Malware Report - Results

This report shows all the different areas TAZER analyzes for the sample: Host, Network Activity, and Detection.

Malware Search Criteria:
  • MD5 =4c806459c744620b84cc6dceb838ef64

  • Malware Report - Results

    File MD5SumSHA1SUMSHA256SUMFUZZY HASHFile Size
    4c806459c744620b84cc6dceb838ef646ec805f13214a93d3b615e8cc614a6cc734966a15053bef3c6b22cb1ac90d124f8794d3f8541119b35b26edd2e221e3b38c52aa53072:ZYhrihSYup/A1kgDwWHUzEfY18miNLrV/LKL9XWyaWWKRp6a6Q8qqoXVUFfDU3eR:yhR9vJoYNi281600

    File Results

    File Name
    show.php.exe
    4.exe

    SNORT Results

    Snort ClassSnort AlertCount
    N/ANo snort alerts generated0

    AV Results

    AV AlertAV Vendor

    Folders (Added) - ICC Results

    PathFolder Name

    Files (Added) - ICC Results

    PathFile Name
    c:/WINDOWS/PrefetchSANDNET.EXE-2012C478.pf
    c:netstat_post.txt
    c:taskv_post.txt
    c:/DELL/VIDEO/OUTPUTnetstat_base.txt
    c:/DELL/VIDEO/OUTPUTnetstat_post.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_base.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_post.txt
    c:/DELL/VIDEO/OUTPUTtaskv_base.txt
    c:/DELL/VIDEO/OUTPUTtaskv_post.txt
    c:/WINDOWS/Prefetch7Z.EXE-1A62CD19.pf
    c:/WINDOWS/PrefetchNET.EXE-01A53C2F.pf
    c:/WINDOWS/PrefetchNET1.EXE-029B9DB4.pf
    c:/WINDOWS/PrefetchSANDNET.EXE-2012C478.pf

    Files (Deleted) - ICC Results

    ActionPathFile Name

    Files (Changed) - ICC Results

    ActionPathFile Name
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/system32/drivers/etchosts
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/PrefetchWMIPRVSE.EXE-28F301A9.pf
    modifiedc:/WINDOWS/system32/drivers/etchosts
    modifiedc:/WINDOWS/system32/wbem/Logswbemess.log
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP

    Registry Keys (Added) - ICC Results

    ActionPath

    Registry Values (Added) - ICC Results

    ActionPathVal_NameVal_Data

    Registry Values (Deleted) - ICC Results

    ActionPathVal_NameVal_TypeMod_Val_TypeVal_DataMod_Val_Data

    Registry Values (Changed) - ICC Results

    ActionPathVal_NameVal_DataMod_Val_Data
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed76 AC F7 94 5F 99 33 45 87 54 77 27 83 3F 5B 58 C9 05 A5 00 43 7F 1E CC 7F BC 9C 21 32 D9 E3 69 1B 4A 0D 34 90 BA C2 4A 40 F2 FD 20 99 9C BB 6F 1A A2 9E 0A D3 E
    modifiedHKLM/SYSTEM/ControlSet001/Services/SharedAccess/EpochEpoch0x00000104 0x00000105
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/SharedAccess/EpochEpoch0x00000104 0x00000105
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x00000002 0x00000001
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed79 11 5E 7B 2F 80 C5 21 6B 88 D9 44 AB 5D C2 6F A7 C7 DB BF E8 63 F1 11 59 46 46 99 92 8B 6B 50 57 A9 72 AC 16 D5 02 8C 48 4F 76 2E 9B 9B 99 1F 4F A7 D3 26 46 C
    modifiedHKLM/SYSTEM/ControlSet001/Services/SharedAccess/EpochEpoch0x00000104 0x00000105
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/SharedAccess/EpochEpoch0x00000104 0x00000105
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x00000002 0x00000001

