File MD5Sum | SHA1SUM | SHA256SUM | FUZZY HASH | File Size |
---|---|---|---|---|
2345df605a8c207357b9d33953877311 | 2c9e6116034f11785985ee57e5d5c318120a9436 | 5396fb95676be4e9cb1bcb0af7ce80b92d32e3868c7eec1ff95120f1d8c50540 | 768:K/va/1ntRseeYaM+0yqzA6n/TOVjUnw05QzB/23nbcuyD7U:Z/BtCH1qvn/TONUv6/Mnouy8 | 40960 |
File Name |
---|
kp.gif.exe |
index.html%3Fgetexe%3Dloader.exe |
Snort Class | Snort Alert | Count |
---|---|---|
Misc Attack | ET RBN Known Russian Business Network IP TCP (5) | 4 |
AV Alert | AV Vendor |
---|
Path | Folder Name |
---|
Action | Path | File Name |
---|
Action | Path |
---|
Action | Path | Val_Name | Val_Data |
---|
Action | Path | Val_Name | Val_Type | Mod_Val_Type | Val_Data | Mod_Val_Data |
---|
Action | Path | Val_Name | Val_Data | Mod_Val_Data |
---|---|---|---|---|
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | 93 6E 8D AC D7 D2 3E C7 00 D2 4C B0 2F 6F 36 98 ED 2A 5B 94 2D FA B7 C0 04 55 8C | 9C 7A FB A9 BA D6 D7 2F 12 95 92 E5 C2 B2 74 D2 CA 48 FA CB 03 9B 7A 88 97 1C E |
modified | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/ProfileList/S-1-5-19 | RefCount | 0x00000002 | 0x00000001 |
modified | HKLM/SYSTEM/ControlSet001/Services/SharedAccess | Start | 0x00000002 | 0x00000004 |
modified | HKLM/SYSTEM/ControlSet001/Services/SharedAccess/Epoch | Epoch | 0x00000104 | 0x00000105 |
modified | HKLM/SYSTEM/ControlSet001/Services/wscsvc | Start | 0x00000002 | 0x00000004 |
modified | HKLM/SYSTEM/CurrentControlSet/Services/SharedAccess | Start | 0x00000002 | 0x00000004 |
modified | HKLM/SYSTEM/CurrentControlSet/Services/SharedAccess/Epoch | Epoch | 0x00000104 | 0x00000105 |
modified | HKLM/SYSTEM/CurrentControlSet/Services/wscsvc | Start | 0x00000002 | 0x00000004 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Connections | SavedLegacySettings | 3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 | 3C 00 00 00 17 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformation | ProgramCount | 0x00000002 | 0x00000001 |
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | 38 AE C7 FA AF B3 12 C1 4F 67 DC 2A B2 03 31 56 D8 AC 53 04 94 AB 5E 08 E5 51 A2 | F8 76 07 3C C3 53 01 11 CD 58 62 AA 54 6D A5 20 C4 89 EB F7 DC 73 4C 59 8A F7 6 |
modified | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/ProfileList/S-1-5-19 | RefCount | 0x00000002 | 0x00000001 |
modified | HKLM/SYSTEM/ControlSet001/Services/SharedAccess | Start | 0x00000002 | 0x00000004 |
modified | HKLM/SYSTEM/ControlSet001/Services/SharedAccess/Epoch | Epoch | 0x00000104 | 0x00000105 |
modified | HKLM/SYSTEM/ControlSet001/Services/wscsvc | Start | 0x00000002 | 0x00000004 |
modified | HKLM/SYSTEM/CurrentControlSet/Services/SharedAccess | Start | 0x00000002 | 0x00000004 |
modified | HKLM/SYSTEM/CurrentControlSet/Services/SharedAccess/Epoch | Epoch | 0x00000104 | 0x00000105 |
modified | HKLM/SYSTEM/CurrentControlSet/Services/wscsvc | Start | 0x00000002 | 0x00000004 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Connections | SavedLegacySettings | 3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 | 3C 00 00 00 17 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformation | ProgramCount | 0x00000002 | 0x00000001 |
DNS | DNS Response |
---|---|
exe.perfectexe.com | Standard query response A 122.224.6.48 |
DstIP | HTTP_HOST | HTTP_REQUEST_URI | HTTP_USER_AGENT | PROTOCOL |
---|---|---|---|---|
239.255.255.250 | 239.255.255.250:1900 | * | --blank-- | 0x11 |
PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|
6 | 60 | 56 | 4863 | 3368 |
17 | 2 | 0 | 350 | 0 |
DPORT | PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|---|
255 | 6 | 60 | 56 | 4863 | 3368 |
1900 | 17 | 2 | 0 | 350 | 0 |
Time | Date | Protocol | SrcIP | DstIP | Dir | Flags | Sport | Dport | Pkts | Bytes |
---|---|---|---|---|---|---|---|---|---|---|
17:13:19 | 2010-08-27 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 11 | 255 | 13 | 1097 |
17:13:24 | 2010-08-27 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 11 | 255 | 10 | 600 |
17:13:29 | 2010-08-27 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 11 | 255 | 6 | 360 |
17:14:36 | 2010-08-27 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 83 | 255 | 13 | 1100 |
17:14:41 | 2010-08-27 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 83 | 255 | 11 | 660 |
17:14:46 | 2010-08-27 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 83 | 255 | 5 | 300 |
17:15:50 | 2010-08-27 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 609 | 255 | 13 | 1097 |
17:15:55 | 2010-08-27 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 609 | 255 | 10 | 600 |
17:16:00 | 2010-08-27 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 609 | 255 | 6 | 360 |
17:17:03 | 2010-08-27 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 112 | 255 | 13 | 1097 |
17:17:08 | 2010-08-27 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 112 | 255 | 11 | 660 |
17:17:13 | 2010-08-27 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 112 | 255 | 5 | 300 |
17:18:46 | 2010-08-27 | 17 | 10.10.10.7 | 239.255.255.250 | -> | e | 8 | 1900 | 2 | 350 |
12:13:57 | 2010-09-02 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 412 | 255 | 13 | 1097 |
12:14:02 | 2010-09-02 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 412 | 255 | 10 | 600 |
12:14:07 | 2010-09-02 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 412 | 255 | 6 | 360 |
12:15:13 | 2010-09-02 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 533 | 255 | 13 | 1097 |
12:15:18 | 2010-09-02 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 533 | 255 | 10 | 600 |
12:15:23 | 2010-09-02 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 533 | 255 | 6 | 360 |
12:16:27 | 2010-09-02 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 462 | 255 | 14 | 1157 |
12:16:32 | 2010-09-02 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 462 | 255 | 10 | 600 |
12:16:37 | 2010-09-02 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 462 | 255 | 5 | 300 |
12:17:42 | 2010-09-02 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e d | 753 | 255 | 13 | 1097 |
12:17:47 | 2010-09-02 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e | 753 | 255 | 13 | 780 |
12:17:52 | 2010-09-02 | 6 | 10.10.10.7 | 122.224.6.48 | -> | e d | 753 | 255 | 7 | 420 |
12:20:07 | 2010-09-02 | 17 | 10.10.10.7 | 239.255.255.250 | -> | e | 8 | 1900 | 2 | 350 |
Packer Name |
---|
Honey Trap Log File Location |
---|
PTFB Log File Location |
---|