Malware Report - Results

This report shows all the different areas TAZER analyzes for the sample: Host, Network Activity, and Detection.

Malware Search Criteria:
  • MD5 =a51770f9581ac7f6c65af774bf1a7450

  • Malware Report - Results

    File MD5SumSHA1SUMSHA256SUMFUZZY HASHFile Size
    a51770f9581ac7f6c65af774bf1a74508e5786a8a51cb42a728e392cdf87da26b42905326e13f6ada04d0cb6e63ed2c911e656005434801fcd48e790011961bb780026023072:124/wTotfpE4mCYT/6i5HSfiyY4x/3g0B8yf/WwG3VTiXa4aLC/lQ6qAkKcE:1sVHTii5HSfrx/237773

    File Results

    File Name
    explorer.exe

    SNORT Results

    Snort ClassSnort AlertCount
    N/ANo snort alerts generated0

    AV Results

    AV AlertAV Vendor
    Backdoor.TrojanSymantec
    N/AMcAfee
    Trojan.Win32.Scar.edlvKaspersky

    Folders (Added) - ICC Results

    PathFolder Name
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5WO4JPI86

    Files (Added) - ICC Results

    PathFile Name
    c:/Documents and Settings/dmc73144/Application Data/Mozilla/Firefox/Profiles/ektregxy.defaultsignons.sqlite
    c:/Documents and Settings/dmc73144/Application DataFILE_10452.exe
    c:/Documents and Settings/dmc73144/Application Datalovely.ini
    c:/Documents and Settings/dmc73144/Application Datanet.bat
    c:/Documents and Settings/dmc73144/Application Datanet.vbs
    c:/Documents and Settings/dmc73144/Application Datarsbot.exe.exe
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Crsbot[1].htm
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/WO4JPI86desktop.ini
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/WO4JPI86profile[1].htm
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/WO4JPI86profile[2].htm
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/WO4JPI86profile[3].htm
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/WO4JPI86profile[4].htm
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/WO4JPI86profile[5].htm
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/WO4JPI86profile[6].htm
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/WO4JPI86profile[7].htm
    c:/WINDOWS/PrefetchAUTOIT3.EXE-32361418.pf
    c:/WINDOWS/PrefetchNTVDM.EXE-1A10A423.pf
    c:/WINDOWS/PrefetchREGSHOT.EXE-010A5EE6.pf
    c:/WINDOWS/PrefetchSANDNET.EXE-2012C478.pf

    Files (Deleted) - ICC Results

    ActionPathFile Name

    Files (Changed) - ICC Results

    ActionPathFile Name
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144NTUSER.DAT
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchHSTART.EXE-221D72BF.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/system32/configsoftware.LOG
    modifiedc:/WINDOWS/system32/drivers/etchosts
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log

    Registry Keys (Added) - ICC Results

    ActionPath
    addedHKLM/SOFTWARE/Microsoft/DownloadManager
    addedHKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_FASTFAT/0000/Control
    addedHKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_FASTFAT/0000/Control
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/Active Directory GC
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/Bigfoot
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/VeriSign
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/WhoWhere

    Registry Values (Added) - ICC Results

    ActionPathVal_NameVal_Data
    addedHKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Runminecraft2 "C:/Documents and Settings/dmc73144/Application Data/rsbot.exe.exe"
    addedHKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_FASTFAT/0000/ControlActiveService"Fastfat"
    addedHKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_FASTFAT/0000/ControlActiveService"Fastfat"
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Identities/{32BF15D6-D919-458D-8A1A-AC3F3B3F3027}Identity Ordinal0x00000001
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Runminecraft2 "C:/Documents and Settings/dmc73144/Application Data/rsbot.exe.exe"
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/RunOnceFILE_10452 "C:/Documents and Settings/dmc73144/Application Data/FILE_10452.exe"
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/MUICacheC://Documents and Settings//dmc73144//Application Data//FILE_10452.exe "FILE_10452"
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/MUICacheC://WINDOWS//system32//ntvdm.exe "NTVDM.EXE"
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/WhoWhereLDAP Server ID0x00000003
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/WhoWhereAccount Name"WhoWhere Internet Directory Service"
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/WhoWhereLDAP Server"ldap.whowhere.com"
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/WhoWhereLDAP URL"http
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/WhoWhereLDAP Search Return0x00000064
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/WhoWhereLDAP Timeout0x0000003C
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/WhoWhereLDAP Authentication0x00000000
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/WhoWhereLDAP Simple Search0x00000001
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/WhoWhereLDAP Logo"%ProgramFiles%Common FilesServiceswhowhere.bmp"
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/VeriSignLDAP Server ID0x00000002
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/VeriSignAccount Name"VeriSign Internet Directory Service"
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/VeriSignLDAP Server"directory.verisign.com"
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/VeriSignLDAP URL"http
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/VeriSignLDAP Search Return0x00000064
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/VeriSignLDAP Timeout0x0000003C
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/VeriSignLDAP Authentication0x00000000
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/VeriSignLDAP Search Base"NULL"
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/VeriSignLDAP Simple Search0x00000001
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/VeriSignLDAP Logo"%ProgramFiles%Common FilesServicesverisign.bmp"
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/BigfootLDAP Server ID0x00000001
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/BigfootAccount Name"Bigfoot Internet Directory Service"
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/BigfootLDAP Server"ldap.bigfoot.com"
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/BigfootLDAP URL"http
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/BigfootLDAP Search Return0x00000064
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/BigfootLDAP Timeout0x0000003C
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/BigfootLDAP Authentication0x00000000
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/BigfootLDAP Simple Search0x00000001
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/BigfootLDAP Logo"%ProgramFiles%Common FilesServicesbigfoot.bmp"
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/Active Directory GCLDAP Server ID0x00000000
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/Active Directory GCAccount Name"Active Directory"
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/Active Directory GCLDAP Server"NULL"
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/Active Directory GCLDAP Search Return0x00000064
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/Active Directory GCLDAP Timeout0x0000003C
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/Active Directory GCLDAP Authentication0x00000002
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/Active Directory GCLDAP Simple Search0x00000000
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/Active Directory GCLDAP Bind DN0x00000000
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/Active Directory GCLDAP Port0x00000CC4
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/Active Directory GCLDAP Resolve Flag0x00000001
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/Active Directory GCLDAP Secure Connection0x00000000
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/Active Directory GCLDAP User Name"NULL"
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/Accounts/Active Directory GCLDAP Search Base"NULL"
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/AccountsAssociatedIDD6 15 BF 32 19 D9 8D 45 8A 1A AC 3F 3B 3F 30 27
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/AccountsPreConfigVer0x00000004
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account Manager/AccountsPreConfigVerNTDS0x00000001
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account ManagerServer ID0x00000004
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Account ManagerDefault LDAP Account"Active Directory GC"

