File MD5Sum | SHA1SUM | SHA256SUM | FUZZY HASH | File Size |
---|---|---|---|---|
e5623a497167d8a6c98e2e6b0293577d | 826cd25fd2b22e03224ab93e4de7b586e13e512e | 1c345270e78e267a734772afb901ea9f3290e755149dc95c3c1f1eabc644fa2e | 6144:EcWMJJhqryYP/daqlzV4GA3Fkk7rzPDCykQSt4lHl+BKg5MOyf:EczJJhqrVPldVzA3FB7fPDCy | 278866 |
File Name |
---|
generalabbrialgroupltd.exe |
Snort Class | Snort Alert | Count |
---|---|---|
N/A | No snort alerts generated | 0 |
AV Alert | AV Vendor |
---|---|
N/A | Symantec |
N/A | McAfee |
N/A | Kaspersky |
Trojan.Chos | Symantec |
Artemis!E5623A497167 | McAfee |
Trojan.Win32.FakeTest.c | Kaspersky |
Trojan.Dropper | Symantec |
Generic | McAfee |
Rootkit.Win32.Tent.cos | Kaspersky |
Backdoor.Trojan | Symantec |
Backdoor.Win32.VB.nim | Kaspersky |
WS.Reputation.1 | Symantec |
Path | Folder Name |
---|---|
c:/Documents and Settings/dmc73144 | test |
c:/Documents and Settings/dmc73144 | test |
Action | Path | File Name |
---|
Action | Path |
---|
Action | Path | Val_Name | Val_Data |
---|
Action | Path | Val_Name | Val_Type | Mod_Val_Type | Val_Data | Mod_Val_Data |
---|
Action | Path | Val_Name | Val_Data | Mod_Val_Data |
---|---|---|---|---|
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | 65 91 16 73 28 F4 EC DD 5B 9D 46 08 B6 D8 40 3A 04 FC 6F E1 96 1C 8C A4 6D E5 F3 | B9 48 EA 16 8D F2 EA 16 92 9E 2A 24 E2 3C E6 68 FA 80 69 94 E0 20 1C 2A C1 A9 9 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformation | ProgramCount | 0x00000002 | 0x00000003 |
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | 77 7B CA 17 FC 16 8F 21 38 4E 36 D3 64 D0 99 F8 C9 97 46 DE B9 0C 49 83 28 10 07 | 88 93 A4 A7 AA 92 EE 71 F6 1A EE 66 B5 8E BA EB 2F ED B2 AB 42 06 30 D1 36 AA 6 |
DNS | DNS Response |
---|
DstIP | HTTP_HOST | HTTP_REQUEST_URI | HTTP_USER_AGENT | PROTOCOL |
---|---|---|---|---|
239.255.255.250 | 239.255.255.250:1900 | * | --blank-- | 0x11 |
PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|
17 | 2 | 0 | 350 | 0 |
DPORT | PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|---|
1900 | 17 | 2 | 0 | 350 | 0 |
Time | Date | Protocol | SrcIP | DstIP | Dir | Flags | Sport | Dport | Pkts | Bytes |
---|---|---|---|---|---|---|---|---|---|---|
20:09:15 | 2011-02-26 | 17 | 10.10.10.7 | 239.255.255.250 | -> | e | 8 | 1900 | 2 | 350 |
13:27:58 | 2011-03-08 | 17 | 10.10.10.7 | 239.255.255.250 | -> | e | 8 | 1900 | 2 | 350 |
Packer Name |
---|
Honey Trap Log File Location |
---|
PTFB Log File Location |
---|