File MD5Sum | SHA1SUM | SHA256SUM | FUZZY HASH | File Size |
---|---|---|---|---|
56b50e4392098ba4f121a2a26e273b0a | 30936a12e023ad4ee31e188cb204186124c461df | af34ae1c20358edd1ec02140ad0e277ab85a6f577b02540521f9b1d4e14084d1 | 1536:xHQJTNrhhlliP452/8QVOvvBSUspjnhhlzk6tb4gHtd6h7FEHMqH1Ddnb:xwJflT2pMv0DV/b4A | 106496 |
File Name |
---|
222.exe |
Snort Class | Snort Alert | Count |
---|---|---|
N/A | No snort alerts generated | 0 |
AV Alert | AV Vendor |
---|---|
N/A | Symantec |
Generic.dx!bank | McAfee |
Trojan.Win32.VB.auou | Kaspersky |
Path | Folder Name |
---|
Path | File Name |
---|---|
c:/WINDOWS/Prefetch | AUTOIT3.EXE-32361418.pf |
c:/WINDOWS/Prefetch | REGSHOT.EXE-010A5EE6.pf |
c:/WINDOWS/Prefetch | SANDNET.EXE-2012C478.pf |
c:/WINDOWS | services.exe |
Action | Path | File Name |
---|
Action | Path |
---|
Action | Path | Val_Name | Val_Data |
---|---|---|---|
added | HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Run | services.exe | "C:/WINDOWS/services.exe" |
Action | Path | Val_Name | Val_Type | Mod_Val_Type | Val_Data | Mod_Val_Data |
---|
Action | Path | Val_Name | Val_Data | Mod_Val_Data |
---|---|---|---|---|
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | 52 62 CF 4D AB 74 FB 9E 9F 7F 42 1A C0 70 B7 2A 86 EA BC 54 43 3C 9D E0 5B 74 F4 | 9B C9 83 08 ED 0A CB 23 18 A9 D8 10 AC 61 FB E3 AC 48 DE CA 41 12 EF E6 43 B7 1F |
DNS | DNS Response |
---|---|
peru.wwwhost.biz | Standard query response A 92.242.140.35 |
continental.wwwhost.biz | Standard query response A 92.242.140.35 |
nacion.wwwhost.biz | Standard query response A 92.242.140.35 |
ecua-chi-bo.wwwhost.biz | Standard query response A 92.242.140.35 |
argentina.americanunfinished.com | Standard query response A 92.242.140.35 |
DstIP | HTTP_HOST | HTTP_REQUEST_URI | HTTP_USER_AGENT | PROTOCOL |
---|
PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|
DPORT | PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|
Time | Date | Protocol | SrcIP | DstIP | Dir | Flags | Sport | Dport | Pkts | Bytes |
---|
Packer Name |
---|
Honey Trap Log File Location |
---|
PTFB Log File Location |
---|