Malware Report - Results

This report shows all the different areas TAZER analyzes for the sample: Host, Network Activity, and Detection.

Malware Search Criteria:
  • MD5 =3815ec73533c286a25a0e5f2356f58e5

  • Malware Report - Results

    File MD5SumSHA1SUMSHA256SUMFUZZY HASHFile Size
    3815ec73533c286a25a0e5f2356f58e587dcfb8c150e362c24a8724a0e7d10cd21c3dcaea240c8a898b65f229dbac814f0b7433a2c9f8f4d7b0bfe56158499b8cb1011e66144:/48lglQc6287PWYFNtt+HVwHMt783Io7wX8bcZsWU9:gDQRPWw3westQ3Hw7406016

    File Results

    File Name
    drop.php%3Fe%3DJavaSignedApplet.exe

    SNORT Results

    Snort ClassSnort AlertCount
    A Network Trojan was DetectedET ATTACK_RESPONSE IRC - Nick change on non-std port17

    AV Results

    AV AlertAV Vendor

    Folders (Added) - ICC Results

    PathFolder Name
    c:/Program FilesKAZAA
    c:My Downloads

    Files (Added) - ICC Results

    PathFile Name
    c:/Documents and Settings/dmc73144/Application Datadata.dat
    c:/Documents and Settings/dmc73144/Application DatafgKDd1hgbF.txt
    c:/Documents and Settings/dmc73144/Application Datagoogle_q35[s6_2]rh_h.tmp
    c:/Documents and Settings/dmc73144/Application Datawindsys2.exe
    c:/Documents and Settings/dmc73144/Local Settings/TempNullBot_saud.exe
    c:/Program Filessvchost.dat
    c:/Program Fileswinlogon.exe
    c:/WINDOWS/PrefetchNULLBOT_SAUD.EXE-02423B30.pf
    c:/WINDOWS/PrefetchREG.EXE-0D2A95F7.pf
    c:/WINDOWS/PrefetchSANDNET.EXE-2012C478.pf
    c:/WINDOWS/PrefetchWINLOGON.EXE-008FCD73.pf
    c:netstat_post.txt
    c:taskv_post.txt

    Files (Deleted) - ICC Results

    ActionPathFile Name

    Files (Changed) - ICC Results

    ActionPathFile Name
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchHSTART.EXE-221D72BF.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/system32/configsoftware.LOG
    modifiedc:/WINDOWS/system32/drivers/etchosts
    modifiedc:/WINDOWS/system32sandnet.exe
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP

    Registry Keys (Added) - ICC Results

    ActionPath

    Registry Values (Added) - ICC Results

    ActionPathVal_NameVal_Data

    Registry Values (Deleted) - ICC Results

    ActionPathVal_NameVal_TypeMod_Val_TypeVal_DataMod_Val_Data

    Registry Values (Changed) - ICC Results

    ActionPathVal_NameVal_DataMod_Val_Data
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed7B D8 9F 32 5B 48 DF 85 63 B5 AA B4 BC 58 37 42 77 ED 86 65 3E D9 F4 90 76 79 D4 96 C7 24 B7 BC 48 5F 7B E7 5B 67 45 39 B5 14 BE FA B9 73 B0 E6 3A 44 52 1C E8 9
    modifiedHKLM/SYSTEM/ControlSet001/Services/SharedAccess/EpochEpoch0x00000104 0x00000106
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/SharedAccess/EpochEpoch0x00000104 0x00000106
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x00000002 0x00000001

    DNS Results

    DNSDNS Response
    saud.markaz-royal.netStandard query response A 46.4.176.169
    nokia2mon2.markaz-royal.netStandard query response A 2.90.213.40

    URL Results

    DstIPHTTP_HOSTHTTP_REQUEST_URIHTTP_USER_AGENTPROTOCOL
    239.255.255.250239.255.255.250:1900*--blank--0x11

    ARGUS PROTOCOL Results

    PROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    64964713074928326
    17203500

    ARGUS DPORT Results

    DPORTPROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    749362762591751715574
    878762202121323212752
    190017203500

