Malware Report - Results

This report shows all the different areas TAZER analyzes for the sample: Host, Network Activity, and Detection.

Malware Search Criteria:
  • MD5 =8bb5873fe1feb146dfe1773ac9d57ce4

  • Malware Report - Results

    File MD5SumSHA1SUMSHA256SUMFUZZY HASHFile Size
    8bb5873fe1feb146dfe1773ac9d57ce4bc0f089f24c68aa6a3ae030b6c365f0d10cbad5a29172a5f58224fd406a154796b401e91944390d00d410a04115c9e79a64984cd6144:RBgh/58KGip9lmh0UwwDdxtPw13OyhFR8uHQ5fSBx:RBMmKGnhDT+JlC1Q289186

    File Results

    File Name
    inter%2Dsecurity.exe

    SNORT Results

    Snort ClassSnort AlertCount
    N/ANo snort alerts generated0

    AV Results

    AV AlertAV Vendor

    Folders (Added) - ICC Results

    PathFolder Name

    Files (Added) - ICC Results

    PathFile Name
    c:/Documents and Settings/dmc73144/Local Settings/Temp~DF5C74.tmp
    c:/WINDOWS/PrefetchSANDNET.EXE-2012C478.pf
    c:/WINDOWS/system32winsys.exe
    c:/WINDOWSwinrun.exe
    c:netstat_post.txt
    c:taskv_post.txt

    Files (Deleted) - ICC Results

    ActionPathFile Name

    Files (Changed) - ICC Results

    ActionPathFile Name
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchHSTART.EXE-221D72BF.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/system32/drivers/etchosts
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP

    Registry Keys (Added) - ICC Results

    ActionPath

    Registry Values (Added) - ICC Results

    ActionPathVal_NameVal_Data

    Registry Values (Deleted) - ICC Results

    ActionPathVal_NameVal_TypeMod_Val_TypeVal_DataMod_Val_Data

    Registry Values (Changed) - ICC Results

    ActionPathVal_NameVal_DataMod_Val_Data
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeedD5 D8 2C E1 AD 3E D8 83 FA 61 09 10 9F 12 5D A0 B0 6B 22 33 C0 B1 78 AF B3 2C CC FC 41 03 CA CB CF 17 74 20 87 9D 2F A9 C4 4D 70 A9 D9 67 B1 DC E2 84 DD 72 95 5
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows NT/CurrentVersion/Windowsload"" "C

    DNS Results

    DNSDNS Response

    URL Results

    DstIPHTTP_HOSTHTTP_REQUEST_URIHTTP_USER_AGENTPROTOCOL
    174.123.213.82174.123.213.82/~dementec/server.phpvb wininet0x06
    239.255.255.250239.255.255.250:1900*--blank--0x11

    ARGUS PROTOCOL Results

    PROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    64453563382045835
    17305250

    ARGUS DPORT Results

    DPORTPROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    8064453563382045835
    190017305250

