Norwegian Honeynet Project | A chapter of The Honeynet Project
Sandbox Data
Version 1.04 - 2006.09.10

SUBMISSIONS   SIGNATURES   FILE NAMES   BOTNETS   IRC   MALWARE-HOSTS   UNKNOWNS   MUTEXES

List of unknown malware samples

This list contains those malware samples we've collected which were neither detected by the sandbox nor triggered any virus signatures (i.e. NO_MALWARE and NO_VIRUS in the report).

ID Time Registered Filename MD5 Hash value
1209  2006-08-31 windowsupdz.exe dea4a0c5ce9f7af66e55d46469151f71
1200  2006-08-27 NfpG+w== e6de5aa7f2e3cd89285e3b92bcfa0106
1184  2006-08-22 Sw7pyg== f2693311c72bf566c9505baaf975319d
1172  2006-08-21 4Z1gOQ== 13ff667bebcc58253faba2313dce7b89
1174  2006-08-21 w== f2693311c72bf566c9505baaf975319d
1176  2006-08-21 msinexec.exe f43f8616703f77ee09c918b98631f548
1166  2006-08-20 D69aZQ== bf954314196e74134bf6a8b6ca0d030d
1152  2006-08-17 fAFRTg== 4732f66bfbe402d05588b0009c80c662
1146  2006-08-16 H5ngOA== 7760bd29a631e8148d654d504ca16809
1123  2006-08-12 qOp4jA== 7760bd29a631e8148d654d504ca16809
1125  2006-08-12 3IO1gw== e82ea249ba59b9a0c48c7572a078ae92
1127  2006-08-12 pyDLMQ== 6f0ce7e80d83ee1b22b679ec865776b5
1131  2006-08-12 AKQYJg== 274d5eb865ba6330723d59f417b8c0fc
1132  2006-08-12 RWV3FA== ce7ed2140fd77162341cebc0b32361e3
1121  2006-08-12 vB+2Og== dace5e57b29aa6a11ae7cc077296f2f6
1120  2006-08-11 K6B4VQ== f117be7abcab427f799b58760adaf7d7
1092  2006-08-10 newexe.exe 058acd893d9e35ad2372430d2d2b1687
1091  2006-08-10 41463.exe 3fdf1dd08b26c6a1a8d7ebfeb2b3e4a1
1090  2006-08-10 sp1.exe df7ce046a443236cd3021dab70c60df2
1089  2006-08-10 MSPF.EXE 3eb699d6ee3f95c894180c28093ebd20
1085  2006-08-10 rundll.exe 5d38f147e89eee4f85442188128c59b2
1093  2006-08-10 rundll.exe 3c5370bab5e3bc44beb12f94f43ab6ff
1096  2006-08-10 MSPF.EXE 27bdaf88959948f0e656528ead9fc65f
1084  2006-08-10 filez.exe 0c96014a5df629f8756042146f80541f
1118  2006-08-10 hXfSMw== 6f0ce7e80d83ee1b22b679ec865776b5
1117  2006-08-10 ad.exe f865dd91bfbedbfd416044c8953217b6
1115  2006-08-10 l4FpYQ== dace5e57b29aa6a11ae7cc077296f2f6
1106  2006-08-10 sp12.exe 39e951c224439030f9342a648160c3d0
1105  2006-08-10 sp1.exe 25af02bb3f51e65ee3e9f8cb0c7490a3
1077  2006-08-03 freememory.exe 527c300c1985d24323178784326c1b27
1071  2006-06-30 msngrer.exe 03f322365b844d8faf9236aab34b4214
1058  2006-06-29 webmsn.exe b13d762261839fe0cd0c12dca0361c1f
1065  2006-06-29 zt 560b6cf29ad44fc93f0324090cdb0113
1066  2006-06-29 sp1.exe a0810230878724091dba7ef7f1f163e4
1067  2006-06-29 SFaenA== 0c96014a5df629f8756042146f80541f
