Malware Report - Results

This report shows all the different areas TAZER analyzes for the sample: Host, Network Activity, and Detection.

Malware Search Criteria:
  • MD5 =5675f5fe409b89eb61136fc3dac675b5

  • Malware Report - Results

    File MD5SumSHA1SUMSHA256SUMFUZZY HASHFile Size
    5675f5fe409b89eb61136fc3dac675b5d33e8c8ce1d2aea0f3df54033a4c6bcb458ec5fbe49fbbf0bae408000b644e2cb44437c56d8e351cd70d57d3ab0cff8cff1b0f1b1536:HGXwVWm5UuQlJd40/llDl8ZUF/elGLQqYXwHPzfRjG86jjDO:HGXwP5dQLe0/bl8ZLlGLZY64lD171008

    File Results

    File Name
    bkb.VirusRamnit%2DaJoSqNtL167.exe

    SNORT Results

    Snort ClassSnort AlertCount
    Misc AttackET RBN Known Russian Business Network IP TCP (316)3
    Misc AttackET RBN Known Russian Business Network IP TCP (66)1
    Misc AttackET RBN Known Russian Business Network IP TCP (187)1
    A Network Trojan was DetectedET DROP Known Bot C&C Server Traffic TCP (group 90) 1
    A Network Trojan was DetectedET DROP Known Bot C&C Server Traffic TCP (group 176) 1

    AV Results

    AV AlertAV Vendor
    Packed.Protexor!gen1Symantec
    PWS-Zbot.gen.diMcAfee
    Virus.Win32.Virut.ceKaspersky

    Folders (Added) - ICC Results

    PathFolder Name

    Files (Added) - ICC Results

    PathFile Name
    c:/Documents and Settings/dmc73144/Start Menu/Programs/Startuppdlkjkis.exe
    c:/Program Files/Internet Explorerdmlconf.dat
    c:/WINDOWS/PrefetchIEXPLORE.EXE-27122324.pf
    c:/WINDOWS/PrefetchSANDNET.EXE-2012C478.pf
    c:netstat_post.txt
    c:taskv_post.txt

    Files (Deleted) - ICC Results

    ActionPathFile Name

    Files (Changed) - ICC Results

    ActionPathFile Name
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Program Files/Internet Exploreriexplore.exe
    modifiedc:/Program Files/OpenSSH/binsh.exe
    modifiedc:/Program Files/OpenSSH/binswitch.exe
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchHSTART.EXE-221D72BF.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/system32/configdefault.LOG
    modifiedc:/WINDOWS/system32/drivers/etchosts
    modifiedc:/WINDOWS/system32netstat.exe
    modifiedc:/WINDOWS/system32tasklist.exe

    Registry Keys (Added) - ICC Results

    ActionPath

    Registry Values (Added) - ICC Results

    ActionPathVal_NameVal_Data

    Registry Values (Deleted) - ICC Results

    ActionPathVal_NameVal_TypeMod_Val_TypeVal_DataMod_Val_Data

    Registry Values (Changed) - ICC Results

    ActionPathVal_NameVal_DataMod_Val_Data
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed79 EC 33 20 B3 35 86 BE 79 F1 2A 83 1C B4 FF 70 A1 61 90 3A 7D 7F 7A 60 01 48 14 C4 D1 28 2D 11 4B 2A 42 9A 90 13 C6 F6 61 55 B3 63 7B 8B 89 4F D7 A1 AA B0 4B C
    modifiedHKLM/SYSTEM/ControlSet001/Services/SharedAccess/EpochEpoch0x00000104 0x00000106
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/SharedAccess/EpochEpoch0x00000104 0x00000106
    modifiedHKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Explorer/Shell FoldersCookiesC:Documents and SettingsDefault UserCookies "C
    modifiedHKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Explorer/Shell FoldersCacheC:Documents and SettingsDefault UserLocal SettingsTemporary Internet Files "C
    modifiedHKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Explorer/Shell FoldersHistoryC:Documents and SettingsDefault UserLocal SettingsHistory "C
    modifiedHKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Explorer/Shell FoldersCookiesC:Documents and SettingsDefault UserCookies "C
    modifiedHKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Explorer/Shell FoldersCacheC:Documents and SettingsDefault UserLocal SettingsTemporary Internet Files "C
    modifiedHKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Explorer/Shell FoldersHistoryC:Documents and SettingsDefault UserLocal SettingsHistory "C

