File MD5Sum | SHA1SUM | SHA256SUM | FUZZY HASH | File Size |
---|---|---|---|---|
8786c4ee5eab3d45cf751bae299a6142 | f27e889b540cbf12543448fd4cb3cc7aa32b6f0b | 5ab42849f2642e10561a3d70aea0131e3d617664286d59a07c9fd4757d8db767 | 6144:lhR2+yf2/X9iSHCQCly3AcyAIsgmAj3Nt9OA:y2/X9iECDgHppXkOA | 216570 |
File Name |
---|
QvodSetupPlusGwA1.exe |
Snort Class | Snort Alert | Count |
---|---|---|
Misc activity | ICMP Destination Unreachable Port Unreachable | 2 |
A Network Trojan was detected | ET USER_AGENTS QVOD Related Spyware/Malware User-Agent (Qvod) | 1 |
AV Alert | AV Vendor |
---|---|
Trojan | Symantec |
Artemis!8786C4EE5EAB | McAfee |
Trojan-Downloader.Win32.Geral.vnk | Kaspersky |
Path | Folder Name |
---|---|
c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5 | ITB2CJ0C |
Action | Path | File Name |
---|
Action | Path |
---|
Action | Path | Val_Name | Val_Data |
---|
Action | Path | Val_Name | Val_Type | Mod_Val_Type | Val_Data | Mod_Val_Data |
---|
Action | Path | Val_Name | Val_Data | Mod_Val_Data |
---|---|---|---|---|
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | 1A 53 30 8D 42 C9 D8 9B 97 84 4E 68 F0 07 BE 42 48 CD CF 6B 91 3C A2 6C 6A 6A 85 | 33 C2 9C 53 33 77 EC CB C0 B7 C6 4C 13 B0 05 C4 DE A1 DF BB DA 2E 3B 14 88 7A 7 |
modified | HKLM/SYSTEM/ControlSet001/Services/SharedAccess/Epoch | Epoch | 0x00000104 | 0x00000105 |
modified | HKLM/SYSTEM/CurrentControlSet/Services/SharedAccess/Epoch | Epoch | 0x00000104 | 0x00000105 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Connections | SavedLegacySettings | 3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 | 3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformation | ProgramCount | 0x00000002 | 0x00000003 |
DNS | DNS Response |
---|---|
update.qvod.com | Standard query response A 122.225.115.152 |
track.qvod.com | Standard query response A 122.225.115.135 A 122.225.115.138 A 122.225.115.141 A 122.225.115.132 |
stun.qvod.com | Standard query response A 61.139.219.210 |
stun01.sipphone.com | Standard query response A 198.65.166.165 |
agent.qvod.com | Standard query response A 122.225.115.155 |
ad.3cg5.com | Standard query response A 121.14.151.72 |
count.3cg5.com | Standard query response A 122.224.32.220 |
track.qvod.com | Standard query response A 122.225.115.132 A 122.225.115.135 A 122.225.115.138 A 122.225.115.141 |
DstIP | HTTP_HOST | HTTP_REQUEST_URI | HTTP_USER_AGENT | PROTOCOL |
---|---|---|---|---|
122.225.115.152 | update.qvod.com | /qd.jpg | QvodDown | 0x06 |
10.10.10.1 | 239.255.255.250:1900 | * | --blank-- | 0x11 |
PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|
1 | 17 | 0 | 1207 | 0 |
6 | 297 | 341 | 19650 | 90655 |
17 | 89 | 300 | 6992 | 18000 |
DPORT | PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|---|
23313 | 1 | 6 | 0 | 426 | 0 |
23057 | 1 | 5 | 0 | 355 | 0 |
32031 | 1 | 2 | 0 | 142 | 0 |
32287 | 1 | 4 | 0 | 284 | 0 |
72 | 6 | 30 | 28 | 1981 | 1684 |
80 | 6 | 253 | 300 | 16681 | 88189 |
88 | 6 | 14 | 13 | 988 | 782 |
80 | 17 | 43 | 248 | 3354 | 14880 |
1900 | 17 | 4 | 20 | 698 | 1200 |
3478 | 17 | 42 | 32 | 2940 | 1920 |
Time | Date | Protocol | SrcIP | DstIP | Dir | Flags | Sport | Dport | Pkts | Bytes |
---|---|---|---|---|---|---|---|---|---|---|
14:53:43 | 2011-04-08 | 1 | 10.10.10.7 | 61.139.219.210 | -> | e | 4007 | 23313 | 6 | 426 |
14:53:43 | 2011-04-08 | 1 | 10.10.10.7 | 61.139.219.210 | -> | e | 4007 | 23057 | 5 | 355 |
14:53:46 | 2011-04-08 | 1 | 10.10.10.7 | 198.65.166.165 | -> | e | 4007 | 32031 | 2 | 142 |
14:53:46 | 2011-04-08 | 1 | 10.10.10.7 | 198.65.166.165 | -> | e | 4007 | 32287 | 4 | 284 |
14:53:38 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.152 | -> | e d | 89 | 80 | 14 | 2416 |
14:53:44 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.152 | -> | e | 89 | 80 | 10 | 1965 |
14:53:48 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 15 | 2299 |
14:53:49 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.152 | -> | e | 89 | 80 | 4 | 513 |
14:53:53 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 12 | 2388 |
14:53:55 | 2011-04-08 | 6 | 10.10.10.7 | 121.14.151.72 | -> | e | 119 | 72 | 13 | 871 |
14:53:55 | 2011-04-08 | 6 | 10.10.10.7 | 122.224.32.220 | -> | e | 378 | 88 | 13 | 930 |
