Malware Report - Results

This report shows all the different areas TAZER analyzes for the sample: Host, Network Activity, and Detection.

Malware Search Criteria:
  • MD5 =e497a664d20455ed2261de1da60a2eb7

  • Malware Report - Results

    File MD5SumSHA1SUMSHA256SUMFUZZY HASHFile Size
    e497a664d20455ed2261de1da60a2eb7eb3a4a8a0e8adf74d2763902a940437a33755ffb799841002332fe9766c11853886dbb86500fb8d01d384178f3967ddcccfc14e06144:+8U2qy6rRZb7jxGYKSTJDPM83llq9v+evY56asFmd+Upwt:gzy6rRxE8UOlwvVvY5homd+X278906

    File Results

    File Name
    1289137%5Fx352fsd.640x480.exe

    SNORT Results

    Snort ClassSnort AlertCount
    A Network Trojan was DetectedSPYWARE-PUT Trojan.Win32.Karagany.A contact to server attempt1
    Misc AttackET RBN Known Russian Business Network IP TCP (62)1

    AV Results

    AV AlertAV Vendor
    Suspicious.Cloud.5Symantec
    Artemis!E497A664D204McAfee
    Trojan-Spy.Win32.SpyEyes.htgKaspersky

    Folders (Added) - ICC Results

    PathFolder Name

    Files (Added) - ICC Results

    PathFile Name
    c:/WINDOWS/PrefetchADOBEUTIL.EXE-27EA9B9F.pf
    c:/WINDOWS/PrefetchB2E.EXE-0B089C36.pf
    c:/WINDOWS/PrefetchFILE.EXE-18E9700F.pf
    c:/WINDOWS/PrefetchRUNDLL32.EXE-1D33A546.pf
    c:/WINDOWS/PrefetchSANDNET.EXE-2012C478.pf
    c:/WINDOWS/PrefetchSTART1.EXE-2DDDAD76.pf
    c:/WINDOWS/system32/drivers/etc127014_128820_f_640x480.jpg
    c:/WINDOWS/system32/drivers/etcerr.log145156
    c:/WINDOWS/system32/drivers/etcfile.exe
    c:/WINDOWS/system32/drivers/etch?sts
    c:/WINDOWS/system32/drivers/etcstart1.exe

    Files (Deleted) - ICC Results

    ActionPathFile Name

    Files (Changed) - ICC Results

    ActionPathFile Name
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchHSTART.EXE-221D72BF.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/system32/configsystem.LOG
    modifiedc:/WINDOWS/system32/drivers/etchosts
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP

    Registry Keys (Added) - ICC Results

    ActionPath

    Registry Values (Added) - ICC Results

    ActionPathVal_NameVal_Data

    Registry Values (Deleted) - ICC Results

    ActionPathVal_NameVal_TypeMod_Val_TypeVal_DataMod_Val_Data

    Registry Values (Changed) - ICC Results

    ActionPathVal_NameVal_DataMod_Val_Data
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed0F 51 8B 3E 9B 41 D0 70 C9 E5 23 C2 11 F9 92 CC 21 D8 A7 BF 56 20 D4 91 98 41 1B B0 9C 91 85 25 97 61 9D 9E 93 BA 42 F0 9B 4C 02 72 63 CB 79 7F 25 BA B9 16 43 0
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Explorer/RecentDocsMRUListEx03 00 00 00 02 00 00 00 00 00 00 00 08 00 00 00 07 00 00 00 06 00 00 00 05 00 00 0A 00 00 00 09 00 00 00 03 00 00 00 02 00 00 00 00 00 00 00 08 00 00 00 07 00 0
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Explorer/RecentDocs/FolderMRUListEx01 00 00 00 03 00 00 00 02 00 00 00 00 00 00 00 FF FF FF FF 04 00 00 00 01 00 00 00 03 00 00 00 02 00 00 00 00 00 00 00 FF FF FF FF
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x00000002 0x00000003

    DNS Results

    DNSDNS Response
    adobe.comStandard query response A 192.150.16.117
    data-fold.orgStandard query response A 193.107.16.43

    URL Results

    DstIPHTTP_HOSTHTTP_REQUEST_URIHTTP_USER_AGENTPROTOCOL
    192.150.16.117adobe.com/geo/productid.phpOpera/10.80 Pesto/2.2.300x06
    193.107.16.43data-fold.org/kadabra/xgate.phpOpera/10.60 Presto/2.2.300x06
    239.255.255.250239.255.255.250:1900*--blank--0x11

    ARGUS PROTOCOL Results

    PROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    61089531030
    17203500

    ARGUS DPORT Results

    DPORTPROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    8061089531030
    190017203500

    ARGUS DATA Results

    TimeDateProtocolSrcIPDstIPDirFlagsSportDportPktsBytes
    10:17:262011-05-27610.10.10.7192.150.16.117-> e 422809989
    10:17:272011-05-27610.10.10.7193.107.16.43-> e 311809994
    10:23:002011-05-271710.10.10.7239.255.255.250-> e 819002350

    Packer Results

    Packer Name

    HoneyTrap Results

    Honey Trap Log File Location

    PTFB Results

    PTFB Log File Location