File MD5Sum | SHA1SUM | SHA256SUM | FUZZY HASH | File Size |
---|---|---|---|---|
8c5cb16d2a4fb306b7e938aa463c9ad0 | 7a8019f958a7231a6b86eeb0c9cdbb273f0c1375 | 245d4e58ec674d98683980572f998ca84a43d6c29e115c5c99f3667f06d5d66d | 6144:EcWMJJhqryYP/daqlzV4GA3Fkk7rzPDCykQSt4lHl+BKg51H:EczJJhqrVPldVzA3FB7fPDCykj | 278832 |
File Name |
---|
schwartzbrothersllc.exe |
Snort Class | Snort Alert | Count |
---|---|---|
N/A | No snort alerts generated | 0 |
AV Alert | AV Vendor |
---|---|
N/A | Symantec |
N/A | McAfee |
N/A | Kaspersky |
Path | Folder Name |
---|---|
c:/Documents and Settings/dmc73144 | test |
c:/Documents and Settings/dmc73144 | test |
Action | Path | File Name |
---|
Action | Path |
---|
Action | Path | Val_Name | Val_Data |
---|
Action | Path | Val_Name | Val_Type | Mod_Val_Type | Val_Data | Mod_Val_Data |
---|
Action | Path | Val_Name | Val_Data | Mod_Val_Data |
---|---|---|---|---|
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | F7 05 93 88 7C 8C 10 F5 87 4C 5E D2 B9 1C 6D 1D 66 F6 E3 11 13 6C FF D6 2B 6E 38 | 59 87 CE BD 8A 49 68 99 38 34 31 3B 37 85 13 24 C7 E0 54 73 1B 2A 5F FA 0A 18 7 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformation | ProgramCount | 0x00000002 | 0x00000003 |
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | 35 35 28 EE CA D9 98 42 4F D6 D0 56 AB 75 AE 26 EF C4 BB 66 16 73 9A 34 DA 6C 39 | 00 DE 26 F1 54 B5 66 6E 4C 04 2F 0F 69 3F 5B 79 C5 57 9F B5 E8 24 05 09 04 CF E |
DNS | DNS Response |
---|
DstIP | HTTP_HOST | HTTP_REQUEST_URI | HTTP_USER_AGENT | PROTOCOL |
---|---|---|---|---|
239.255.255.250 | 239.255.255.250:1900 | * | --blank-- | 0x11 |
PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|
17 | 2 | 0 | 350 | 0 |
DPORT | PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|---|
1900 | 17 | 2 | 0 | 350 | 0 |
Time | Date | Protocol | SrcIP | DstIP | Dir | Flags | Sport | Dport | Pkts | Bytes |
---|---|---|---|---|---|---|---|---|---|---|
19:59:48 | 2011-02-26 | 17 | 10.10.10.7 | 239.255.255.250 | -> | e | 8 | 1900 | 2 | 350 |
15:40:16 | 2011-03-08 | 17 | 10.10.10.7 | 239.255.255.250 | -> | e | 8 | 1900 | 2 | 350 |
Packer Name |
---|
Honey Trap Log File Location |
---|
PTFB Log File Location |
---|