Malware Report - Results

This report shows all the different areas TAZER analyzes for the sample: Host, Network Activity, and Detection.

Malware Search Criteria:
  • MD5 =ce48c3c03aa847ca3028436600d37415

  • Malware Report - Results

    File MD5SumSHA1SUMSHA256SUMFUZZY HASHFile Size
    ce48c3c03aa847ca3028436600d3741550236d6e8a3f82e96c34f6eab35753b8276536e80e5c0381d38c412e64cd4c75d42f8f8df91b4255da6264439949ba2d595a83df768:bVS7w7A0Kn1Jz1F1IpX4aa4vdh65tbmbzM1bgZvi63xnbcuyD7U:E7w7jX4aZvdhitiXMJg9i63x41472

    File Results

    File Name
    dgh4.txt.exe

    SNORT Results

    Snort ClassSnort AlertCount
    Misc AttackET RBN Known Russian Business Network IP TCP (25)4
    Misc AttackET DROP Spamhaus DROP Listed Traffic Inbound1

    AV Results

    AV AlertAV Vendor
    Backdoor.TrojanSymantec
    GenericMcAfee
    Backdoor.Win32.VB.lvnKaspersky
    N/ASymantec
    N/AMcAfee
    Trojan-Ransom.Win32.XBlocker.aokKaspersky

    Folders (Added) - ICC Results

    PathFolder Name

    Files (Added) - ICC Results

    PathFile Name
    c:/Documents and Settings/dmc73144/Local Settings/Temp64cucen.exe
    c:/Documents and Settings/dmc73144/Local Settings/Tempa2ga3dk8.bat
    c:/Documents and Settings/dmc73144/Local Settings/Temp~DF8C0E.tmp
    c:/WINDOWS/Prefetch64CUCEN.EXE-24E04B4D.pf
    c:/WINDOWS/PrefetchNET.EXE-01A53C2F.pf
    c:/WINDOWS/PrefetchNET1.EXE-029B9DB4.pf
    c:/WINDOWS/PrefetchSANDNET.EXE-2012C478.pf
    c:/WINDOWS/PrefetchSC.EXE-012262AF.pf
    c:/WINDOWS/system32ljwsah6.log
    c:netstat_post.txt
    c:tasksvc_post.txt
    c:taskv_post.txt

    Files (Deleted) - ICC Results

    ActionPathFile Name

    Files (Changed) - ICC Results

    ActionPathFile Name
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/Documents and Settings/LocalServicentuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchHSTART.EXE-221D72BF.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/system32/configsoftware.LOG
    modifiedc:/WINDOWS/system32/configsystem.LOG
    modifiedc:/WINDOWS/system32/drivers/etchosts
    modifiedc:/WINDOWS/system32/wbem/Logswbemess.log
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log

    Registry Keys (Added) - ICC Results

    ActionPath

    Registry Values (Added) - ICC Results

    ActionPathVal_NameVal_Data

    Registry Values (Deleted) - ICC Results

    ActionPathVal_NameVal_TypeMod_Val_TypeVal_DataMod_Val_Data

    Registry Values (Changed) - ICC Results

    ActionPathVal_NameVal_DataMod_Val_Data
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed7C 02 F0 97 68 E7 07 C1 12 BC 81 79 A4 89 1B 81 9E 58 B5 78 69 C8 AA 79 6C 20 A9 56 05 17 7B 78 16 B9 DD CE EE B9 47 07 F7 DA 4B B1 9B 96 56 F0 93 1A FA 2C B7 2
    modifiedHKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/ProfileList/S-1-5-19RefCount0x00000002 0x00000001
    modifiedHKLM/SYSTEM/ControlSet001/Services/SharedAccessStart0x00000002 0x00000004
    modifiedHKLM/SYSTEM/ControlSet001/Services/SharedAccess/EpochEpoch0x00000104 0x00000105
    modifiedHKLM/SYSTEM/ControlSet001/Services/wscsvcStart0x00000002 0x00000004
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/SharedAccessStart0x00000002 0x00000004
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/SharedAccess/EpochEpoch0x00000104 0x00000105
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/wscsvcStart0x00000002 0x00000004
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 18 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x00000002 0x00000001

    DNS Results

    DNSDNS Response
    mskla.comStandard query response A 193.105.207.31

    URL Results

    DstIPHTTP_HOSTHTTP_REQUEST_URIHTTP_USER_AGENTPROTOCOL
    193.105.207.31mskla.com/list.php?c=637B5483A711A8046A8DC5EDFCB9EF3E029BF6CDC0F2E24AAAE8BAED862E99B6AD937C61215668069BE2DD47BAFFA98BF9039E691F66BCED384CC16A&v=2&t=0.3598139Mozilla/4.0 (compatible; MSIE 6.0.2900.2180; Windows NT 5.1.2600)0x06
    193.105.207.31mskla.com/list.php?c=6B73568175C365C9E106F4DCD491DA0B039A4B70DDEFD870094B7E29B9112A059EA05B4687F0C7A9F18829B30C49B09209F3A156A6DF1C4D582C3A91&v=2&t=0.8878443Mozilla/4.0 (compatible; MSIE 6.0.2900.2180; Windows NT 5.1.2600)0x06
    193.105.207.31mskla.com/list.php?c=9189DE09E650F4588D6AE9C10B4EF42578E19FA4C3F17FD70446BDEA68C0D2FD81BF1F02F88F4729F68F8218C5803517708A8F786E1711409AEE15BE&v=2&t=0.6916315Mozilla/4.0 (compatible; MSIE 6.0.2900.2180; Windows NT 5.1.2600)0x06
    193.105.207.31mskla.com/list.php?c=F7EF23F4D6608824C4230A227D38C716AD349BA020121BB33D7F8ADDB71F6A45506E918C2057EE80C8B15CC66E2B391B817BA35484FD772686F2953E&v=2&t=0.314068Mozilla/4.0 (compatible; MSIE 6.0.2900.2180; Windows NT 5.1.2600)0x06
    239.255.255.250239.255.255.250:1900*--blank--0x11

    ARGUS PROTOCOL Results

    PROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    6201624232060
    17203500

    ARGUS DPORT Results

    DPORTPROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    806201624232060
    190017203500

    ARGUS DATA Results

    TimeDateProtocolSrcIPDstIPDirFlagsSportDportPktsBytes
    05:04:062010-07-07610.10.10.7193.105.207.31-> e 1228091121
    05:05:092010-07-07610.10.10.7193.105.207.31-> e 4108091121
    05:06:182010-07-07610.10.10.7193.105.207.31-> e 918091121
    05:07:222010-07-07610.10.10.7193.105.207.31-> e 6168091120
    05:09:292010-07-071710.10.10.7239.255.255.250-> e 819002350

    Packer Results

    Packer Name

    HoneyTrap Results

    Honey Trap Log File Location

    PTFB Results

    PTFB Log File Location