1070  2006-06-29 bot.exe 138074bd380abc192b2eee2441426585
1030  2006-06-23 AVGcore11234.exe 3601ef828b4bd591e29148c501927929
1008  2006-06-23 msngrer.exe 27eb815f101a9295fbb601986f393d01
1003  2006-06-23 Windows-.exe fe91f878f9b477c14a3c6d734545c52c
993  2006-06-23 hqghumea.dll d465944e71583405b8a4f1b264164381
985  2006-06-23 msngrer.exe 1ab6af646a6f083d59757b54ed8071da
979  2006-06-23 msnserve.pif 849fd3a8b6079c64ed7ecbf76f7c6dad
974  2006-06-23 svchost32.exe 20cbbf5ded37554ab43ae6e58fbed783
973  2006-06-23 l7PfVQ== 740f1794fee074927f689ae3f2d5a413
1015  2006-06-23 bling.exe 4f12dfb4b613abc4ddf56d087223a868
1019  2006-06-23 eraseme_41463.exe ce03a5523e4415b021fb69965e909849
1026  2006-06-23 UpMsnGraond.exe ba6ba5ced4ba7bcda65c7cf1908efdef
1056  2006-06-23 Visu0dll.exe 838158be0c0445f7a4914de204df1e00
1053  2006-06-23 msngrer.exe d543bd52a2922c4a7a4de184ff1c977b
1051  2006-06-23 winmsfw.exe da149d2cc354ea03de5b97b2c0b05e73
1050  2006-06-23 Windows-.exe ed54b437a4afcdcd189c1523e363e1aa
1042  2006-06-23 eraseme_10683.exe 04cb88703c78a3ffa6f678a9a77c66c7
1037  2006-06-23 host.exe 614efe6fb28cd2310f7b63a3c6900b3d
1034  2006-06-23 eraseme_75008.exe bb5621c9dd7b96ceb2e5a435fd330865
1032  2006-06-23 UpMsnGraond.exe 2b6f3d5996c9fadab2483d966ff71287
962  2006-05-31 JetAudio.exe 2ba544727f8745b112db7b1ee518fa67
970  2006-05-31 drives.exe dc66e8ca863f739a2a457f71082bbdf7
950  2006-05-30 3l+ATg== 76e0c3f26fad143ccff84d52846fa82f
944  2006-05-30 hqghumea.dll d465944e71583405b8a4f1b264164381
937  2006-05-29 xrsN+Q== 7f50943ea6af956f3dee90dfc80fa998
930  2006-05-29 AntiSsy.pif 476cd7049e5d448bbbab137a84d62172
927  2006-05-29 basic69.exe a05d79639f35e6db275fbc483d2916a3
918  2006-05-28 IL+SYw== 76e0c3f26fad143ccff84d52846fa82f
903  2006-05-27 Windows-.exe 8babcb27086cf12fcf510427f771de7b
910  2006-05-27 ywD8qQ== 6b9d27a53974ae879a0cfb5dc67f00ae
883  2006-05-23 spread.exe b22d41984a14dff24f037ac8c94c0907
873  2006-05-20 0.exe 79ec75e21162d38f85e525550e30a5ae
871  2006-05-19 Windows-.exe 96837ddfcc76cc352d67c116343d0194
855  2006-05-07 Windows-.exe 1ca5f55ecd887b6b528aabb0e7ee2175
845  2006-04-30 kjsdu_36770.exe 9daf7781aeaac42024c20ba746886d38
830  2006-04-27 newexe.exe 4a20cbc07d70284a151d76b16dae1a5d
829  2006-04-27 wsaugt32.exe 3a863bbb113212194e8a0d9da6cf1773
828  2006-04-26 wsaugt32.exe c373b25eb52965b8f5ff1d6bb9b3e44c
825  2006-04-25 wsaugt32.exe aa9601a7e51d5fcd2bf60e2c82dfd2c9
795  2006-04-13 newexe.exe d76152f168f84f20719902ce8b297278
773  2006-04-09 Samsong.exe e8f874e041860bff5f314abcf358763d
