**** Malware_Report_-_Results **** This report shows all the different areas TAZER analyzes for the sample: Host, Network Activity, and Detection. Malware Search Criteria: MD5 =933bb6d8cee414557e3633153cb1f3c0 **** Malware_Report_-_Results **** _____________________________________________________________________________________________________________________________________________________________________________________________________________________ |File_MD5Sum_____________________|SHA1SUM_________________________________|SHA256SUM_______________________________________________________|FUZZY_HASH______________________________________________________|File_Size| |933bb6d8cee414557e3633153cb1f3c0|81749e12407ddbfbc7564f7487c77b7861f356d4|e771c3f170e1a7f4d97d5a7557a8fcdb5b050cab277e03df07f965bcfb879051|1536:dW9vJ7Z3247p2WI7d+rv43nYCGnm/bbxdzCOrRLj8:Q704zGcQ/Gm/reEH8|79528____| **** File_Results **** ______________ |File_Name_____| |l.php.exe_____| |exe.exe_______| |%3Fc%3D917.exe| **** SNORT_Results **** ___________________________________________ |Snort_Class|Snort_Alert______________|Count| |N/A________|No_snort_alerts_generated|0____| **** AV_Results **** ________________________________ |AV_Alert______________|AV_Vendor| |N/A___________________|Symantec_| |N/A___________________|McAfee___| |N/A___________________|Kaspersky| |Trojan.Win32.Qhost.nso|Kaspersky| **** Folders_(Added)_-_ICC_Results **** ________________ |Path|Folder_Name| **** Files_(Added)_-_ICC_Results **** ______________________________________________ |Path________________|File_Name________________| |c:/WINDOWS/Prefetch_|SANDNET.EXE-2012C478.pf__| |c:/WINDOWS/system32_|hosts____________________| |c:__________________|netstat_post.txt_________| |c:__________________|tasksvc_post.txt_________| |c:__________________|taskv_post.txt___________| |c:/WINDOWS/Prefetch_|SANDNET.EXE-2012C478.pf__| |c:/WINDOWS/system32_|hosts____________________| |c:__________________|netstat_post.txt_________| |c:__________________|taskv_post.txt___________| |c:/WINDOWS/Prefetch_|SANDNET.EXE-2012C478.pf__| |c:/WINDOWS/system32_|hosts____________________| |c:__________________|netstat_post.txt_________| |c:__________________|taskv_post.txt___________| |c:/WINDOWS/Prefetch_|SANDNET.EXE-2012C478.pf__| |c:/WINDOWS/system32_|hosts____________________| |c:__________________|netstat_post.txt_________| |c:__________________|tasksvc_post.txt_________| |c:__________________|taskv_post.txt___________| |c:/WINDOWS/Prefetch_|SANDNET.EXE-2012C478.pf__| |c:/WINDOWS/system32_|hosts____________________| |c:__________________|netstat_post.txt_________| |c:__________________|tasksvc_post.txt_________| |c:__________________|taskv_post.txt___________| |c:/DELL/VIDEO/OUTPUT|netstat_base.txt_________| |c:/DELL/VIDEO/OUTPUT|netstat_post.txt_________| |c:/DELL/VIDEO/OUTPUT|tasksvc_base.txt_________| |c:/DELL/VIDEO/OUTPUT|tasksvc_post.txt_________| |c:/DELL/VIDEO/OUTPUT|taskv_base.txt___________| |c:/DELL/VIDEO/OUTPUT|taskv_post.txt___________| |c:/WINDOWS/Prefetch_|7Z.EXE-1A62CD19.pf_______| |c:/WINDOWS/Prefetch_|CYGRUNSRV.EXE-01BF82AE.pf| |c:/WINDOWS/Prefetch_|NET.EXE-01A53C2F.pf______| |c:/WINDOWS/Prefetch_|NET1.EXE-029B9DB4.pf_____| |c:/DELL/VIDEO/OUTPUT|netstat_base.txt_________| |c:/DELL/VIDEO/OUTPUT|netstat_post.txt_________| |c:/DELL/VIDEO/OUTPUT|tasksvc_base.txt_________| |c:/DELL/VIDEO/OUTPUT|tasksvc_post.txt_________| |c:/DELL/VIDEO/OUTPUT|taskv_base.txt___________| |c:/DELL/VIDEO/OUTPUT|taskv_post.txt___________| |c:/WINDOWS/Prefetch_|7Z.EXE-1A62CD19.pf_______| |c:/WINDOWS/Prefetch_|NET.EXE-01A53C2F.pf______| |c:/WINDOWS/Prefetch_|NET1.EXE-029B9DB4.pf_____| |c:__________________|netstat_post.txt_________| |c:__________________|tasksvc_post.txt_________| |c:__________________|taskv_post.txt___________| **** Files_(Deleted)_-_ICC_Results **** _____________________ |Action|Path|File_Name| **** Files_(Changed)_-_ICC_Results **** ________________________________________________________________________ |Action__|Path__________________________________|File_Name_______________| |modified|c:/Documents_and_Settings/dmc73144____|ntuser.dat.LOG__________| |modified|c:/WINDOWS/Prefetch___________________|CMD.EXE-087B4001.pf_____| |modified|c:/WINDOWS/Prefetch___________________|HSTART.EXE-221D72BF.pf__| |modified|c:/WINDOWS/Prefetch___________________|NETSTAT.EXE-2B2B4428.pf_| |modified|c:/WINDOWS/Prefetch___________________|SH.EXE-00254D2B.pf______| |modified|c:/WINDOWS/Prefetch___________________|SLEEP.EXE-094A3D2A.pf___| |modified|c:/WINDOWS/Prefetch___________________|SSHD.EXE-298CA236.pf____| |modified|c:/WINDOWS/Prefetch___________________|SWITCH.EXE-0496EC21.pf__| |modified|c:/WINDOWS/Prefetch___________________|TASKLIST.EXE-10D94B23.pf| |modified|c:/WINDOWS/system32/drivers/etc_______|hosts___________________| |modified|c:/WINDOWS/system32/wbem/Logs_________|wmiprov.log_____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|INDEX.MAP_______________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|MAPPING.VER_____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|MAPPING2.MAP____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|OBJECTS.MAP_____________| |modified|c:/Documents_and_Settings/dmc73144____|ntuser.dat.LOG__________| |modified|c:/WINDOWS/Prefetch___________________|CMD.EXE-087B4001.pf_____| |modified|c:/WINDOWS/Prefetch___________________|HSTART.EXE-221D72BF.pf__| |modified|c:/WINDOWS/Prefetch___________________|NETSTAT.EXE-2B2B4428.pf_| |modified|c:/WINDOWS/Prefetch___________________|SH.EXE-00254D2B.pf______| |modified|c:/WINDOWS/Prefetch___________________|SLEEP.EXE-094A3D2A.pf___| |modified|c:/WINDOWS/Prefetch___________________|SSHD.EXE-298CA236.pf____| |modified|c:/WINDOWS/Prefetch___________________|SWITCH.EXE-0496EC21.pf__| |modified|c:/WINDOWS/system32/drivers/etc_______|hosts___________________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|INDEX.MAP_______________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|MAPPING.VER_____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|MAPPING2.MAP____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|OBJECTS.MAP_____________| |modified|c:/Documents_and_Settings/dmc73144____|ntuser.dat.LOG__________| |modified|c:/WINDOWS/Prefetch___________________|CMD.EXE-087B4001.pf_____| |modified|c:/WINDOWS/Prefetch___________________|HSTART.EXE-221D72BF.pf__| |modified|c:/WINDOWS/Prefetch___________________|NETSTAT.EXE-2B2B4428.pf_| |modified|c:/WINDOWS/Prefetch___________________|SH.EXE-00254D2B.pf______| |modified|c:/WINDOWS/Prefetch___________________|SLEEP.EXE-094A3D2A.pf___| |modified|c:/WINDOWS/Prefetch___________________|SSHD.EXE-298CA236.pf____| |modified|c:/WINDOWS/Prefetch___________________|SWITCH.EXE-0496EC21.pf__| |modified|c:/WINDOWS/system32/drivers/etc_______|hosts___________________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|INDEX.MAP_______________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|MAPPING.VER_____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|MAPPING2.MAP____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|OBJECTS.MAP_____________| |modified|c:/Documents_and_Settings/dmc73144____|ntuser.dat.LOG__________| |modified|c:/WINDOWS/Prefetch___________________|CMD.EXE-087B4001.pf_____| |modified|c:/WINDOWS/Prefetch___________________|HSTART.EXE-221D72BF.pf__| |modified|c:/WINDOWS/Prefetch___________________|NETSTAT.EXE-2B2B4428.pf_| |modified|c:/WINDOWS/Prefetch___________________|SH.EXE-00254D2B.pf______| |modified|c:/WINDOWS/Prefetch___________________|SLEEP.EXE-094A3D2A.pf___| |modified|c:/WINDOWS/Prefetch___________________|SSHD.EXE-298CA236.pf____| |modified|c:/WINDOWS/Prefetch___________________|SWITCH.EXE-0496EC21.pf__| |modified|c:/WINDOWS/Prefetch___________