Malware Report - Results

This report shows all the different areas TAZER analyzes for the sample: Host, Network Activity, and Detection.

Malware Search Criteria:
  • MD5 =51642679ae9ca2cd69c7caa68c0b5925

  • Malware Report - Results

    File MD5SumSHA1SUMSHA256SUMFUZZY HASHFile Size
    51642679ae9ca2cd69c7caa68c0b5925c2cb1a7e9b65d02746944d7ade9dd1f9ea2b81a088311791731faab0883454d3c86b06eea8ebdae40e8c872d80f3a068e8386471768:HcKTtqOYEym8L5iR4iZtyUyJmJvbcYRaD1ciq8W7Kg4ZdQiX+1enN+dX0fMnM:HcKZHYEn8ds4yk44497

    File Results

    File Name
    js.js.exe

    SNORT Results

    Snort ClassSnort AlertCount
    A Network Trojan was detectedET TROJAN Generic Trojan Checkin (2)1
    Misc AttackET RBN Known Russian Business Network IP TCP (74)1

    AV Results

    AV AlertAV Vendor
    Trojan.DropperSymantec
    GenericMcAfee
    Trojan-Downloader.Win32.Geral.sscKaspersky

    Folders (Added) - ICC Results

    PathFolder Name
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Program FilesRAV
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5ITB2CJ0C
    c:/Program FilesRAV

    Files (Added) - ICC Results

    PathFile Name
    c:/DELL/VIDEO/OUTPUTnetstat_base.txt
    c:/DELL/VIDEO/OUTPUTnetstat_post.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_base.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_post.txt
    c:/DELL/VIDEO/OUTPUTtaskv_base.txt
    c:/DELL/VIDEO/OUTPUTtaskv_post.txt
    c:/Documents and Settings/dmc73144/Local Settings/Tempcc190750.exe
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0CCount[1].htm
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:/WINDOWS/infoem0.inf
    c:/WINDOWS/infoem0.PNF
    c:/WINDOWS/Prefetch7Z.EXE-1A62CD19.pf
    c:/WINDOWS/PrefetchCC190750.EXE-0C6519FF.pf
    c:/WINDOWS/PrefetchNET.EXE-01A53C2F.pf
    c:/WINDOWS/PrefetchNET1.EXE-029B9DB4.pf
    c:/WINDOWS/PrefetchREG.EXE-0D2A95F7.pf
    c:/WINDOWS/PrefetchRUNONCE.EXE-2803F297.pf
    c:/WINDOWS/PrefetchSANDNET.EXE-2012C478.pf
    c:/WINDOWS/PrefetchSC.EXE-012262AF.pf
    c:/WINDOWS/system32/driversCCTest.sys
    c:/WINDOWS/system32jsseting.data
    c:/WINDOWS/system32kav.exe
    c:/DELL/VIDEO/OUTPUTnetstat_base.txt
    c:/DELL/VIDEO/OUTPUTnetstat_post.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_base.txt
    c:/DELL/VIDEO/OUTPUTtasksvc_post.txt
    c:/DELL/VIDEO/OUTPUTtaskv_base.txt
    c:/DELL/VIDEO/OUTPUTtaskv_post.txt
    c:/Documents and Settings/dmc73144/Local Settings/Tempcc170171.exe
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0CCount[1].htm
    c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5/ITB2CJ0Cdesktop.ini
    c:/WINDOWS/infoem0.inf
    c:/WINDOWS/infoem0.PNF
    c:/WINDOWS/Prefetch7Z.EXE-1A62CD19.pf
    c:/WINDOWS/PrefetchCC170171.EXE-02F34BBE.pf
    c:/WINDOWS/PrefetchREG.EXE-0D2A95F7.pf
    c:/WINDOWS/PrefetchRUNONCE.EXE-2803F297.pf
    c:/WINDOWS/PrefetchSANDNET.EXE-2012C478.pf
    c:/WINDOWS/PrefetchSC.EXE-012262AF.pf
    c:/WINDOWS/system32/driversCCTest.sys
    c:/WINDOWS/system32jsseting.data
    c:/WINDOWS/system32kav.exe