14:53:58 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 11 | 1782 |
14:54:01 | 2011-04-08 | 6 | 10.10.10.7 | 121.14.151.72 | -> | e | 119 | 72 | 10 | 600 |
14:54:01 | 2011-04-08 | 6 | 10.10.10.7 | 122.224.32.220 | -> | e | 378 | 88 | 10 | 600 |
14:54:03 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 12 | 2388 |
14:54:06 | 2011-04-08 | 6 | 10.10.10.7 | 121.14.151.72 | -> | e | 119 | 72 | 6 | 360 |
14:54:06 | 2011-04-08 | 6 | 10.10.10.7 | 122.224.32.220 | -> | e | 378 | 88 | 4 | 240 |
14:54:09 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 11 | 2055 |
14:54:14 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 12 | 2115 |
14:54:19 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 12 | 2388 |
14:54:25 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 11 | 2055 |
14:54:30 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 12 | 2115 |
14:54:35 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 11 | 2055 |
14:54:41 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 11 | 2055 |
14:54:46 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 12 | 2388 |
14:54:51 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 12 | 2115 |
14:54:57 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 13 | 2448 |
14:55:03 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 12 | 2115 |
14:53:40 | 2011-04-08 | 17 | 10.10.10.7 | 61.139.219.210 | <-> | eU | 3041 | 3478 | 16 | 1030 |
14:53:40 | 2011-04-08 | 17 | 10.10.10.7 | 61.139.219.210 | <-> | eU | 3042 | 3478 | 27 | 1760 |
14:53:43 | 2011-04-08 | 17 | 10.10.10.7 | 198.65.166.165 | <-> | eU | 5481 | 3478 | 10 | 670 |
14:53:43 | 2011-04-08 | 17 | 10.10.10.7 | 198.65.166.165 | <-> | eU | 5482 | 3478 | 21 | 1400 |
14:53:45 | 2011-04-08 | 17 | 10.10.10.7 | 10.10.10.1 | <-> | e | 503 | 1900 | 13 | 1238 |
14:53:48 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 6 | 378 |
14:53:51 | 2011-04-08 | 17 | 10.10.10.7 | 10.10.10.1 | <- | e | 503 | 1900 | 11 | 660 |
14:53:53 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 7 | 438 |
14:53:58 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 5 | 318 |
14:54:03 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 7 | 438 |
14:54:09 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 6 | 378 |
14:54:14 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 7 | 438 |
14:54:20 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 6 | 378 |
14:54:25 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 6 | 378 |
14:54:30 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 7 | 438 |
14:54:36 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 5 | 318 |
14:54:42 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 7 | 456 |
14:54:48 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 7 | 438 |
14:54:54 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 7 | 438 |
14:55:00 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 6 | 378 |
14:55:05 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 5 | 318 |
14:55:08 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 11 | 2055 |
14:55:13 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 14 | 2538 |
14:55:19 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 10 | 1965 |
14:55:24 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 14 | 2538 |
14:55:30 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 11 | 2055 |
14:55:35 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 13 | 2448 |
14:55:41 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 13 | 2448 |
14:55:47 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 10 | 1965 |
14:55:52 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 11 | 2055 |
14:55:57 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 11 | 2055 |
14:56:02 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 11 | 2055 |
14:56:07 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 12 | 2388 |
14:56:12 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 11 | 2055 |
14:56:17 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 12 | 2115 |
14:56:23 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 11 | 2055 |
14:56:28 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 11 | 2055 |
