File MD5Sum | SHA1SUM | SHA256SUM | FUZZY HASH | File Size |
---|---|---|---|---|
2ea83963c15a02577f66784e15af47da | c9650c337baf310a39797ecfa0e607220e56d15a | 9e8380608b547a395e563a13207707226596559442df470798c55b5d0293c0c2 | 12288:kz+4KMVzDfrTRYQ3+WltCiHE4vTB3cwhu7CdfCRHHDfVIEO:oFDf/RkWjJvTOeusQjm | 539648 |
File Name |
---|
FHackPublic.exe |
Snort Class | Snort Alert | Count |
---|---|---|
N/A | No snort alerts generated | 0 |
AV Alert | AV Vendor |
---|---|
Trojan.Gen | Symantec |
Generic | McAfee |
Trojan.Win32.Siscos.aos | Kaspersky |
Path | Folder Name |
---|---|
c: | Windupdt |
Path | File Name |
---|---|
c:/WINDOWS/Prefetch | SANDNET.EXE-2012C478.pf |
c:/WINDOWS/Prefetch | WINUPDATE.EXE-26CE0264.pf |
c: | netstat_post.txt |
c: | taskv_post.txt |
c:/Windupdt | WinUpdate.exe |
Action | Path | File Name |
---|
Action | Path |
---|
Action | Path | Val_Name | Val_Data |
---|
Action | Path | Val_Name | Val_Type | Mod_Val_Type | Val_Data | Mod_Val_Data |
---|
Action | Path | Val_Name | Val_Data | Mod_Val_Data |
---|---|---|---|---|
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | 9F F8 AB 52 F2 F5 2F A6 48 A3 56 24 8D 85 94 B8 AA FD 3A E2 84 BA 0E 34 B0 49 51 | 35 0A 35 7B 14 8D D2 E0 36 29 85 25 53 33 24 3E FA EA 0F 6F 3E 51 40 68 5B AB 7 |
modified | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Winlogon | Userinit | C:WINDOWSsystem32userinit.exe, | "C |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformation | ProgramCount | 0x00000002 | 0x00000001 |
DNS | DNS Response |
---|---|
fuckingnubs.no-ip.biz | Standard query response A 66.30.17.158 |
DstIP | HTTP_HOST | HTTP_REQUEST_URI | HTTP_USER_AGENT | PROTOCOL |
---|---|---|---|---|
239.255.255.250 | 239.255.255.250:1900 | * | --blank-- | 0x11 |
PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|
6 | 277 | 272 | 16778 | 16357 |
17 | 1 | 0 | 175 | 0 |
DPORT | PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|---|
2100 | 6 | 277 | 272 | 16778 | 16357 |
1900 | 17 | 1 | 0 | 175 | 0 |
Time | Date | Protocol | SrcIP | DstIP | Dir | Flags | Sport | Dport | Pkts | Bytes |
---|---|---|---|---|---|---|---|---|---|---|
09:15:41 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 42 | 2100 | 12 | 724 |
09:15:46 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 42 | 2100 | 11 | 660 |
09:15:52 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 42 | 2100 | 4 | 240 |
09:15:52 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 412 | 2100 | 13 | 793 |
09:15:58 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 412 | 2100 | 11 | 660 |
09:16:03 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 412 | 2100 | 11 | 660 |
09:16:08 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 514 | 2100 | 12 | 733 |
09:16:13 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 514 | 2100 | 11 | 660 |
09:16:18 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 514 | 2100 | 13 | 780 |
09:16:23 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 452 | 2100 | 13 | 793 |
09:16:29 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 452 | 2100 | 10 | 600 |
09:16:34 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 452 | 2100 | 10 | 600 |
09:16:39 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 452 | 2100 | 4 | 240 |
09:16:40 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 536 | 2100 | 13 | 793 |
09:16:45 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 536 | 2100 | 10 | 600 |
09:16:50 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 536 | 2100 | 14 | 840 |
09:16:56 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 212 | 2100 | 13 | 793 |
09:17:01 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 212 | 2100 | 11 | 660 |
09:17:06 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 212 | 2100 | 13 | 780 |
09:17:12 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 578 | 2100 | 12 | 733 |
09:17:17 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 578 | 2100 | 11 | 660 |
09:17:22 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 578 | 2100 | 13 | 780 |
09:17:27 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 109 | 2100 | 13 | 793 |
09:17:33 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 109 | 2100 | 10 | 600 |
09:17:38 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 109 | 2100 | 14 | 840 |
09:17:43 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 58 | 2100 | 13 | 793 |
09:17:49 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 58 | 2100 | 11 | 660 |
09:17:54 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 58 | 2100 | 13 | 780 |
09:18:00 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 111 | 2100 | 13 | 793 |
09:18:05 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 111 | 2100 | 11 | 660 |
09:18:10 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 111 | 2100 | 13 | 780 |
09:18:16 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 213 | 2100 | 12 | 733 |
09:18:21 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 213 | 2100 | 11 | 660 |
09:18:26 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 213 | 2100 | 13 | 780 |
09:18:32 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 731 | 2100 | 12 | 733 |
09:18:37 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 731 | 2100 | 10 | 600 |
09:18:42 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 731 | 2100 | 14 | 840 |
09:18:48 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 773 | 2100 | 13 | 793 |
09:18:53 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 773 | 2100 | 11 | 660 |
09:18:58 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 773 | 2100 | 13 | 780 |
09:19:04 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 774 | 2100 | 12 | 733 |
09:19:09 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 774 | 2100 | 11 | 660 |
09:19:14 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 774 | 2100 | 13 | 780 |
09:19:19 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 817 | 2100 | 13 | 793 |
09:19:25 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 817 | 2100 | 11 | 660 |
09:19:30 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e | 817 | 2100 | 13 | 780 |
09:19:36 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e d | 818 | 2100 | 8 | 484 |
09:19:43 | 2011-05-16 | 6 | 10.10.10.7 | 66.30.17.158 | -> | e d | 818 | 2100 | 3 | 185 |
09:21:13 | 2011-05-16 | 17 | 10.10.10.7 | 239.255.255.250 | -> | e | 8 | 1900 | 1 | 175 |
Packer Name |
---|
Honey Trap Log File Location |
---|
PTFB Log File Location |
---|