File MD5Sum | SHA1SUM | SHA256SUM | FUZZY HASH | File Size |
---|---|---|---|---|
c94211cc8fd1d3494f774a63d865e090 | 5b7163f78883729b4f5a2e78ea8e19911d5b6b4e | 9de8b2c1bc0ec944e5af221097851cc07ffa6a1caad811049f54d820a2adc080 | 1536:Ks0isU3UHPRYRdqgohnAM2PgMHcIOmHcJqOrVhZnveftyha9:Ks0is62WRsHIpAqghZnveVyha | 70224 |
File Name |
---|
setup2683.exe |
Snort Class | Snort Alert | Count |
---|---|---|
N/A | No snort alerts generated | 0 |
AV Alert | AV Vendor |
---|---|
Trojan.ADH | Symantec |
W32/Bamital.p | McAfee |
Backdoor.Win32.Shiz.djl | Kaspersky |
Trojan.Gen | Symantec |
PWS-Banker!gvk | McAfee |
Trojan-Banker.Win32.Banker.bkee | Kaspersky |
N/A | Symantec |
Generic.bfr!bu | McAfee |
N/A | Kaspersky |
Packed-AA!3B98D3D0A19E | McAfee |
Trojan-Banker.Win32.Banker.auzi | Kaspersky |
Artemis!C94211CC8FD1 | McAfee |
Trojan.Win32.Menti.gena | Kaspersky |
Path | Folder Name |
---|
Action | Path | File Name |
---|
Action | Path |
---|
Action | Path | Val_Name | Val_Data |
---|
Action | Path | Val_Name | Val_Type | Mod_Val_Type | Val_Data | Mod_Val_Data |
---|
Action | Path | Val_Name | Val_Data | Mod_Val_Data |
---|---|---|---|---|
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | 2A 13 5C EB 9A 5B 07 E0 2B 2D 58 59 7E 3D DB 53 6C E4 4F 2B 2D 74 96 2A 47 39 DE | 10 08 81 95 0D D7 DB E9 80 C4 CB 3F 68 7A 9B DD 42 9B AD FF 91 C1 FF D7 DE D0 0 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformation | ProgramCount | 0x00000002 | 0x00000001 |
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | 7D 3D 98 3A 7E F5 B0 17 F7 97 39 B3 1A 97 0D 78 D2 08 26 D6 E7 DE 0F CA 86 4E 1F | 64 39 0F B4 CB 3F B6 7A E9 E7 A5 6D 9B C3 10 F5 D8 51 63 7C 37 5A 41 BD 79 B1 7 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformation | ProgramCount | 0x00000002 | 0x00000001 |
DNS | DNS Response |
---|
DstIP | HTTP_HOST | HTTP_REQUEST_URI | HTTP_USER_AGENT | PROTOCOL |
---|---|---|---|---|
239.255.255.250 | 239.255.255.250:1900 | * | --blank-- | 0x11 |
PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|
17 | 1 | 0 | 175 | 0 |
DPORT | PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|---|
1900 | 17 | 1 | 0 | 175 | 0 |
Time | Date | Protocol | SrcIP | DstIP | Dir | Flags | Sport | Dport | Pkts | Bytes |
---|---|---|---|---|---|---|---|---|---|---|
04:58:47 | 2011-04-28 | 17 | 10.10.10.7 | 239.255.255.250 | -> | e | 8 | 1900 | 1 | 175 |
Packer Name |
---|
Honey Trap Log File Location |
---|
PTFB Log File Location |
---|