    DNS Results

    DNSDNS Response

    URL Results

    DstIPHTTP_HOSTHTTP_REQUEST_URIHTTP_USER_AGENTPROTOCOL
    77.78.240.80drivers-win-x4442124.com/vk/get_ip_pay_needblock_lite.php0x06
    77.78.240.80drivers-win-x4442124.com/vk/1-md50x06
    77.78.240.80drivers-win-x4442124.com/vk/1-encode0x06
    239.255.255.250239.255.255.250:1900*--blank--0x11

    ARGUS PROTOCOL Results

    PROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    69084589221432
    17203500

    ARGUS DPORT Results

    DPORTPROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    8069084589221432
    190017203500

    ARGUS DATA Results

    TimeDateProtocolSrcIPDstIPDirFlagsSportDportPktsBytes
    07:55:462010-09-25610.10.10.777.78.240.80-> e 22480131971
    07:55:512010-09-25610.10.10.777.78.240.80-> e 22480101965
    07:55:562010-09-25610.10.10.777.78.240.80-> e 224806633
    07:55:572010-09-25610.10.10.777.78.240.80-> e 28480131947
    07:56:022010-09-25610.10.10.777.78.240.80-> e 28480101965
    07:56:072010-09-25610.10.10.777.78.240.80-> e 284806633
    07:56:082010-09-25610.10.10.777.78.240.80-> e 51180131950
    07:56:132010-09-25610.10.10.777.78.240.80-> e 51180112298
    07:56:182010-09-25610.10.10.777.78.240.80-> e 511805300
    07:58:192010-09-25610.10.10.777.78.240.80-> e 61980131971
    07:58:242010-09-25610.10.10.777.78.240.80-> e 61980112298
    07:58:292010-09-25610.10.10.777.78.240.80-> e 619805300
    07:58:302010-09-25610.10.10.777.78.240.80-> e 66880131947
    07:58:352010-09-25610.10.10.777.78.240.80-> e 66880112298
    07:58:412010-09-25610.10.10.777.78.240.80-> e 668805300
    07:58:412010-09-25610.10.10.777.78.240.80-> e 46180131950
    07:58:462010-09-25610.10.10.777.78.240.80-> e 46180112298
    07:58:512010-09-25610.10.10.777.78.240.80-> e 461805300
    08:01:102010-09-251710.10.10.7239.255.255.250-> e 819002350
    20:09:142010-09-25610.10.10.777.78.240.80-> e 22280131971
    20:09:192010-09-25610.10.10.777.78.240.80-> e d 22280122631
    20:09:252010-09-25610.10.10.777.78.240.80-> e 222805300
    20:09:252010-09-25610.10.10.777.78.240.80-> e 22380131947
    20:09:312010-09-25610.10.10.777.78.240.80-> e 22380112298
    20:09:362010-09-25610.10.10.777.78.240.80-> e 223805300
    20:09:362010-09-25610.10.10.777.78.240.80-> e 40080131950
    20:09:422010-09-25610.10.10.777.78.240.80-> e 40080101965
    20:09:472010-09-25610.10.10.777.78.240.80-> e 400806633
    20:11:482010-09-25610.10.10.777.78.240.80-> e 29980131971
    20:11:532010-09-25610.10.10.777.78.240.80-> e 29980101965
    20:11:582010-09-25610.10.10.777.78.240.80-> e 299806633
    20:11:592010-09-25610.10.10.777.78.240.80-> e 71480142280
    20:12:042010-09-25610.10.10.777.78.240.80-> e 71480112025
    20:12:102010-09-25610.10.10.777.78.240.80-> e 75680131950
    20:12:102010-09-25610.10.10.777.78.240.80-> e 714804240
    20:12:152010-09-25610.10.10.777.78.240.80-> e 75680112298
    20:12:202010-09-25610.10.10.777.78.240.80-> e 756805300
    20:14:392010-09-251710.10.10.7239.255.255.250-> e 819002350

    Packer Results

    Packer Name

    HoneyTrap Results

    Honey Trap Log File Location

    PTFB Results

    PTFB Log File Location