File MD5Sum | SHA1SUM | SHA256SUM | FUZZY HASH | File Size |
---|---|---|---|---|
ddc6c46af5f67f3bb44abec39fdc589d | b52e1c0d4b0f944c3507f997aa98394ed11d6d8f | 01daea6dccf1c44cc4e0a12e35fbb303f9c9a4560af40f2d3791c16147ed3723 | 3072:WGYGpO/QN/iR7zcMbqC2CU7CM1ujutoZrrx1/L+XGJ0a2efaZKHjrbAx:WpCO/o/iR8MbqwUYju | 154112 |
File Name |
---|
load.php%3Fspl%3Dmdac.exe |
Snort Class | Snort Alert | Count |
---|---|---|
N/A | No snort alerts generated | 0 |
AV Alert | AV Vendor |
---|---|
N/A | Symantec |
N/A | McAfee |
N/A | Kaspersky |
Action | Path | File Name |
---|
Action | Path |
---|
Action | Path | Val_Name | Val_Data |
---|
Action | Path | Val_Name | Val_Type | Mod_Val_Type | Val_Data | Mod_Val_Data |
---|
Action | Path | Val_Name | Val_Data | Mod_Val_Data |
---|---|---|---|---|
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | 31 27 1D 1B 63 94 44 AC CD 58 AA B0 1A A3 D4 40 D9 FF D5 30 1E 0E 24 D2 3C 1F 1A | D9 6E 92 2E AB A5 EA E2 75 64 58 ED 66 40 BF 8E 65 7B EC A7 38 57 E6 56 CC 27 C |
modified | HKLM/SYSTEM/ControlSet001/Services/wscsvc | Start | 0x00000002 | 0x00000004 |
modified | HKLM/SYSTEM/CurrentControlSet/Services/wscsvc | Start | 0x00000002 | 0x00000004 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Connections | SavedLegacySettings | 3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 | 3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0 |
DNS | DNS Response |
---|---|
windowsupdate.microsoft.com | Standard query response CNAME windowsupdate.microsoft.nsatc.net A 207.46.18.94 |
myantivirus-plus.org | Standard query response A 91.188.60.3 |
PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|
6 | 15 | 12 | 1486 | 1545 |
17 | 2 | 0 | 350 | 0 |
DPORT | PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|---|
80 | 6 | 15 | 12 | 1486 | 1545 |
1900 | 17 | 2 | 0 | 350 | 0 |
Time | Date | Protocol | SrcIP | DstIP | Dir | Flags | Sport | Dport | Pkts | Bytes |
---|---|---|---|---|---|---|---|---|---|---|
15:11:07 | 2010-05-13 | 6 | 10.10.10.7 | 207.46.18.94 | -> | e | 105 | 80 | 9 | 1002 |
15:11:08 | 2010-05-13 | 6 | 10.10.10.7 | 91.188.60.3 | -> | e | 27 | 80 | 9 | 1013 |
15:11:10 | 2010-05-13 | 6 | 10.10.10.7 | 91.188.60.3 | -> | e | 313 | 80 | 9 | 1016 |
15:16:46 | 2010-05-13 | 17 | 10.10.10.7 | 239.255.255.250 | -> | e | 8 | 1900 | 2 | 350 |
Packer Name |
---|
Honey Trap Log File Location |
---|
PTFB Log File Location |
---|