File MD5Sum | SHA1SUM | SHA256SUM | FUZZY HASH | File Size |
---|---|---|---|---|
7fa68ae89f63bdbb5603610441ab8175 | 9302c2450537d84f5772e7d12d60dee91f6468d1 | 28b5e9bd8453f930b4529171b51af45252bfe1657f5d7d759a53f1bc47c40ad9 | 12288:8BMmKGnhDT+JlChHgnMEuJ2XmLJoS05Z32mykIc:OMmnDC+hHgME8mwJovnGmqc | 541680 |
File Name |
---|
youtube.exe |
Snort Class | Snort Alert | Count |
---|---|---|
A Network Trojan was detected | ET TROJAN Banker.OT Checkin | 1 |
A Network Trojan was detected | ET TROJAN Banker.OT Checkin (2 packet) | 1 |
AV Alert | AV Vendor |
---|---|
N/A | Symantec |
Generic.dx!tcz | McAfee |
N/A | Kaspersky |
Path | Folder Name |
---|
Path | File Name |
---|---|
c:/WINDOWS/Prefetch | SANDNET.EXE-2012C478.pf |
c:/WINDOWS | systemhosts.exe |
c: | netstat_post.txt |
c: | taskv_post.txt |
c: | tempcharc |
Action | Path | File Name |
---|
Action | Path |
---|
Action | Path | Val_Name | Val_Data |
---|
Action | Path | Val_Name | Val_Type | Mod_Val_Type | Val_Data | Mod_Val_Data |
---|
Action | Path | Val_Name | Val_Data | Mod_Val_Data |
---|---|---|---|---|
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | 8E 87 18 09 A3 EB 91 8D 27 3A 09 37 F7 0A A5 48 0C A0 5B 4B 05 DF 75 5F EB 1E 0B | F1 A8 6D 26 F1 3D 8C 33 57 2C DA 59 CB 3D C5 3A 79 4C ED 78 9B 62 9A E7 F1 D2 7 |
DNS | DNS Response |
---|---|
akininguemtaska.info | Standard query response A 65.254.54.5 |
PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|
6 | 21 | 17 | 2603 | 2120 |
17 | 5 | 0 | 875 | 0 |
DPORT | PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|---|
80 | 6 | 21 | 17 | 2603 | 2120 |
1900 | 17 | 5 | 0 | 875 | 0 |
Time | Date | Protocol | SrcIP | DstIP | Dir | Flags | Sport | Dport | Pkts | Bytes |
---|---|---|---|---|---|---|---|---|---|---|
19:58:55 | 2010-07-11 | 6 | 10.10.10.7 | 65.254.54.5 | -> | e | 63 | 80 | 9 | 969 |
19:58:56 | 2010-07-11 | 6 | 10.10.10.7 | 65.254.54.5 | -> | e | 65 | 80 | 9 | 969 |
19:58:57 | 2010-07-11 | 6 | 10.10.10.7 | 65.254.54.5 | -> | e | 66 | 80 | 9 | 969 |
19:58:58 | 2010-07-11 | 6 | 10.10.10.7 | 65.254.54.5 | -> | e | 33 | 80 | 11 | 1816 |
20:04:15 | 2010-07-11 | 17 | 10.10.10.7 | 239.255.255.250 | -> | e | 4002 | 1900 | 2 | 350 |
20:04:21 | 2010-07-11 | 17 | 10.10.10.7 | 239.255.255.250 | -> | e | 4002 | 1900 | 1 | 175 |
20:04:25 | 2010-07-11 | 17 | 10.10.10.7 | 239.255.255.250 | -> | e | 3562 | 1900 | 2 | 350 |
Packer Name |
---|
Honey Trap Log File Location |
---|
PTFB Log File Location |
---|