772  2006-04-09 jimbo.exe c2e72cec056183fd5bc5e3ec68b40c37
741  2006-03-28 Reads.exe 596635651813ea67ab7662e0f1673dcd
739  2006-03-26 bling.exe 464e2253377e2666cbf45c6c59625388
736  2006-03-26 keys.exe aa1652cd3aa3da029a105a741bdc2ba2
733  2006-03-25 rp5.exe 4501fe2d24a396326ebdd1006fee3635
730  2006-03-24 rp5.exe 7fbec293d5dc8bcd8302f59484284ea6
727  2006-03-24 newexe.exe 3ba9c56c788484d8be0c7d0a5c372288
725  2006-03-23 asn2.exe eecb8b8303068c7f278d39e39317e529
712  2006-03-22 rp5.exe e271c2c7d213ae658bef9db8dafecbb7
713  2006-03-22 rp5.exe 9c368e4417c11c2ff5af0991dec5d011
715  2006-03-22 asn2.exe d26f7575f97e6a89e97f7dd6e2bde8c9
716  2006-03-22 asn2.exe 265ce1484aced45505f33057eeaf3807
704  2006-03-21 system32.exe 5e8b0d93c279c4556490331d114cc48b
699  2006-03-18 rp5.exe f593ff1ae1ff2194f41bb0df3e3ed227
689  2006-03-17 rp5.exe 6d46a6ccd94cde0129778f6bce9e91aa
692  2006-03-17 rp5.exe cbc757f4597257cd1259e91297604531
685  2006-03-16 rp5.exe 95140f026eeb8b9c49d9151a07c45c29
682  2006-03-15 rp5.exe 9291587b85191b06bbf80d4ea1fb142e
679  2006-03-13 MSPlayerAIT.exe 6d3ac9687109b8f7a6dc2cdfe1d7feb7
667  2006-03-11 rp5.exe 2b3e273b9b37ec6b7732d2e9d9c1608e
662  2006-03-09 Firewall-UpdateV9.exe b122e5aaceebd3b39aa5ee40bc10e709
661  2006-03-09 rp5.exe a05f28f889197f3996ab267412b65dcd
658  2006-03-07 rp5.exe ddc4b5258b906e14c9fad84a7cd56b3d
632  2006-03-02 rp5.exe 26529794abe9529c22ce5b4f3e5165df
630  2006-03-02 rp5.exe e79020ee96e3e287a5b7dd8632e6a50e
619  2006-02-28 rp5.exe 608b393ee184da93e9e57279248ebb78
600  2006-02-26 rp5.exe 60df9b391a1456fe1dda0071aa87147d
602  2006-02-26 winxpstats.exe f80ae30e351e4c3a2e9f8f6df629dfec
603  2006-02-26 rp5.exe 3780075cda61d6fc9487e412dc20d6bf
608  2006-02-26 setup_27108.exe 02d87eb606fc102564901362e2d9675d
598  2006-02-25 rp5.exe 7fe4619881c89f54e7dd4655fcfdd3b8
587  2006-02-25 setup_06138.exe 825d79c3d758de1257ee5d1efb49de27
581  2006-02-23 setup_27108.exe 38de18676fb083801094c05c29c20a04
568  2006-02-18 laordewl.exe 4f9c99977f5bfea89677a5af2fa2341b
571  2006-02-18 update32.exe ae4833fa5c4064980ca03010e241ff5d
572  2006-02-18 winfixup.exe d814c4dda400aac37d1b4814381245a5
562  2006-02-15 plscdff.exe 674a5448809c7144b3e11889e7fd0c16
555  2006-02-12 MNSQ.exe 1a1bcfc683f6bfbec797cfb7c729fbb8
544  2006-02-09 taskmnegr.exe d1c070f309848af1b47a214b65954b1b
543  2006-02-08 tasks.exe 5cdd47f2f82bd3a79e6994fc6ba9dd1a
538  2006-02-06 win32ssr.exe_Download.tmp f4b86cce77eb87a886412884c2e534a7
511  2006-01-29 cvxfVw== 993ff92bc4a7bed3c8e80663ba38fa75