    ARGUS DATA Results

    TimeDateProtocolSrcIPDstIPDirFlagsSportDportPktsBytes
    02:55:482010-06-16610.10.10.7174.123.213.82-> e 32809895
    02:55:512010-06-16610.10.10.7174.123.213.82-> e 62809895
    02:55:542010-06-16610.10.10.7174.123.213.82-> e 63809895
    02:55:562010-06-16610.10.10.7174.123.213.82-> e 64809895
    02:55:592010-06-16610.10.10.7174.123.213.82-> e 65809895
    02:56:012010-06-16610.10.10.7174.123.213.82-> e 66809895
    02:56:042010-06-16610.10.10.7174.123.213.82-> e 33809895
    02:56:062010-06-16610.10.10.7174.123.213.82-> e 126809895
    02:56:092010-06-16610.10.10.7174.123.213.82-> e 392809895
    02:56:112010-06-16610.10.10.7174.123.213.82-> e 475809895
    02:56:142010-06-16610.10.10.7174.123.213.82-> e 440809895
    02:56:172010-06-16610.10.10.7174.123.213.82-> e 332809895
    02:56:192010-06-16610.10.10.7174.123.213.82-> e 441809895
    02:56:222010-06-16610.10.10.7174.123.213.82-> e 476809895
    02:56:242010-06-16610.10.10.7174.123.213.82-> e 415809895
    02:56:272010-06-16610.10.10.7174.123.213.82-> e 416809895
    02:56:292010-06-16610.10.10.7174.123.213.82-> e 266809895
    02:56:322010-06-16610.10.10.7174.123.213.82-> e 393809895
    02:56:352010-06-16610.10.10.7174.123.213.82-> e 481809895
    02:56:372010-06-16610.10.10.7174.123.213.82-> e 209809895
    02:56:402010-06-16610.10.10.7174.123.213.82-> e 442809895
    02:56:422010-06-16610.10.10.7174.123.213.82-> e 482809895
    02:56:452010-06-16610.10.10.7174.123.213.82-> e 376809895
    02:56:482010-06-16610.10.10.7174.123.213.82-> e 210809895
    02:56:502010-06-16610.10.10.7174.123.213.82-> e 443809895
    02:56:532010-06-16610.10.10.7174.123.213.82-> e 483809895
    02:56:552010-06-16610.10.10.7174.123.213.82-> e 444809895
    02:56:582010-06-16610.10.10.7174.123.213.82-> e 364809895
    02:57:002010-06-16610.10.10.7174.123.213.82-> e 438809895
    02:57:032010-06-16610.10.10.7174.123.213.82-> e 493809895
    02:57:052010-06-16610.10.10.7174.123.213.82-> e 446809895
    02:57:082010-06-16610.10.10.7174.123.213.82-> e 494809895
    02:57:112010-06-16610.10.10.7174.123.213.82-> e 447809895
    02:57:132010-06-16610.10.10.7174.123.213.82-> e 321809895
    02:57:162010-06-16610.10.10.7174.123.213.82-> e 448809895
    02:57:182010-06-16610.10.10.7174.123.213.82-> e 495809895
    02:57:212010-06-16610.10.10.7174.123.213.82-> e 449809895
    02:57:242010-06-16610.10.10.7174.123.213.82-> e 248809895
    02:57:262010-06-16610.10.10.7174.123.213.82-> e 284809895
    02:57:292010-06-16610.10.10.7174.123.213.82-> e 225809895
    02:57:312010-06-16610.10.10.7174.123.213.82-> e 226809895
    02:57:342010-06-16610.10.10.7174.123.213.82-> e 227809895
    02:57:362010-06-16610.10.10.7174.123.213.82-> e 439809895
    02:57:392010-06-16610.10.10.7174.123.213.82-> e 159809895
    02:57:422010-06-16610.10.10.7174.123.213.82-> e 451809895
    02:57:442010-06-16610.10.10.7174.123.213.82-> e 42809895
    02:57:472010-06-16610.10.10.7174.123.213.82-> e 412809895
    02:57:492010-06-16610.10.10.7174.123.213.82-> e 91809895
    02:57:522010-06-16610.10.10.7174.123.213.82-> e 513809895
    02:57:552010-06-16610.10.10.7174.123.213.82-> e 514809895
    02:57:572010-06-16610.10.10.7174.123.213.82-> e 452809895
    02:58:002010-06-16610.10.10.7174.123.213.82-> e 21809895
    02:58:032010-06-16610.10.10.7174.123.213.82-> e 379809895
    02:58:052010-06-16610.10.10.7174.123.213.82-> e 189809895
    02:58:082010-06-16610.10.10.7174.123.213.82-> e 190809895
    02:58:112010-06-16610.10.10.7174.123.213.82-> e 191809895
    02:58:132010-06-16610.10.10.7174.123.213.82-> e 92809895
    02:58:162010-06-16610.10.10.7174.123.213.82-> e 516809895
    02:58:192010-06-16610.10.10.7174.123.213.82-> e 336809895
    02:58:212010-06-16610.10.10.7174.123.213.82-> e 337809895
    02:58:242010-06-16610.10.10.7174.123.213.82-> e 338809895
    02:58:272010-06-16610.10.10.7174.123.213.82-> e 517809895
    02:58:292010-06-16610.10.10.7174.123.213.82-> e 612809895
    02:58:322010-06-16610.10.10.7174.123.213.82-> e 613809895
    02:58:342010-06-16610.10.10.7174.123.213.82-> e 614809895
    02:58:372010-06-16610.10.10.7174.123.213.82-> e 615809895
    02:58:392010-06-16610.10.10.7174.123.213.82-> e 616809895
    02:58:422010-06-16610.10.10.7174.123.213.82-> e 411809895
    02:58:452010-06-16610.10.10.7174.123.213.82-> e 456809895
    02:58:472010-06-16610.10.10.7174.123.213.82-> e 632809895
    02:58:502010-06-16610.10.10.7174.123.213.82-> e 633809895
    02:58:522010-06-16610.10.10.7174.123.213.82-> e 634809895
    02:58:552010-06-16610.10.10.7174.123.213.82-> e 635809895
    02:58:572010-06-16610.10.10.7174.123.213.82-> e 293809895
    02:59:002010-06-16610.10.10.7174.123.213.82-> e 471809895
    02:59:032010-06-16610.10.10.7174.123.213.82-> e 636809895
    02:59:052010-06-16610.10.10.7174.123.213.82-> e 348809895
    02:59:082010-06-16610.10.10.7174.123.213.82-> e 24809895
    02:59:102010-06-16610.10.10.7174.123.213.82-> e 459809895
    02:59:132010-06-16610.10.10.7174.123.213.82-> e 645809895
    02:59:162010-06-16610.10.10.7174.123.213.82-> e 460809895
    02:59:182010-06-16610.10.10.7174.123.213.82-> e 646809895
    02:59:212010-06-16610.10.10.7174.123.213.82-> e 647809895
    02:59:232010-06-16610.10.10.7174.123.213.82-> e 648809895
    02:59:262010-06-16610.10.10.7174.123.213.82-> e 649809895
    02:59:282010-06-16610.10.10.7174.123.213.82-> e 650809895
    02:59:312010-06-16610.10.10.7174.123.213.82-> e 651809895
    02:59:332010-06-16610.10.10.7174.123.213.82-> e 652809895
    02:59:362010-06-16610.10.10.7174.123.213.82-> e 653809895
    03:01:082010-06-161710.10.10.7239.255.255.250-> e 819002350
    03:01:142010-06-161710.10.10.7239.255.255.250-> e 819001175

    Packer Results

    Packer Name

    HoneyTrap Results

    Honey Trap Log File Location

    PTFB Results

    PTFB Log File Location