp7.tmp
    c:/Documents and Settings/dmc73144/Local Settings/Temp/nsc3.tmp5tbp.exe
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0CCARAKZV5.htm
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:/WINDOWS/Prefetch1EUROP.EXE-368E3FF5.pf
    c:/WINDOWS/Prefetch2E4U - BUCKS.EXE-007AB57D.pf
    c:/WINDOWS/Prefetch3IC.EXE-06683A57.pf
    c:/WINDOWS/Prefetch4IR.EXE-33E1CB57.pf
    c:/WINDOWS/Prefetch5TBP.EXE-12B768EB.pf
    c:/WINDOWS/PrefetchB2L0ZJ6.EXE-04228E99.pf
    c:/WINDOWS/PrefetchEXEREV.EXE-37FA894F.pf
    c:/WINDOWS/PrefetchGRPCONV.EXE-111CD845.pf
    c:/WINDOWS/PrefetchNET.EXE-01A53C2F.pf
    c:/WINDOWS/PrefetchNET1.EXE-029B9DB4.pf
    c:/WINDOWS/PrefetchRUNDLL32.EXE-253557CF.pf
    c:/WINDOWS/PrefetchRUNDLL32.EXE-2C8B53CF.pf
    c:/WINDOWS/PrefetchRUNDLL32.EXE-47DB8CE3.pf
    c:/WINDOWS/PrefetchRUNONCE.EXE-2803F297.pf
    c:/WINDOWS/PrefetchSANDNET.EXE-2012C478.pf
    c:/WINDOWS/PrefetchSC.EXE-012262AF.pf
    c:/WINDOWS/PrefetchSVCHOST.EXE-3530F672.pf
    c:/WINDOWSarugiqin.dll
    c:/WINDOWSmgiodma.dll
    c:netstat_post.txt
    c:tasksvc_post.txt
    c:taskv_post.txt

    Files (Deleted) - ICC Results

    ActionPathFile Name

    Files (Changed) - ICC Results

    ActionPathFile Name
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/Documents and Settings/LocalServicentuser.dat.LOG
    modifiedc:/Program Files/OpenSSH/var/logOpenSSHd.log
    modifiedc:/WINDOWS/PrefetchHSTART.EXE-221D72BF.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/system32/configdefault.LOG
    modifiedc:/WINDOWS/system32/configsoftware.LOG
    modifiedc:/WINDOWS/system32/configSYSTEM
    modifiedc:/WINDOWS/system32/configsystem.LOG
    modifiedc:/WINDOWS/system32/drivers/etchosts
    modifiedc:/WINDOWS/system32/wbem/Logswbemess.log
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log

    Registry Keys (Added) - ICC Results

    ActionPath

    Registry Values (Added) - ICC Results

    ActionPathVal_NameVal_Data

    Registry Values (Deleted) - ICC Results

    ActionPathVal_NameVal_TypeMod_Val_TypeVal_DataMod_Val_Data

    Registry Values (Changed) - ICC Results

    ActionPathVal_NameVal_DataMod_Val_Data
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeedC7 C2 AB D7 E5 AF 0C E3 65 F3 DB E2 4F 5F 5F 3F 32 42 75 02 04 D0 60 A5 F2 95 4D 09 C9 4E B9 C9 8C 26 84 1B 03 05 15 8A B0 59 E4 83 F5 55 B6 B7 08 8E 53 22 5E 1
    modifiedHKLM/SOFTWARE/Microsoft/DirectDraw/MostRecentApplicationName"msoobe.exe" "svchost.exe"
    modifiedHKLM/SOFTWARE/Microsoft/DirectDraw/MostRecentApplicationID0x3B7D853E 0x41107ED6
    modifiedHKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/ProfileList/S-1-5-19RefCount0x00000002 0x00000001
    modifiedHKLM/SYSTEM/ControlSet001/Services/SharedAccessStart0x00000002 0x00000004
    modifiedHKLM/SYSTEM/ControlSet001/Services/SharedAccess/EpochEpoch0x00000104 0x00000105
    modifiedHKLM/SYSTEM/ControlSet001/Services/wscsvcStart0x00000002 0x00000004
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/SharedAccessStart0x00000002 0x00000004
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/SharedAccess/EpochEpoch0x00000104 0x00000105
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/wscsvcStart0x00000002 0x00000004
    modifiedHKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/3CurrentLevel0x00011000 0x00000000
    modifiedHKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/316010x00000001 0x00000000
    modifiedHKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/31A100x00000001 0x00000000
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 19 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x00000002 0x00000001
    modifiedHKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/3CurrentLevel0x00011000 0x00000000
    modifiedHKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/316010x00000001 0x00000000
    modifiedHKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/31A100x00000001 0x00000000