    Registry Values (Deleted) - ICC Results

    ActionPathVal_NameVal_TypeMod_Val_TypeVal_DataMod_Val_Data

    Registry Values (Changed) - ICC Results

    ActionPathVal_NameVal_DataMod_Val_Data
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeedDC 3D 4A DC 08 36 5C 1B 6F B2 A0 3B 59 F9 6E A6 6B DC B9 87 2A 08 BA 52 13 76 8A9E 0E 3A 34 57 6E 93 77 C8 42 F4 B0 35 18 C1 2F AF 7D 9B C3 91 A7 1E 21 A2 68 92
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/IdentitiesIdentity Ordinal0x000000010x00000002
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 003C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x000000020x00000003

    DNS Results

    DNSDNS Response
    dl.dropbox.comStandard query response CNAME dl-balancer3-985632286.us-east-1.elb.amazonaws.com A 107.22.250.232
    www.facebook.comStandard query response A 69.171.224.12

    URL Results

    DstIPHTTP_HOSTHTTP_REQUEST_URIHTTP_USER_AGENTPROTOCOL
    107.22.250.232dl.dropbox.com/u/36324022/rsbot.exeMozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)0x06
    69.171.224.12www.facebook.com/profile.php?id=411455934648626&sk=infoMozilla/5.0 (Windows NT 6.1; rv:2.0b7pre) Gecko/20100921 Firefox/4.0b7pre0x06
    69.171.224.12www.facebook.com/profile.php?id=52539515487804&sk=infoMozilla/5.0 (Windows NT 6.1; rv:2.0b7pre) Gecko/20100921 Firefox/4.0b7pre0x06
    69.171.224.12www.facebook.com/profile.php?id=310105395852289&sk=infoMozilla/5.0 (Windows NT 6.1; rv:2.0b7pre) Gecko/20100921 Firefox/4.0b7pre0x06
    69.171.224.12www.facebook.com/profile.php?id=74675941738356&sk=infoMozilla/5.0 (Windows NT 6.1; rv:2.0b7pre) Gecko/20100921 Firefox/4.0b7pre0x06
    69.171.224.12www.facebook.com/profile.php?id=829409895918295&sk=infoMozilla/5.0 (Windows NT 6.1; rv:2.0b7pre) Gecko/20100921 Firefox/4.0b7pre0x06
    69.171.224.12www.facebook.com/profile.php?id=17473150399194&sk=infoMozilla/5.0 (Windows NT 6.1; rv:2.0b7pre) Gecko/20100921 Firefox/4.0b7pre0x06
    69.171.224.12www.facebook.com/profile.php?id=132485936477809&sk=infoMozilla/5.0 (Windows NT 6.1; rv:2.0b7pre) Gecko/20100921 Firefox/4.0b7pre0x06
    69.171.224.12www.facebook.com/profile.php?id=512573729158732&sk=infoMozilla/5.0 (Windows NT 6.1; rv:2.0b7pre) Gecko/20100921 Firefox/4.0b7pre0x06
    69.171.224.12www.facebook.com/profile.php?id=497004096959042&sk=infoMozilla/5.0 (Windows NT 6.1; rv:2.0b7pre) Gecko/20100921 Firefox/4.0b7pre0x06

    ARGUS PROTOCOL Results

    PROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    6504048835150

    ARGUS DPORT Results

    DPORTPROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    806504048835150

    ARGUS DATA Results

    TimeDateProtocolSrcIPDstIPDirFlagsSportDportPktsBytes
    17:50:422011-10-18610.10.10.7107.22.250.232-> e 5178091009
    17:50:582011-10-18610.10.10.769.171.224.12-> e 5478091003
    17:51:142011-10-18610.10.10.769.171.224.12-> e 5878091002
    17:51:302011-10-18610.10.10.769.171.224.12-> e 3828091003
    17:51:462011-10-18610.10.10.769.171.224.12-> e 498091002
    17:52:022011-10-18610.10.10.769.171.224.12-> e 1778091003
    17:52:182011-10-18610.10.10.769.171.224.12-> e 2158091002
    17:52:342011-10-18610.10.10.769.171.224.12-> e 6808091003
    17:52:502011-10-18610.10.10.769.171.224.12-> e 7238091003
    17:53:062011-10-18610.10.10.769.171.224.12-> e 7678091003

    Packer Results

    Packer Name

    HoneyTrap Results

    Honey Trap Log File Location

    PTFB Results

    PTFB Log File Location