    DNS Results

    DNSDNS Response
    google.comStandard query response A 74.125.93.105 A 74.125.93.106 A 74.125.93.147 A 74.125.93.99 A 74.125.93.103 A 74.125.93.104
    zahlung.nameStandard query response A 193.23.126.55
    ilo.brenz.plStandard query response A 83.133.119.197
    tybdtyutjfyvetscev.comStandard query response A 66.228.49.83
    ervwetyrbuyouiylkdhrbt.comStandard query response A 64.158.56.57 A 63.251.179.57
    buhpop.comStandard query response A 64.158.56.57 A 63.251.179.57
    wervynuuyjhnbvfservdy.comStandard query response A 208.73.210.29
    tmtadt.comStandard query response A 63.251.179.57 A 64.158.56.57
    tybsyiutnrtvtybdrser.comStandard query response A 63.251.179.57 A 64.158.56.57
    denjou.comStandard query response A 63.251.179.57 A 64.158.56.57
    vlixta.comStandard query response A 63.251.179.57 A 64.158.56.57
    bzluxo.comStandard query response A 63.251.179.57 A 64.158.56.57
    dobcpe.comStandard query response A 63.251.179.57 A 64.158.56.57
    fjjvok.comStandard query response A 63.251.179.57 A 64.158.56.57
    ilo.brenz.plStandard query response A 60.190.222.139
    emcegn.comStandard query response A 64.158.56.57 A 63.251.179.57
    zkdbza.comStandard query response A 63.251.179.57 A 64.158.56.57

    URL Results

    DstIPHTTP_HOSTHTTP_REQUEST_URIHTTP_USER_AGENTPROTOCOL
    239.255.255.250239.255.255.250:1900*--blank--0x11

    ARGUS PROTOCOL Results

    PROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    63513272185341793
    17203500

    ARGUS DPORT Results

    DPORTPROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    806122111773028795
    44362292161412312998
    190017203500