14:56:33 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 12 | 2388 |
14:56:39 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 11 | 2055 |
14:56:44 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 11 | 2055 |
14:56:49 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 11 | 2055 |
14:56:54 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 12 | 2115 |
14:56:59 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 10 | 1965 |
14:57:04 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 11 | 2055 |
14:57:09 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 12 | 2388 |
14:57:15 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 11 | 2055 |
14:57:20 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 12 | 2115 |
14:57:25 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 12 | 2388 |
14:57:31 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 11 | 2055 |
14:57:36 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e | 417 | 80 | 11 | 2055 |
14:57:41 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e d | 417 | 80 | 8 | 1845 |
14:57:46 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e d | 417 | 80 | 3 | 2115 |
14:57:54 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e d | 417 | 80 | 1 | 333 |
14:59:09 | 2011-04-08 | 6 | 10.10.10.7 | 122.225.115.155 | -> | e d | 417 | 80 | 1 | 333 |
14:55:10 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 7 | 438 |
14:55:16 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 7 | 438 |
14:55:22 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 10 | 618 |
14:55:28 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 12 | 738 |
14:55:34 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 7 | 438 |
14:55:39 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 6 | 378 |
14:55:45 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <-> | e | 4001 | 80 | 7 | 438 |
14:55:51 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <- | e | 4001 | 80 | 5 | 300 |
14:55:52 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <-> | e | 4001 | 80 | 5 | 318 |
14:55:56 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.135 | <- | e | 4001 | 80 | 1 | 60 |
14:55:57 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <-> | e | 4001 | 80 | 6 | 378 |
14:56:02 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <-> | e | 4001 | 80 | 6 | 378 |
14:56:07 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <-> | e | 4001 | 80 | 7 | 438 |
14:56:13 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <-> | e | 4001 | 80 | 6 | 378 |
14:56:18 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <-> | e | 4001 | 80 | 6 | 378 |
14:56:23 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <-> | e | 4001 | 80 | 7 | 438 |
14:56:29 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <-> | e | 4001 | 80 | 6 | 378 |
14:56:34 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <-> | e | 4001 | 80 | 6 | 378 |
14:56:39 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <-> | e | 4001 | 80 | 5 | 318 |
14:56:44 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <-> | e | 4001 | 80 | 6 | 378 |
14:56:49 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <-> | e | 4001 | 80 | 6 | 378 |
14:56:54 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <-> | e | 4001 | 80 | 7 | 438 |
14:57:00 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <-> | e | 4001 | 80 | 6 | 378 |
14:57:05 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <- | e | 4001 | 80 | 5 | 300 |
14:57:11 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <-> | e | 4001 | 80 | 7 | 438 |
14:57:16 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <-> | e | 4001 | 80 | 7 | 438 |
14:57:22 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <-> | e | 4001 | 80 | 8 | 516 |
14:57:29 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <-> | e | 4001 | 80 | 7 | 438 |
14:57:35 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <-> | e | 4001 | 80 | 7 | 438 |
14:57:41 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <- | e | 4001 | 80 | 6 | 360 |
14:57:46 | 2011-04-08 | 17 | 10.10.10.7 | 122.225.115.132 | <- | e | 4001 | 80 | 3 | 180 |
Packer Name |
---|
Honey Trap Log File Location |
---|
PTFB Log File Location |
---|