    DNS Results

    DNSDNS Response
    ikea.comStandard query response A 192.71.68.7
    sitesell.comStandard query response A 66.43.48.39
    google.aeStandard query response A 74.125.113.105 A 74.125.113.106 A 74.125.113.147 A 74.125.113.99 A 74.125.113.103 A 74.125.113.104
    grosstag.inStandard query response A 1.1.1.1
    aacartel.comStandard query response, Server failure
    rooftopjam.inStandard query response A 66.228.54.181
    baonsale.comStandard query response, Server failure
    w.nucleardiscover.comStandard query response A 60.190.223.75
    jumppack.inStandard query response A 66.228.54.181
    140807db081f.lalith.netStandard query response A 202.150.208.68
    hk9sk2mfmf3h0.comStandard query response A 63.251.179.57 A 64.158.56.57

    URL Results

    DstIPHTTP_HOSTHTTP_REQUEST_URIHTTP_USER_AGENTPROTOCOL
    1.1.1.1grosstag.in/?ini=v22MmjDnH4OmXzNmvVFHEeE2PuPsctM6PdFWTH11KB0CWwXTiUHUzGr1BVrHIQqMgMqV7ZlDeAiBMF4XAHPzbYuRtufQpKX/MPtsu+7pkA==Mozilla/5.0 (Windows NT 6.1; wget 3.0; rv:5.0) Gecko/20100101 Firefox/5.00x06
    66.228.54.181rooftopjam.in/?ini=v22MmjDnH4OmXzNmvVFHEeE2PuPsctM6PdFWTH11KB0CWwXTiUHUzGr1BVrHIQqMgMqV7ZlDeAiBMF4XAHPzbYuRtufQpKX/MPtsu+7pkA==Mozilla/5.0 (Windows NT 6.1; wget 3.0; rv:5.0) Gecko/20100101 Firefox/5.00x06
    66.228.54.181jumppack.in/?ini=v22MmjDnH4OmXzNmvVFHEeE2PuPsctM6PdFWTH11KB0CWwXTiUHUzGr1BVrHIQqMgMqV7ZlDeAiBMF4XAHPzbYuRtufQpKX/MPtsu+7pkA==Mozilla/5.0 (Windows NT 6.1; wget 3.0; rv:5.0) Gecko/20100101 Firefox/5.00x06
    239.255.255.250239.255.255.250:1900*--blank--0x11

    ARGUS PROTOCOL Results

    PROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    61171081037914961
    17203500

    ARGUS DPORT Results

    DPORTPROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    8065046521811231
    4436222014351204
    8886454237262526
    190017203500

    ARGUS DATA Results

    TimeDateProtocolSrcIPDstIPDirFlagsSportDportPktsBytes
    10:31:102011-08-08610.10.10.71.1.1.1-> e 10880132415
    10:31:152011-08-08610.10.10.71.1.1.1-> e 10880101965
    10:31:212011-08-08610.10.10.71.1.1.1-> e 108806633
    10:31:222011-08-08610.10.10.766.228.54.181-> e 12780132417
    10:31:272011-08-08610.10.10.766.228.54.181-> e 12780112298
    10:31:292011-08-08610.10.10.760.190.223.75-> e 503888141184
    10:31:332011-08-08610.10.10.766.228.54.181-> e 127805300
    10:31:332011-08-08610.10.10.766.228.54.181-> e 41780132415
    10:31:342011-08-08610.10.10.760.190.223.75-> e 50388810600
    10:31:382011-08-08610.10.10.766.228.54.181-> e 41780101965
    10:31:402011-08-08610.10.10.760.190.223.75-> e 5038885300
    10:31:402011-08-08610.10.10.7202.150.208.68-> e 1198091408
    10:31:432011-08-08610.10.10.766.228.54.181-> e 417806633
    10:32:432011-08-08610.10.10.760.190.223.75-> e 253888131124
    10:32:482011-08-08610.10.10.760.190.223.75-> e 25388811660
    10:32:532011-08-08610.10.10.760.190.223.75-> e 2538885300
    10:33:552011-08-08610.10.10.760.190.223.75-> e 258888131124
    10:34:002011-08-08610.10.10.760.190.223.75-> e 25888811660
    10:34:052011-08-08610.10.10.760.190.223.75-> e 2588885300
    10:34:252011-08-08610.10.10.763.251.179.57-> e 16444313856
    10:34:302011-08-08610.10.10.763.251.179.57-> e 16444310600
    10:34:352011-08-08610.10.10.763.251.179.57-> e 1644436360
    10:34:362011-08-08610.10.10.763.251.179.57-> e 35844313823
    10:36:322011-08-081710.10.10.7239.255.255.250-> e 819002350

    Packer Results

    Packer Name

    HoneyTrap Results

    Honey Trap Log File Location

    PTFB Results

    PTFB Log File Location