515  2006-01-29 1Q== 206c72207b731683893f4772d6cc470d
518  2006-01-29 wmediav.exe ee018aadc873aa344d8eda7a247e8628
487  2006-01-12 eraseme_51755.exe b1b93a9738cb729f3b581daacf3dcb4d
485  2006-01-11 usbhub.exe d9b963885f8f010f0f6b6a741776c1b6
456  2006-01-05 commdlg32.exe f1ea96e0c2052ef799484c2bf1d9e4a4
452  2006-01-04 FirewallingV10.exe 891bb31138dc886dc8a58fbb63a38975
449  2006-01-03 olecli32.exe 5271bbe9578df0626e82cc9b22d7c3b4
443  2006-01-02 MNSQ.exe 9feb7fff6ad3ab4c19f793e86d5282bc
441  2006-01-02 spoolss.exe 29a5d860960988e3d1ea203e1a7c9dda
439  2006-01-01 xkjmxtu.exe c3ae74b413c0a680ec21463393043049
428  2005-12-30 eraseme_02403.exe 7eac026af1b7f20f52765af44e0926d8
429  2005-12-30 sysmsn.exe b3c4cf0c527596bfc5d37e4dd7c20a99
419  2005-12-27 autowxckn.exe e51d1365d9af2e368ecd88b2a2ac66b7
415  2005-12-27 sysmsn.exe 5f6c8c40c21588eb4b90521d9b5658a0
394  2005-12-22 schost.exe 93afb299aa9a9e8fc6438b874eb8af23
392  2005-12-22 tskmgr.exe 4d1c966da340f62c9eecdba6c1582a0c
389  2005-12-22 wmedia.exe dc3839955b70c30aef19c441cb9c65e1
381  2005-12-20 wmloader.exe 7076878aa1ec20f4df5035b5a51e3431
379  2005-12-20 IEEXPLORER.exe 04b754121c326e898f373cf41fb9850c
370  2005-12-16 tskmgr.exe d41fb48565be2a4edf092ea59fbfd92a
372  2005-12-16 tskmgr.exe 336bb19a8fd908cb64ccbc7a16279d64
364  2005-12-15 Fbhm3g== 1d12c4912f384d2ea1a74892233c82c9
358  2005-12-12 iwinlogon.exe c1aa1ea3127a127ecaf7084c25f2f44b
75  2005-12-10 schedsvc32.exe 23d172a1e46678e6156c479c68af32d7
73  2005-12-10 svc32.pif ef42ede99d5ac95c973b40d449c41864
72  2005-12-10 windvr.exe ff216a4361061e2f652a43dfe40a7c40
70  2005-12-10 msnger.exe 0b7006ad3280c00365a96abf50fb8dc7
64  2005-12-10 mswind32.pif 1a93ad10e57c8e87d4581a695f19c3f0
52  2005-12-10 sTHJFQ== d77d9e54ca4d444e65d6cb5eb22f8d3e
76  2005-12-10 svc32.pif d97ef87d5f9a120c52fec8de919bb157
79  2005-12-10 svc32.pif 239d7ff5ef9193800f617d110771d132
80  2005-12-10 explorer.pif ffced795cb0b414acb3ed29861e4173c
81  2005-12-10 svch32.pif 91ef59383e7ed58bf27cf54950129524
82  2005-12-10 svch32.pif 2774a6c2dc67a777eec34b728e802cb2
83  2005-12-10 svch32.pif 8a53c1043cc4dd4d21831f7ff00389a0
86  2005-12-10 svch32.pif 4b72c37a30fda4db4281b0e45aafc595
90  2005-12-10 Vo4xmQ== 247253771b1d1ddeb3fe3f012cafa43e
50  2005-12-10 mswi32.pif 5b109033b8d7b6733e559a4895aa530e
49  2005-12-10 mswi32.pif 8cbb4dd2b78ba87e3e82b8f998659ae1
11  2005-12-10 ming.pif 44a09a21c32d5c029e222427b37e4e2b
15  2005-12-10 javams32.exe a2927dead584d5f8f8f646ae3a771930
16  2005-12-10 javams32.exe 9576beeb454cd578b964a9e4ed6d3a37