    ARGUS DATA Results

    TimeDateProtocolSrcIPDstIPDirFlagsSportDportPktsBytes
    15:19:262011-06-25610.10.10.774.125.93.105-> e 22580111756
    15:19:262011-06-25610.10.10.7193.23.126.55-> e 22644315904
    15:19:262011-06-25610.10.10.783.133.119.197-> e 22780152052
    15:19:312011-06-25610.10.10.774.125.93.105-> e 22580101965
    15:19:312011-06-25610.10.10.7193.23.126.55-> e 2264436360
    15:19:312011-06-25610.10.10.783.133.119.197-> e 2278081572
    15:19:322011-06-25610.10.10.7193.23.126.55-> e 43944315973
    15:19:362011-06-25610.10.10.774.125.93.105-> e 225804513
    15:19:372011-06-25610.10.10.7193.23.126.55-> e 4394436360
    15:19:482011-06-25610.10.10.766.228.49.83-> e 51144315904
    15:19:532011-06-25610.10.10.766.228.49.83-> e 5114436360
    15:19:542011-06-25610.10.10.766.228.49.83-> e 14244315973
    15:19:592011-06-25610.10.10.766.228.49.83-> e 1424436360
    15:20:042011-06-25610.10.10.783.133.119.197-> e 34480152052
    15:20:092011-06-25610.10.10.783.133.119.197-> e 34480101965
    15:20:102011-06-25610.10.10.764.158.56.57-> e 53044316964
    15:20:152011-06-25610.10.10.764.158.56.57-> e 5304435300
    15:20:162011-06-25610.10.10.764.158.56.57-> e 192443161033
    15:20:212011-06-25610.10.10.764.158.56.57-> e 1924435300
    15:20:252011-06-25610.10.10.764.158.56.57-> e 53144311664
    15:20:302011-06-25610.10.10.764.158.56.57-> e 53144310600
    15:20:322011-06-25610.10.10.7208.73.210.29-> e 56844315904
    15:20:352011-06-25610.10.10.764.158.56.57-> e 5314434240
    15:20:362011-06-25610.10.10.774.125.93.105-> e 56980111756
    15:20:382011-06-25610.10.10.7208.73.210.29-> e 5684436360
    15:20:382011-06-25610.10.10.7208.73.210.29-> e 57044315973
    15:20:412011-06-25610.10.10.774.125.93.105-> e 56980112298
    15:20:432011-06-25610.10.10.783.133.119.197-> e 57180152052
    15:20:442011-06-25610.10.10.7208.73.210.29-> e 5704436360
    15:20:452011-06-25610.10.10.764.158.56.57-> e 5314432120
    15:20:452011-06-25610.10.10.763.251.179.57-> e 57244312724
    15:20:462011-06-25610.10.10.774.125.93.105-> e 569803180
    15:20:482011-06-25610.10.10.783.133.119.197-> e 571804786
    15:20:502011-06-25610.10.10.763.251.179.57-> e 57244310600
    15:20:552011-06-25610.10.10.763.251.179.57-> e 57344315904
    15:20:552011-06-25610.10.10.763.251.179.57-> e 5724433180
    15:21:002011-06-25610.10.10.763.251.179.57-> e 5734436360
    15:21:012011-06-25610.10.10.763.251.179.57-> e 607443161033
    15:21:052011-06-25610.10.10.763.251.179.57-> e 60844311664
    15:21:052011-06-25610.10.10.763.251.179.57-> e 5724432120
    15:21:062011-06-25610.10.10.763.251.179.57-> e 6074435300
    15:21:102011-06-25610.10.10.763.251.179.57-> e 60844310600
    15:21:152011-06-25610.10.10.763.251.179.57-> e 6084434240
    15:21:192011-06-25610.10.10.783.133.119.197-> e 2280172445
    15:21:252011-06-25610.10.10.763.251.179.57-> e 62644311664
    15:21:252011-06-25610.10.10.763.251.179.57-> e 6084432120
    15:21:302011-06-25610.10.10.763.251.179.57-> e 62644310600
    15:21:352011-06-25610.10.10.763.251.179.57-> e 6264434240
    15:21:452011-06-25610.10.10.763.251.179.57-> e 62744311664
    15:21:452011-06-25610.10.10.763.251.179.57-> e 6264432120
    15:21:472011-06-25610.10.10.774.125.93.105-> e 32580111756
    15:21:502011-06-25610.10.10.763.251.179.57-> e 62744311660
    15:21:522011-06-25610.10.10.774.125.93.105-> e 32580101965
    15:21:552011-06-25610.10.10.783.133.119.197-> e 64080172168
    15:21:552011-06-25610.10.10.763.251.179.57-> e 6274433180
    15:21:572011-06-25610.10.10.774.125.93.105-> e 325804513
    15:22:002011-06-25610.10.10.783.133.119.197-> e 640802393
    15:22:052011-06-25610.10.10.763.251.179.57-> e 6274432120
    15:22:052011-06-25610.10.10.763.251.179.57-> e 72644312724
    15:22:112011-06-25610.10.10.763.251.179.57-> e 72644310600
    15:22:162011-06-25610.10.10.763.251.179.57-> e 7264433180
    15:22:252011-06-25610.10.10.763.251.179.57-> e 7264432120
    15:22:252011-06-25610.10.10.763.251.179.57-> e 77244312724
    15:22:302011-06-25610.10.10.760.190.222.139-> e 77380131659
    15:22:312011-06-25610.10.10.763.251.179.57-> e 77244310600
    15:22:362011-06-25610.10.10.763.251.179.57-> e 7724433180
    15:22:462011-06-25610.10.10.764.158.56.57-> e 82044311664
    15:22:452011-06-25610.10.10.763.251.179.57-> e 7724432120
    15:22:512011-06-25610.10.10.764.158.56.57-> e 82044311660
    15:22:562011-06-25610.10.10.764.158.56.57-> e 8204433180
    15:22:572011-06-25610.10.10.774.125.93.105-> e 82180111756
    15:23:022011-06-25610.10.10.774.125.93.105-> e 82180112298
    15:23:032011-06-25610.10.10.760.190.222.139-> e 82280152052
    15:23:062011-06-25610.10.10.764.158.56.57-> e 8204432120
    15:23:062011-06-25610.10.10.763.251.179.57-> e 82344312724
    15:23:072011-06-25610.10.10.774.125.93.105-> e 821803180
    15:23:082011-06-25610.10.10.760.190.222.139-> e 822802393
    15:23:112011-06-25610.10.10.763.251.179.57-> e d 8234435300
    15:23:172011-06-25610.10.10.763.251.179.57-> e d 8234432120
    15:24:442011-06-251710.10.10.7239.255.255.250-> e 819002350

    Packer Results

    Packer Name

    HoneyTrap Results

    Honey Trap Log File Location

    PTFB Results

    PTFB Log File Location