    Files (Deleted) - ICC Results

    ActionPathFile Name

    Files (Changed) - ICC Results

    ActionPathFile Name
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchHSTART.EXE-221D72BF.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWS/PrefetchWMIPRVSE.EXE-28F301A9.pf
    modifiedc:/WINDOWSsetupapi.log
    modifiedc:/WINDOWS/system32/CatRoot/{F750E6C3-38EE-11D1-85E5-00C04FC295EE}TimeStamp
    modifiedc:/WINDOWS/system32/CatRoot2edb.chk
    modifiedc:/WINDOWS/system32/CatRoot2edb.log
    modifiedc:/WINDOWS/system32/CatRoot2tmp.edb
    modifiedc:/WINDOWS/system32/CatRoot2/{F750E6C3-38EE-11D1-85E5-00C04FC295EE}catdb
    modifiedc:/WINDOWS/system32/CatRoot2/{F750E6C3-38EE-11D1-85E5-00C04FC295EE}TimeStamp
    modifiedc:/WINDOWS/system32/configsoftware
    modifiedc:/WINDOWS/system32/configsoftware.LOG
    modifiedc:/WINDOWS/system32/configSysEvent.Evt
    modifiedc:/WINDOWS/system32/configsystem.LOG
    modifiedc:/WINDOWS/system32/drivers/etchosts
    modifiedc:/WINDOWS/system32/wbem/Logswbemess.log
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING1.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP
    modifiedc:/Documents and Settings/dmc73144/Cookiesindex.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/History/History.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5index.dat
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchHSTART.EXE-221D72BF.pf
    modifiedc:/WINDOWS/PrefetchNETSTAT.EXE-2B2B4428.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchTASKLIST.EXE-10D94B23.pf
    modifiedc:/WINDOWSsetupapi.log
    modifiedc:/WINDOWS/system32/CatRoot/{F750E6C3-38EE-11D1-85E5-00C04FC295EE}TimeStamp
    modifiedc:/WINDOWS/system32/CatRoot2edb.chk
    modifiedc:/WINDOWS/system32/CatRoot2edb.log
    modifiedc:/WINDOWS/system32/CatRoot2tmp.edb
    modifiedc:/WINDOWS/system32/CatRoot2/{F750E6C3-38EE-11D1-85E5-00C04FC295EE}catdb
    modifiedc:/WINDOWS/system32/CatRoot2/{F750E6C3-38EE-11D1-85E5-00C04FC295EE}TimeStamp
    modifiedc:/WINDOWS/system32/configsoftware
    modifiedc:/WINDOWS/system32/configsoftware.LOG
    modifiedc:/WINDOWS/system32/configsystem.LOG
    modifiedc:/WINDOWS/system32/drivers/etchosts
    modifiedc:/WINDOWS/system32/wbem/Logswbemess.log
    modifiedc:/WINDOWS/system32/wbem/Logswmiprov.log
    modifiedc:/WINDOWS/system32/wbem/Repository/FSINDEX.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING.VER
    modifiedc:/WINDOWS/system32/wbem/Repository/FSMAPPING2.MAP
    modifiedc:/WINDOWS/system32/wbem/Repository/FSOBJECTS.MAP