________|TASKLIST.EXE-10D94B23.pf| |modified|c:/WINDOWS/system32/drivers/etc_______|hosts___________________| |modified|c:/WINDOWS/system32/wbem/Logs_________|wmiprov.log_____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|INDEX.MAP_______________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|MAPPING.VER_____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|MAPPING2.MAP____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|OBJECTS.MAP_____________| |modified|c:/Documents_and_Settings/dmc73144____|ntuser.dat.LOG__________| |modified|c:/WINDOWS/Prefetch___________________|CMD.EXE-087B4001.pf_____| |modified|c:/WINDOWS/Prefetch___________________|HSTART.EXE-221D72BF.pf__| |modified|c:/WINDOWS/Prefetch___________________|NETSTAT.EXE-2B2B4428.pf_| |modified|c:/WINDOWS/Prefetch___________________|SH.EXE-00254D2B.pf______| |modified|c:/WINDOWS/Prefetch___________________|SLEEP.EXE-094A3D2A.pf___| |modified|c:/WINDOWS/Prefetch___________________|SSHD.EXE-298CA236.pf____| |modified|c:/WINDOWS/Prefetch___________________|SWITCH.EXE-0496EC21.pf__| |modified|c:/WINDOWS/Prefetch___________________|TASKLIST.EXE-10D94B23.pf| |modified|c:/WINDOWS/system32/drivers/etc_______|hosts___________________| |modified|c:/WINDOWS/system32/wbem/Logs_________|wmiprov.log_____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|INDEX.MAP_______________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|MAPPING.VER_____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|MAPPING2.MAP____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|OBJECTS.MAP_____________| |modified|c:/Documents_and_Settings/dmc73144____|ntuser.dat.LOG__________| |modified|c:/Program_Files/OpenSSH/var/run______|sshd.pid________________| |modified|c:/WINDOWS/Prefetch___________________|CMD.EXE-087B4001.pf_____| |modified|c:/WINDOWS/Prefetch___________________|NETSTAT.EXE-2B2B4428.pf_| |modified|c:/WINDOWS/Prefetch___________________|SH.EXE-00254D2B.pf______| |modified|c:/WINDOWS/Prefetch___________________|SLEEP.EXE-094A3D2A.pf___| |modified|c:/WINDOWS/Prefetch___________________|SSHD.EXE-298CA236.pf____| |modified|c:/WINDOWS/Prefetch___________________|SWITCH.EXE-0496EC21.pf__| |modified|c:/WINDOWS/Prefetch___________________|TASKLIST.EXE-10D94B23.pf| |modified|c:/WINDOWS/Prefetch___________________|WMIPRVSE.EXE-28F301A9.pf| |modified|c:/WINDOWS/system32/wbem/Logs_________|wbemess.log_____________| |modified|c:/WINDOWS/system32/wbem/Logs_________|wmiprov.log_____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|INDEX.MAP_______________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|MAPPING.VER_____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|MAPPING2.MAP____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|OBJECTS.MAP_____________| |modified|c:/Documents_and_Settings/dmc73144____|ntuser.dat.LOG__________| |modified|c:/WINDOWS/Prefetch___________________|CMD.EXE-087B4001.pf_____| |modified|c:/WINDOWS/Prefetch___________________|NETSTAT.EXE-2B2B4428.pf_| |modified|c:/WINDOWS/Prefetch___________________|SH.EXE-00254D2B.pf______| |modified|c:/WINDOWS/Prefetch___________________|SLEEP.EXE-094A3D2A.pf___| |modified|c:/WINDOWS/Prefetch___________________|SSHD.EXE-298CA236.pf____| |modified|c:/WINDOWS/Prefetch___________________|SWITCH.EXE-0496EC21.pf__| |modified|c:/WINDOWS/Prefetch___________________|TASKLIST.EXE-10D94B23.pf| |modified|c:/WINDOWS/Prefetch___________________|WMIPRVSE.EXE-28F301A9.pf| |modified|c:/WINDOWS/system32/wbem/Logs_________|wbemess.log_____________| |modified|c:/WINDOWS/system32/wbem/Logs_________|wmiprov.log_____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|INDEX.MAP_______________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|MAPPING.VER_____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|MAPPING2.MAP____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|OBJECTS.MAP_____________