    ARGUS DATA Results

    TimeDateProtocolSrcIPDstIPDirFlagsSportDportPktsBytes
    05:59:342010-12-27610.10.10.746.4.176.169-> e 567493171085
    05:59:392010-12-27610.10.10.746.4.176.169-> e 56749310600
    05:59:392010-12-27610.10.10.72.90.213.40-> e 44878711664
    05:59:442010-12-27610.10.10.746.4.176.169-> e 5674936360
    05:59:442010-12-27610.10.10.72.90.213.40-> e 44878711660
    05:59:482010-12-27610.10.10.746.4.176.169-> e 1087493171073
    05:59:492010-12-27610.10.10.72.90.213.40-> e 4487875300
    05:59:532010-12-27610.10.10.746.4.176.169-> e 108749311660
    05:59:532010-12-27610.10.10.72.90.213.40-> e 316878711664
    05:59:582010-12-27610.10.10.746.4.176.169-> e 10874935300
    05:59:582010-12-27610.10.10.72.90.213.40-> e 316878710600
    06:00:022010-12-27610.10.10.746.4.176.169-> e 1897493161019
    06:00:032010-12-27610.10.10.72.90.213.40-> e 31687876360
    06:00:072010-12-27610.10.10.746.4.176.169-> e 189749310600
    06:00:082010-12-27610.10.10.72.90.213.40-> e 190878712724
    06:00:122010-12-27610.10.10.746.4.176.169-> e 18974935300
    06:00:132010-12-27610.10.10.72.90.213.40-> e 190878711660
    06:00:162010-12-27610.10.10.746.4.176.169-> e 191749315959
    06:00:192010-12-27610.10.10.72.90.213.40-> e 19087874240
    06:00:212010-12-27610.10.10.746.4.176.169-> e 191749311660
    06:00:232010-12-27610.10.10.72.90.213.40-> e 530878712724
    06:00:262010-12-27610.10.10.746.4.176.169-> e 19174935300
    06:00:282010-12-27610.10.10.72.90.213.40-> e 530878710600
    06:00:302010-12-27610.10.10.746.4.176.169-> e 541749315959
    06:00:332010-12-27610.10.10.72.90.213.40-> e 53087875300
    06:00:352010-12-27610.10.10.746.4.176.169-> e 541749310600
    06:00:382010-12-27610.10.10.72.90.213.40-> e 542878711664
    06:00:402010-12-27610.10.10.746.4.176.169-> e 54174936360
    06:00:432010-12-27610.10.10.72.90.213.40-> e 542878710600
    06:00:442010-12-27610.10.10.746.4.176.169-> e 5437493171073
    06:00:482010-12-27610.10.10.72.90.213.40-> e 54287876360
    06:00:492010-12-27610.10.10.746.4.176.169-> e 543749311660
    06:00:532010-12-27610.10.10.72.90.213.40-> e 581878712724
    06:00:542010-12-27610.10.10.746.4.176.169-> e 54374935300
    06:00:582010-12-27610.10.10.746.4.176.169-> e 5827493171073
    06:00:582010-12-27610.10.10.72.90.213.40-> e 581878711660
    06:01:032010-12-27610.10.10.746.4.176.169-> e 582749310600
    06:01:042010-12-27610.10.10.72.90.213.40-> e 58187874240
    06:01:082010-12-27610.10.10.746.4.176.169-> e 58274936360
    06:01:082010-12-27610.10.10.72.90.213.40-> e 380878711664
    06:01:122010-12-27610.10.10.746.4.176.169-> e 583749315959
    06:01:132010-12-27610.10.10.72.90.213.40-> e 380878711660
    06:01:172010-12-27610.10.10.746.4.176.169-> e 583749311660
    06:01:182010-12-27610.10.10.72.90.213.40-> e 38087875300
    06:01:222010-12-27610.10.10.746.4.176.169-> e 58374935300
    06:01:232010-12-27610.10.10.72.90.213.40-> e 48878711664
    06:01:262010-12-27610.10.10.746.4.176.169-> e 102749315959
    06:01:282010-12-27610.10.10.72.90.213.40-> e 48878711660
    06:01:312010-12-27610.10.10.746.4.176.169-> e 102749310600
    06:01:332010-12-27610.10.10.72.90.213.40-> e 4887875300
    06:01:362010-12-27610.10.10.746.4.176.169-> e 10274936360
    06:01:382010-12-27610.10.10.72.90.213.40-> e 436878711664