    Registry Keys (Added) - ICC Results

    ActionPath

    Registry Values (Added) - ICC Results

    ActionPathVal_NameVal_Data

    Registry Values (Deleted) - ICC Results

    ActionPathVal_NameVal_TypeMod_Val_TypeVal_DataMod_Val_Data

    Registry Values (Changed) - ICC Results

    ActionPathVal_NameVal_DataMod_Val_Data
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed70 F8 8F 7D 54 60 FA 93 FC 31 AE 63 F3 21 B2 5B 29 75 F2 D6 B8 9A CE E6 AE D9 3B 58 E5 9E 92 CD 81 86 60 52 A8 A0 DF E7 30 9B 92 BD 5D 80 ED 1D CB 0E 76 13 6B 3
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecFilter{72385235-70fa-11d1-864c-14a300000000}description"Matches all ICMP packets between this computer and any other computer." "??????????????????? ICMP ??"
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecFilter{72385235-70fa-11d1-864c-14a300000000}ipsecName"All ICMP Traffic" "?? ICMP ???"
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecFilter{72385235-70fa-11d1-864c-14a300000000}ipsecDataB5 20 DC 80 C8 2E D1 11 A8 9E 00 A0 24 8D 30 21 52 00 00 00 01 00 00 00 02 00 00 B5 20 DC 80 C8 2E D1 11 A8 9E 00 A0 24 8D 30 21 52 00 00 00 01 00 00 00 02 00 0
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecFilter{72385235-70fa-11d1-864c-14a300000000}whenChanged0x4A436155 0x46EE3DCE
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecFilter{7238523a-70fa-11d1-864c-14a300000000}description"Matches all IP packets from this computer to any other computer, except broadca "??????????????????? ICMP ?,????????Kerberos?RSVP ? ISAKMP (IKE)?"
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecFilter{7238523a-70fa-11d1-864c-14a300000000}ipsecName"All IP Traffic" "?? IP ???"
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecFilter{7238523a-70fa-11d1-864c-14a300000000}ipsecDataB5 20 DC 80 C8 2E D1 11 A8 9E 00 A0 24 8D 30 21 4A 00 00 00 01 00 00 00 02 00 00 B5 20 DC 80 C8 2E D1 11 A8 9E 00 A0 24 8D 30 21 4A 00 00 00 01 00 00 00 02 00 0
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecFilter{7238523a-70fa-11d1-864c-14a300000000}whenChanged0x4A436155 0x46EE3DCE
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecISAKMPPolicy{72385234-70fa-11d1-864c-14a300000000}whenChanged0x4A436156 0x46EE3DCE
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecNegotiationPolicy{72385233-70fa-11d1-864c-14a300000000}description"Accepts unsecured communication, but requests clients to establish trust and se "????????,?????????????????????????????????????????"
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecNegotiationPolicy{72385233-70fa-11d1-864c-14a300000000}ipsecName"Request Security (Optional)" "???? (??)"
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecNegotiationPolicy{72385233-70fa-11d1-864c-14a300000000}whenChanged0x4A436155 0x46EE3DCE
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecNegotiationPolicy{7238523b-70fa-11d1-864c-14a300000000}description"Permit unsecured IP packets to pass through." "?????? IP ????"
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecNegotiationPolicy{7238523b-70fa-11d1-864c-14a300000000}ipsecName"Permit" "??"
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecNegotiationPolicy{7238523b-70fa-11d1-864c-14a300000000}whenChanged0x4A436155 0x46EE3DCE
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecNegotiationPolicy{7238523f-70fa-11d1-864c-14a300000000}description"Accepts unsecured communication, but always requires clients to establish trust "????????,?????????????????????????????????"
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecNegotiationPolicy{7238523f-70fa-11d1-864c-14a300000000}ipsecName"Require Security" "????"
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecNegotiationPolicy{7238523f-70fa-11d1-864c-14a300000000}whenChanged0x4A436155 0x46EE3DCE
    modifiedHKLM/SYSTEM/ControlSet001/Control/GroupOrderListExtended Base04 00 00 00 01 00 00 00 02 00 00 00 04 00 00 00 03 00 00 00 05 00 00 00 01 00 00 00 02 00 00 00 04 00 00 00 03 00 00 00 05 00 00 00
    modifiedHKLM/SYSTEM/CurrentControlSet/Control/GroupOrderListExtended Base04 00 00 00 01 00 00 00 02 00 00 00 04 00 00 00 03 00 00 00 05 00 00 00 01 00 00 00 02 00 00 00 04 00 00 00 03 00 00 00 05 00 00 00
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformationProgramCount0x00000002 0x00000001
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed23 C7 F8 6E 78 92 C5 71 55 E9 A8 80 59 2E CB 95 BE 7A 0B BF 2C 40 F4 19 11 D5 6B A3 BA F8 D7 6F 25 6E 8A E5 B1 5F 5A 06 06 20 3C 40 55 86 A7 5A A9 90 96 D9 16 4
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecFilter{72385235-70fa-11d1-864c-14a300000000}description"Matches all ICMP packets between this computer and any other computer." "??????????????????? ICMP ??"
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecFilter{72385235-70fa-11d1-864c-14a300000000}ipsecName"All ICMP Traffic" "?? ICMP ???"
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecFilter{72385235-70fa-11d1-864c-14a300000000}ipsecDataB5 20 DC 80 C8 2E D1 11 A8 9E 00 A0 24 8D 30 21 52 00 00 00 01 00 00 00 02 00 00 B5 20 DC 80 C8 2E D1 11 A8 9E 00 A0 24 8D 30 21 52 00 00 00 01 00 00 00 02 00 0
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecFilter{72385235-70fa-11d1-864c-14a300000000}whenChanged0x4A436155 0x46EE3DCE
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecFilter{7238523a-70fa-11d1-864c-14a300000000}description"Matches all IP packets from this computer to any other computer, except broadca "??????????????????? ICMP ?,????????Kerberos?RSVP ? ISAKMP (IKE)?"
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecFilter{7238523a-70fa-11d1-864c-14a300000000}ipsecName"All IP Traffic" "?? IP ???"
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecFilter{7238523a-70fa-11d1-864c-14a300000000}ipsecDataB5 20 DC 80 C8 2E D1 11 A8 9E 00 A0 24 8D 30 21 4A 00 00 00 01 00 00 00 02 00 00 B5 20 DC 80 C8 2E D1 11 A8 9E 00 A0 24 8D 30 21 4A 00 00 00 01 00 00 00 02 00 0
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecFilter{7238523a-70fa-11d1-864c-14a300000000}whenChanged0x4A436155 0x46EE3DCE
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecISAKMPPolicy{72385234-70fa-11d1-864c-14a300000000}whenChanged0x4A436156 0x46EE3DCE
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecNegotiationPolicy{72385233-70fa-11d1-864c-14a300000000}description"Accepts unsecured communication, but requests clients to establish trust and se "????????,?????????????????????????????????????????"
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecNegotiationPolicy{72385233-70fa-11d1-864c-14a300000000}ipsecName"Request Security (Optional)" "???? (??)"
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecNegotiationPolicy{72385233-70fa-11d1-864c-14a300000000}whenChanged0x4A436155 0x46EE3DCE
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecNegotiationPolicy{7238523b-70fa-11d1-864c-14a300000000}description"Permit unsecured IP packets to pass through." "?????? IP ????"
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecNegotiationPolicy{7238523b-70fa-11d1-864c-14a300000000}ipsecName"Permit" "??"
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecNegotiationPolicy{7238523b-70fa-11d1-864c-14a300000000}whenChanged0x4A436155 0x46EE3DCE
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecNegotiationPolicy{7238523f-70fa-11d1-864c-14a300000000}description"Accepts unsecured communication, but always requires clients to establish trust "????????,?????????????????????????????????"
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecNegotiationPolicy{7238523f-70fa-11d1-864c-14a300000000}ipsecName"Require Security" "????"
    modifiedHKLM/SOFTWARE/Policies/Microsoft/Windows/IPSec/Policy/Local/ipsecNegotiationPolicy{7238523f-70fa-11d1-864c-14a300000000}whenChanged0x4A436155 0x46EE3DCE
    modifiedHKLM/SYSTEM/ControlSet001/Control/GroupOrderListExtended Base04 00 00 00 01 00 00 00 02 00 00 00 04 00 00 00 03 00 00 00 05 00 00 00 01 00 00 00 02 00 00 00 04 00 00 00 03 00 00 00 05 00 00 00
    modifiedHKLM/SYSTEM/CurrentControlSet/Control/GroupOrderListExtended Base04 00 00 00 01 00 00 00 02 00 00 00 04 00 00 00 03 00 00 00 05 00 00 00 01 00 00 00 02 00 00 00 04 00 00 00 03 00 00 00 05 00 00 00
    modifiedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/ConnectionsSavedLegacySettings3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0

