File MD5Sum | SHA1SUM | SHA256SUM | FUZZY HASH | File Size |
---|---|---|---|---|
78c9b71bc239d2351e2f587a859cdfe1 | d829d35856c17931a66ec29142309eb934503558 | c28b75103d864b3b10218dece9eaf714cf2d3401d123220574936fba3907b9d0 | 384:SFLg2MOlzFaFs4BxKSnJ0dDHCUmMKqS0jBNH3wjmED3wR0Acdtvr:SFLJGs4BwS+dzr1SwNXDEDA | 25088 |
File Name |
---|
fm01.css.exe |
Snort Class | Snort Alert | Count |
---|---|---|
N/A | No snort alerts generated | 0 |
AV Alert | AV Vendor |
---|---|
Trojan | Symantec |
Generic | McAfee |
Trojan-Downloader.Win32.Geral.vnk | Kaspersky |
Path | Folder Name |
---|---|
c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5 | ITB2CJ0C |
Action | Path | File Name |
---|
Action | Path |
---|
Action | Path | Val_Name | Val_Data |
---|
Action | Path | Val_Name | Val_Type | Mod_Val_Type | Val_Data | Mod_Val_Data |
---|
Action | Path | Val_Name | Val_Data | Mod_Val_Data |
---|---|---|---|---|
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | 34 E4 0E 7B 25 BC 24 7D 7A 72 D1 FE F9 6B DE C7 7D 75 12 8C 30 69 D5 72 2C 29 16 | EF 3B 6C E7 D8 25 76 DB 36 BC 3D DC 0D 00 C4 0C 93 C6 E2 45 A4 42 D2 16 31 D3 A |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Connections | SavedLegacySettings | 3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 | 3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformation | ProgramCount | 0x00000002 | 0x00000001 |
DNS | DNS Response |
---|---|
ad.wdtx.net | Standard query response A 122.224.32.37 |
count.wemv.net | Standard query response A 122.224.32.37 |
DstIP | HTTP_HOST | HTTP_REQUEST_URI | HTTP_USER_AGENT | PROTOCOL |
---|---|---|---|---|
239.255.255.250 | 239.255.255.250:1900 | * | --blank-- | 0x11 |
PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|
6 | 44 | 41 | 2969 | 2466 |
17 | 1 | 0 | 175 | 0 |
DPORT | PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|---|
72 | 6 | 30 | 28 | 1981 | 1684 |
88 | 6 | 14 | 13 | 988 | 782 |
1900 | 17 | 1 | 0 | 175 | 0 |
Time | Date | Protocol | SrcIP | DstIP | Dir | Flags | Sport | Dport | Pkts | Bytes |
---|---|---|---|---|---|---|---|---|---|---|
15:57:49 | 2011-05-26 | 6 | 10.10.10.7 | 122.224.32.37 | -> | e | 56 | 72 | 13 | 874 |
15:57:49 | 2011-05-26 | 6 | 10.10.10.7 | 122.224.32.37 | -> | e | 44 | 88 | 14 | 990 |
15:57:49 | 2011-05-26 | 6 | 10.10.10.7 | 122.224.32.37 | -> | e | 20 | 72 | 14 | 931 |
15:57:54 | 2011-05-26 | 6 | 10.10.10.7 | 122.224.32.37 | -> | e | 56 | 72 | 11 | 660 |
15:57:54 | 2011-05-26 | 6 | 10.10.10.7 | 122.224.32.37 | -> | e | 44 | 88 | 10 | 600 |
15:57:55 | 2011-05-26 | 6 | 10.10.10.7 | 122.224.32.37 | -> | e | 20 | 72 | 10 | 600 |
15:57:59 | 2011-05-26 | 6 | 10.10.10.7 | 122.224.32.37 | -> | e | 56 | 72 | 5 | 300 |
15:57:59 | 2011-05-26 | 6 | 10.10.10.7 | 122.224.32.37 | -> | e | 44 | 88 | 3 | 180 |
15:58:00 | 2011-05-26 | 6 | 10.10.10.7 | 122.224.32.37 | -> | e | 20 | 72 | 5 | 300 |
16:03:07 | 2011-05-26 | 17 | 10.10.10.7 | 239.255.255.250 | -> | e | 8 | 1900 | 1 | 175 |
Packer Name |
---|
Honey Trap Log File Location |
---|
PTFB Log File Location |
---|