| |modified|c:/Documents_and_Settings/dmc73144____|ntuser.dat.LOG__________| |modified|c:/WINDOWS/Prefetch___________________|CMD.EXE-087B4001.pf_____| |modified|c:/WINDOWS/Prefetch___________________|NETSTAT.EXE-2B2B4428.pf_| |modified|c:/WINDOWS/Prefetch___________________|SH.EXE-00254D2B.pf______| |modified|c:/WINDOWS/Prefetch___________________|SSHD.EXE-298CA236.pf____| |modified|c:/WINDOWS/Prefetch___________________|SWITCH.EXE-0496EC21.pf__| |modified|c:/WINDOWS/Prefetch___________________|TASKLIST.EXE-10D94B23.pf| |modified|c:/WINDOWS/Prefetch___________________|WMIPRVSE.EXE-28F301A9.pf| |modified|c:/WINDOWS/system32/wbem/Logs_________|wmiprov.log_____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|INDEX.MAP_______________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|MAPPING.VER_____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|MAPPING2.MAP____________| |modified|c:/WINDOWS/system32/wbem/Repository/FS|OBJECTS.MAP_____________| **** Registry_Keys_(Added)_-_ICC_Results **** ___________ |Action|Path| **** Registry_Values_(Added)_-_ICC_Results **** _____________________________ |Action|Path|Val_Name|Val_Data| **** Registry_Values_(Deleted)_-_ICC_Results **** ________________________________________________________________ |Action|Path|Val_Name|Val_Type|Mod_Val_Type|Val_Data|Mod_Val_Data| **** Registry_Values_(Changed)_-_ICC_Results **** __________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________ |Action__|Path_______________________________________________________________|Val_Name____|Val_Data________________________________________________________________________|Mod_Val_Data___________________________________________________________________| |modified|HKLM/SOFTWARE/Microsoft/Cryptography/RNG___________________________|Seed________|45_72_55_20_D8_23_86_DC_85_0B_80_93_54_22_1A_C6_4B_24_EE_2B_AB_FA_78_C3_29_F0_90|3A_4F_23_F2_89_BD_7F_F7_31_CD_CD_0F_A7_9D_AB_B9_AD_D7_46_D7_A8_58_CF_58_F6_9E_8| |modified|HKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformation|ProgramCount|0x00000002______________________________________________________________________|0x00000001_____________________________________________________________________| |modified|HKLM/SOFTWARE/Microsoft/Cryptography/RNG___________________________|Seed________|9F_99_E9_CD_73_33_40_FB_65_28_FB_8B_F3_A2_BF_A2_E3_F5_FF_74_5F_17_40_B9_FA_4D_E1|26_7A_3F_11_D0_88_53_61_67_0D_4D_7C_9B_76_7F_86_59_81_BF_D4_A5_31_83_38_0C_DB_C| |modified|HKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformation|ProgramCount|0x00000002______________________________________________________________________|0x00000001_____________________________________________________________________| |modified|HKLM/SOFTWARE/Microsoft/Cryptography/RNG___________________________|Seed________|FC_32_65_78_EB_51_02_E7_2D_D8_E3_1B_33_97_BE_0E_E0_0D_F5_83_F5_2B_10_34_23_72_8E|69_5B_D7_89_1F_97_26_D7_27_5A_7B_9F_1D_05_90_E9_7A_20_56_54_D6_F2_FC_73_D7_74_A| |modified|HKLM/SOFTWARE/Microsoft/Cryptography/RNG___________________________|Seed________|54_4E_B0_3B_57_BD_47_62_94_70_45_63_9F_A2_11_B9_23_D7_F5_D4_2F_34_34_32_FB_A9_3D|E8_90_9F_75_C6_33_F4_A6_8C_93_DA_A6_BD_18_83_27_C7_86_18_15_3D_47_43_BB_7D_23_A| |modified|HKLM/SOFTWARE/Microsoft/Cryptography/RNG___________________________|Seed________|90_53_75_F9_E5_94_14_FE_15_F5_2C_FB_D3_43_5C_F3_42_DC_DF_6C_2A_F5_FC_F7_07_EF_FC|FF_C3_AB_E2_9C_26_40_D8_CC_7A_24_E9_B8_4A_53_46_79_76_CA_0A_B7_B0_AB_5A_77_27_1| |modified|HKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformation|ProgramCount|0x00000002______________________________________________________________________|0x00000001_____________________________________________________________________| |modified|HKLM/SOFTWARE/Microsoft/Cryptography/RNG___________________________|Seed________|DC_FB_58_40_9E_AA_AE_36_A2_32_99_3D_36_A5_FA_62_A1_84_3E_98_4