File MD5Sum | SHA1SUM | SHA256SUM | FUZZY HASH | File Size |
---|---|---|---|---|
d0156ae1692748fea9fdebde80c7f470 | 0bc6ca8b79b92d8f46faaf75c2a1f6b638b0c734 | 0961724abbb7e95a38ec51284d2bbc3bc6587e3fc20fe8d24ed71be22c91378a | 1536:weWP9f5c7G2G5nr3OxGaXeGFdQT4VVC1aCHP+DR/5v259dN:2P9f5c7G22OxGaXeGFdQTMVC12M | 84588 |
File Name |
---|
Postales.exe |
Snort Class | Snort Alert | Count |
---|---|---|
N/A | No snort alerts generated | 0 |
AV Alert | AV Vendor |
---|---|
Infostealer.Bancos | Symantec |
Generic.dx!zuz | McAfee |
Trojan.Win32.VBKrypt.djsq | Kaspersky |
Path | Folder Name |
---|
Action | Path | File Name |
---|
Action | Path |
---|
Action | Path | Val_Name | Val_Data |
---|
Action | Path | Val_Name | Val_Type | Mod_Val_Type | Val_Data | Mod_Val_Data |
---|
Action | Path | Val_Name | Val_Data | Mod_Val_Data |
---|---|---|---|---|
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | 59 21 CC 51 F6 33 C5 A2 06 3D 78 58 36 D1 A7 4C EF B2 39 01 81 E5 E8 25 1C A3 83 | 89 D1 39 AD 07 AB EE 72 31 FB 33 5C 17 FA 9E A7 CC FB 42 10 7D 16 04 0D 4C F6 C |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Connections | SavedLegacySettings | 3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 | 3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows NT/CurrentVersion/Windows | load | "" | "C |
DNS | DNS Response |
---|---|
www.ira.maristas.cl | Standard query response A 201.238.196.195 |
DstIP | HTTP_HOST | HTTP_REQUEST_URI | HTTP_USER_AGENT | PROTOCOL |
---|---|---|---|---|
201.238.196.195 | www.ira.maristas.cl | /galerias/content/2011/componentes/configuracion | vb wininet | 0x06 |
239.255.255.250 | 239.255.255.250:1900 | * | --blank-- | 0x11 |
PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|
6 | 99 | 81 | 8180 | 10906 |
17 | 1 | 0 | 175 | 0 |
DPORT | PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|---|
80 | 6 | 99 | 81 | 8180 | 10906 |
1900 | 17 | 1 | 0 | 175 | 0 |
Time | Date | Protocol | SrcIP | DstIP | Dir | Flags | Sport | Dport | Pkts | Bytes |
---|---|---|---|---|---|---|---|---|---|---|
15:33:52 | 2011-06-18 | 6 | 10.10.10.7 | 201.238.196.195 | -> | e | 311 | 80 | 9 | 927 |
15:34:04 | 2011-06-18 | 6 | 10.10.10.7 | 201.238.196.195 | -> | e | 127 | 80 | 9 | 927 |
15:34:15 | 2011-06-18 | 6 | 10.10.10.7 | 201.238.196.195 | -> | e | 189 | 80 | 9 | 927 |
15:34:27 | 2011-06-18 | 6 | 10.10.10.7 | 201.238.196.195 | -> | e | 190 | 80 | 9 | 927 |
15:34:39 | 2011-06-18 | 6 | 10.10.10.7 | 201.238.196.195 | -> | e | 539 | 80 | 9 | 927 |
15:34:51 | 2011-06-18 | 6 | 10.10.10.7 | 201.238.196.195 | -> | e | 540 | 80 | 9 | 927 |
15:35:03 | 2011-06-18 | 6 | 10.10.10.7 | 201.238.196.195 | -> | e | 46 | 80 | 9 | 927 |
15:35:14 | 2011-06-18 | 6 | 10.10.10.7 | 201.238.196.195 | -> | e | 581 | 80 | 9 | 927 |
15:35:26 | 2011-06-18 | 6 | 10.10.10.7 | 201.238.196.195 | -> | e | 102 | 80 | 9 | 927 |
15:35:38 | 2011-06-18 | 6 | 10.10.10.7 | 201.238.196.195 | -> | e | 436 | 80 | 9 | 927 |
15:35:50 | 2011-06-18 | 6 | 10.10.10.7 | 201.238.196.195 | -> | e | 49 | 80 | 9 | 927 |
15:36:02 | 2011-06-18 | 6 | 10.10.10.7 | 201.238.196.195 | -> | e | 23 | 80 | 9 | 927 |
15:36:14 | 2011-06-18 | 6 | 10.10.10.7 | 201.238.196.195 | -> | e | 411 | 80 | 9 | 927 |
15:36:26 | 2011-06-18 | 6 | 10.10.10.7 | 201.238.196.195 | -> | e | 735 | 80 | 9 | 927 |
15:36:38 | 2011-06-18 | 6 | 10.10.10.7 | 201.238.196.195 | -> | e | 736 | 80 | 9 | 927 |
15:36:50 | 2011-06-18 | 6 | 10.10.10.7 | 201.238.196.195 | -> | e | 783 | 80 | 9 | 927 |
15:37:02 | 2011-06-18 | 6 | 10.10.10.7 | 201.238.196.195 | -> | e | 784 | 80 | 9 | 927 |
15:37:14 | 2011-06-18 | 6 | 10.10.10.7 | 201.238.196.195 | -> | e | 830 | 80 | 9 | 927 |
15:37:25 | 2011-06-18 | 6 | 10.10.10.7 | 201.238.196.195 | -> | e | 831 | 80 | 9 | 927 |
15:37:37 | 2011-06-18 | 6 | 10.10.10.7 | 201.238.196.195 | -> | e d | 832 | 80 | 7 | 1080 |
15:39:11 | 2011-06-18 | 6 | 10.10.10.7 | 201.238.196.195 | -> | e | 832 | 80 | 2 | 393 |
15:39:11 | 2011-06-18 | 17 | 10.10.10.7 | 239.255.255.250 | -> | e | 8 | 1900 | 1 | 175 |
Packer Name |
---|
Honey Trap Log File Location |
---|
PTFB Log File Location |
---|