    DNS Results

    DNSDNS Response
    js.jk136.comStandard query response A 202.103.221.20
    www.yztq.netStandard query response A 123.196.125.15
    www.yztq.netStandard query response A 61.183.11.242

    URL Results

    DstIPHTTP_HOSTHTTP_REQUEST_URIHTTP_USER_AGENTPROTOCOL
    123.196.125.15www.yztq.net/tj/count.asp?mac=00c029ebbf39&ver=1.0&os=WindowsXP&dtime=2011-2-2baidu0x06
    61.183.11.242www.yztq.net/tj/count.asp?mac=00c029ebbf39&ver=1.0&os=WindowsXP&dtime=2011-2-2baidu0x06
    239.255.255.250239.255.255.250:1900*--blank--0x11

    ARGUS PROTOCOL Results

    PROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    6444130795196
    17203500

    ARGUS DPORT Results

    DPORTPROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES
    106302820961684
    80614139833512
    190017203500

    ARGUS DATA Results

    TimeDateProtocolSrcIPDstIPDirFlagsSportDportPktsBytes
    21:21:372011-03-23610.10.10.7202.103.221.20-> e 3991013928
    21:21:372011-03-23610.10.10.7123.196.125.15-> e 40080132017
    21:21:382011-03-23610.10.10.7202.103.221.20-> e 5091013932
    21:21:422011-03-23610.10.10.7202.103.221.20-> e 3991010600
    21:21:422011-03-23610.10.10.7123.196.125.15-> e 40080112298
    21:21:432011-03-23610.10.10.7202.103.221.20-> e 5091010600
    21:21:472011-03-23610.10.10.7202.103.221.20-> e 399106360
    21:21:482011-03-23610.10.10.7123.196.125.15-> e 400803180
    21:21:482011-03-23610.10.10.7202.103.221.20-> e 509106360
    01:59:182011-05-08610.10.10.7202.103.221.20-> e 5131013928
    01:59:192011-05-08610.10.10.761.183.11.242-> e 51480132017
    01:59:202011-05-08610.10.10.7202.103.221.20-> e 4521013932
    01:59:232011-05-08610.10.10.7202.103.221.20-> e 5131010600
    01:59:242011-05-08610.10.10.761.183.11.242-> e 51480101965
    01:59:252011-05-08610.10.10.7202.103.221.20-> e 4521010600
    01:59:282011-05-08610.10.10.7202.103.221.20-> e 513106360
    01:59:292011-05-08610.10.10.761.183.11.242-> e 514804513
    01:59:302011-05-08610.10.10.7202.103.221.20-> e 452106360
    02:04:212011-05-081710.10.10.7239.255.255.250-> e 819002350

    Packer Results

    Packer Name

    HoneyTrap Results

    Honey Trap Log File Location

    PTFB Results

    PTFB Log File Location