    06:01:402010-12-27610.10.10.746.4.176.169-> e 381749315959
    06:01:432010-12-27610.10.10.72.90.213.40-> e 436878711660
    06:01:452010-12-27610.10.10.746.4.176.169-> e 381749311660
    06:01:482010-12-27610.10.10.72.90.213.40-> e 43687875300
    06:01:502010-12-27610.10.10.746.4.176.169-> e 38174935300
    06:01:532010-12-27610.10.10.72.90.213.40-> e 230878711664
    06:01:542010-12-27610.10.10.746.4.176.169-> e 454749315959
    06:01:582010-12-27610.10.10.72.90.213.40-> e 230878711660
    06:01:592010-12-27610.10.10.746.4.176.169-> e 454749311660
    06:02:032010-12-27610.10.10.72.90.213.40-> e 23087875300
    06:02:042010-12-27610.10.10.746.4.176.169-> e 45474935300
    06:02:082010-12-27610.10.10.746.4.176.169-> e 231749315959
    06:02:082010-12-27610.10.10.72.90.213.40-> e 294878711664
    06:02:132010-12-27610.10.10.746.4.176.169-> e 231749311660
    06:02:132010-12-27610.10.10.72.90.213.40-> e 294878711660
    06:02:182010-12-27610.10.10.746.4.176.169-> e 23174935300
    06:02:182010-12-27610.10.10.72.90.213.40-> e 29487875300
    06:02:222010-12-27610.10.10.746.4.176.169-> e 740749315959
    06:02:232010-12-27610.10.10.72.90.213.40-> e 741878711664
    06:02:272010-12-27610.10.10.746.4.176.169-> e 740749310600
    06:02:282010-12-27610.10.10.72.90.213.40-> e 741878711660
    06:02:322010-12-27610.10.10.746.4.176.169-> e 74074936360
    06:02:332010-12-27610.10.10.72.90.213.40-> e 74187875300
    06:02:362010-12-27610.10.10.746.4.176.169-> e 788749315959
    06:02:382010-12-27610.10.10.72.90.213.40-> e 789878711664
    06:02:412010-12-27610.10.10.746.4.176.169-> e 788749311660
    06:02:432010-12-27610.10.10.72.90.213.40-> e 789878711660
    06:02:462010-12-27610.10.10.746.4.176.169-> e 78874935300
    06:02:482010-12-27610.10.10.72.90.213.40-> e 78987875300
    06:02:502010-12-27610.10.10.746.4.176.169-> e 790749315959
    06:02:532010-12-27610.10.10.72.90.213.40-> e 791878711664
    06:02:552010-12-27610.10.10.746.4.176.169-> e 790749310600
    06:02:582010-12-27610.10.10.72.90.213.40-> e 791878710600
    06:03:002010-12-27610.10.10.746.4.176.169-> e 79074936360
    06:03:032010-12-27610.10.10.72.90.213.40-> e 79187876360
    06:03:042010-12-27610.10.10.746.4.176.169-> e 838749315959
    06:03:082010-12-27610.10.10.72.90.213.40-> e 839878711664
    06:03:102010-12-27610.10.10.746.4.176.169-> e 838749311660
    06:03:132010-12-27610.10.10.72.90.213.40-> e 839878711660
    06:03:152010-12-27610.10.10.746.4.176.169-> e 83874935300
    06:03:192010-12-27610.10.10.746.4.176.169-> e 840749315959
    06:03:182010-12-27610.10.10.72.90.213.40-> e 83987875300
    06:03:232010-12-27610.10.10.72.90.213.40-> e 841878711664
    06:03:242010-12-27610.10.10.746.4.176.169-> e 840749310600
    06:03:282010-12-27610.10.10.72.90.213.40-> e d 841878710600
    06:03:292010-12-27610.10.10.746.4.176.169-> e 84074936360
    06:03:332010-12-27610.10.10.72.90.213.40-> e d 84187874240
    06:03:442010-12-27610.10.10.72.90.213.40-> e d 8418787160
    06:03:562010-12-27610.10.10.72.90.213.40-> e d 8418787160
    06:05:052010-12-271710.10.10.7239.255.255.250-> e 819002350

    Packer Results

    Packer Name

    HoneyTrap Results

    Honey Trap Log File Location

    PTFB Results

    PTFB Log File Location