E_CF_F4_60_4C_03_52|B5_3C_B0_C4_B1_E8_C8_CC_DF_4E_5F_79_2F_C8_A9_92_FE_E5_C6_94_6A_CD_82_26_6C_FA_A| |modified|HKLM/SYSTEM/ControlSet001/Control/ServiceCurrent___________________|____________|0x00000009______________________________________________________________________|0x0000000A_____________________________________________________________________| |modified|HKLM/SYSTEM/CurrentControlSet/Control/ServiceCurrent_______________|____________|0x00000009______________________________________________________________________|0x0000000A_____________________________________________________________________| |modified|HKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformation|ProgramCount|0x00000002______________________________________________________________________|0x00000001_____________________________________________________________________| |modified|HKLM/SOFTWARE/Microsoft/Cryptography/RNG___________________________|Seed________|06_ED_84_FE_65_C8_33_5E_F0_95_04_6C_0C_99_BC_59_36_54_18_3E_D7_7C_3E_A7_E6_FC_63|DC_58_04_15_1D_B0_04_DE_38_DF_6F_65_E6_63_65_21_BB_05_1D_C0_FE_4A_6A_C8_AF_40_5| |modified|HKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformation|ProgramCount|0x00000002______________________________________________________________________|0x00000001_____________________________________________________________________| |modified|HKLM/SOFTWARE/Microsoft/Cryptography/RNG___________________________|Seed________|C0_46_1D_FC_56_91_45_5B_51_2A_A6_EB_D5_F9_72_D4_53_33_4B_26_EA_F0_08_62_63_40_46|63_95_34_48_6F_0A_27_A9_D7_7B_85_BB_CD_63_A2_DF_5F_13_71_31_56_3A_9C_2D_BF_D0_D| |modified|HKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformation|ProgramCount|0x00000002______________________________________________________________________|0x00000001_____________________________________________________________________| **** DNS_Results **** ________________ |DNS|DNS_Response| **** URL_Results **** ______________________________________________________________________________ |DstIP__________|HTTP_HOST___________|HTTP_REQUEST_URI|HTTP_USER_AGENT|PROTOCOL| |239.255.255.250|239.255.255.250:1900|*_______________|--blank--______|0x11____| **** ARGUS_PROTOCOL_Results **** ______________________________________________ |PROTOCOL|SRC_PKTS|DST_PKTS|SRC_BYTES|DST_BYTES| |17______|3_______|0_______|525______|0________| **** ARGUS_DPORT_Results **** ____________________________________________________ |DPORT|PROTOCOL|SRC_PKTS|DST_PKTS|SRC_BYTES|DST_BYTES| |1900_|17______|3_______|0_______|525______|0________| **** ARGUS_DATA_Results **** ________________________________________________________________________________________ |Time____|Date______|Protocol|SrcIP_____|DstIP__________|Dir|Flags|Sport|Dport|Pkts|Bytes| |13:59:22|2010-08-09|17______|10.10.10.7|239.255.255.250|->_|e____|8____|1900_|2___|350__| |13:59:28|2010-08-09|17______|10.10.10.7|239.255.255.250|->_|e____|8____|1900_|1___|175__| |22:26:10|2010-08-09|17______|10.10.10.7|239.255.255.250|->_|e____|8____|1900_|2___|350__| |08:50:26|2010-08-10|17______|10.10.10.7|239.255.255.250|->_|e____|8____|1900_|2___|350__| |01:34:49|2010-08-11|17______|10.10.10.7|239.255.255.250|->_|e____|8____|1900_|2___|350__| |07:16:31|2010-08-11|17______|10.10.10.7|239.255.255.250|->_|e____|8____|1900_|2___|350__| |19:12:52|2010-08-11|17______|10.10.10.7|239.255.255.250|->_|e____|8____|1900_|2___|350__| |19:12:58|2010-08-11|17______|10.10.10.7|239.255.255.250|->_|e____|8____|1900_|1___|175__| |07:06:51|2010-08-12|17______|10.10.10.7|239.255.255.250|->_|e____|8____|1900_|2___|350__| |07:42:38|2010-08-13|17______|10.10.10.7|239.255.255.250|->_|e____|8____|1900_|1___|175__| **** Packer_Results **** ___________ |Packer_Name| **** HoneyTrap_Results **** ____________________________ |Honey_Trap_Log_File_Location| **** PTFB_Results **** ______________________ |PTFB_Log_File_Location|