19  2005-12-10 ms32.pif b4181c1e60c790f73bbdac9ea0ddfced
20  2005-12-10 WINDOWS32.exe d0690778418e17ab0366ea731a9fbdc9
21  2005-12-10 WINDOWS32.exe aa32689b6d15a9d9b18d5d2733910e95
27  2005-12-10 12345.exe cd1505b2480c9de1148cc56248e214b9
32  2005-12-10 msw32.pif 0cdd4bf8d1b2d24a98d47d0a1b5cf399
33  2005-12-10 ming.pif aed89d43463033d1326dc8275f190cd9
38  2005-12-10 msserv.exe ebc33665569b83938cdbca901c4c5fcd
39  2005-12-10 msw32.pif 6f0277530a0e90553d6165acd519c2f4
45  2005-12-10 up32.pif 104c2cb582d7a4d362e1fdf4155842f4
47  2005-12-10 msw32.pif e9c53e4ec1a437063a58cce0a832dd6b
1  2005-12-10 yQdirQ== 088e22bc5ba031c91cb31a701890eda0
91  2005-12-10 hhs.pif 7b091004b1335900e3590448e41a443b
92  2005-12-10 soff.pif 84d91031dd810d1b7758470d09d12b05
128  2005-12-10 BHSV.EXE f29502e17e09cd421a5cbec53ae77b0b
132  2005-12-10 bload.exe 15146fe04d7de3464e01833fda326d51
159  2005-12-10 myhost2.exe c8555d8d28aee72d5adc0f4f8910b023
183  2005-12-10 eraseme_13481.exe 9acc62e84eed085ac0e4e10a2649fd13
196  2005-12-10 eraseme_60774.exe 868c21ecfed08ee8900c548f3c6f9e53
211  2005-12-10 asn2.exe 30ba4e7e3119112c86f323fb67684e3a
216  2005-12-10 YOgnow== e732d885a68a46fe68d9c3408689d53a
226  2005-12-10 3HAr4w== d671a3bfc2bedeefd4329dc9038de6b6
227  2005-12-10 eraseme_27108.exe f2b13878b6da4a10d74aa3b4ffeddc6b
265  2005-12-10 updt.pif 3c3b7017d69e59e2460991efba5a8f77
266  2005-12-10 wuamkop.exe ce25f4f182ccdbef90dd38d2bb127498
298  2005-12-10 UxRqqw== ad9472f2d770e6fc70c197c7cf010575
303  2005-12-10 eraseme_27108.exe 72d26eda8973d100e62dd44ce0e9e118
126  2005-12-10 BHSV.EXE a60fda05491589a89dc108d6cf2b5b12
125  2005-12-10 syscvhost.exe eee9d2975d5b8160de475d13df30d9d8
98  2005-12-10 hhs.pif e30ee435f7fee5c87f5598013d16530d
99  2005-12-10 dload.exe 5c6cffb4af116f7242e7c5892d3604cf
100  2005-12-10 hhs32.pif e10df7ef4c8dd4228bc649de63c06b83
101  2005-12-10 hhs32.pif e9549c07c1f4b868818aaa39864be7c9
104  2005-12-10 hhs32.pif 5c0074d0998f21631012b8f159bfc949
106  2005-12-10 IHSVC.EXE 41d2fb10214351c78b8c50f5a7dfde52
108  2005-12-10 IHSVC.EXE d6db301a4ae12a00a6d3807afee4d482
113  2005-12-10 eraseme_27108.exe ef0d1515e3db544bec7b12cd5f7ad936
117  2005-12-10 lsd 393f45ca33a94d144505a864d037679a
119  2005-12-10 IHSVC.EXE 9fa3edbecdd287c7e116a08d264ff718
121  2005-12-10 msnger.exe 4c8efd47a150b766b4d080e23ec9604e
122  2005-12-10 eraseme_27108.exe 8f330780d90f0b07dc36edab240c5378
123  2005-12-10 bload.exe 867f90f9defd841038a91cd200bb48dd
332  2005-12-10 rundll32.exe 52316e44fc82dfa373e01011b9dc938f