File MD5Sum | SHA1SUM | SHA256SUM | FUZZY HASH | File Size |
---|---|---|---|---|
f542dff8f4c1b4f968f0f28d7019f34e | 50b89a16b7e7f7cb89217c80477d6c2f4c758eef | 184e2a129e069e866d129a2e88b5fb210f744de234bd60963722d76884771586 | 768:UFLJ6YQbQh7lERyv3BUtpp/fPlV//l2l:0F6tAEC36R/lVF2 | 25088 |
File Name |
---|
xm05.css.exe |
Snort Class | Snort Alert | Count |
---|---|---|
N/A | No snort alerts generated | 0 |
AV Alert | AV Vendor |
---|
Path | Folder Name |
---|---|
c:/Documents and Settings/dmc73144/Local Settings/Temporary Internet Files/Content.IE5 | ITB2CJ0C |
Action | Path | File Name |
---|
Action | Path |
---|
Action | Path | Val_Name | Val_Data |
---|
Action | Path | Val_Name | Val_Type | Mod_Val_Type | Val_Data | Mod_Val_Data |
---|
Action | Path | Val_Name | Val_Data | Mod_Val_Data |
---|---|---|---|---|
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | EF AD D9 BB B0 E8 E9 E9 39 10 A4 36 8F AA 5A 5A 5E 7A E9 E5 E3 56 D5 06 06 05 D2 | 04 EF CA CF F2 A5 32 1A 2D 13 EE A8 F3 19 E0 1D 10 C4 8F B4 0D F1 43 0E F6 C3 5 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Connections | SavedLegacySettings | 3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 | 3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformation | ProgramCount | 0x00000002 | 0x00000001 |
DNS | DNS Response |
---|---|
ad.wdtx.net | Standard query response A 121.14.152.137 |
count.wemv.net | Standard query response A 122.224.7.220 |
DstIP | HTTP_HOST | HTTP_REQUEST_URI | HTTP_USER_AGENT | PROTOCOL |
---|---|---|---|---|
239.255.255.250 | 239.255.255.250:1900 | * | --blank-- | 0x11 |
PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|
6 | 44 | 41 | 2969 | 2466 |
17 | 5 | 0 | 875 | 0 |
DPORT | PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|---|
72 | 6 | 30 | 28 | 1981 | 1684 |
88 | 6 | 14 | 13 | 988 | 782 |
1900 | 17 | 5 | 0 | 875 | 0 |
Time | Date | Protocol | SrcIP | DstIP | Dir | Flags | Sport | Dport | Pkts | Bytes |
---|---|---|---|---|---|---|---|---|---|---|
20:19:30 | 2011-06-10 | 6 | 10.10.10.7 | 121.14.152.137 | -> | e | 106 | 72 | 13 | 874 |
20:19:31 | 2011-06-10 | 6 | 10.10.10.7 | 121.14.152.137 | -> | e | 11 | 72 | 13 | 871 |
20:19:32 | 2011-06-10 | 6 | 10.10.10.7 | 122.224.7.220 | -> | e | 115 | 88 | 13 | 930 |
20:19:35 | 2011-06-10 | 6 | 10.10.10.7 | 121.14.152.137 | -> | e | 106 | 72 | 10 | 600 |
20:19:36 | 2011-06-10 | 6 | 10.10.10.7 | 121.14.152.137 | -> | e | 11 | 72 | 10 | 600 |
20:19:37 | 2011-06-10 | 6 | 10.10.10.7 | 122.224.7.220 | -> | e | 115 | 88 | 10 | 600 |
20:19:40 | 2011-06-10 | 6 | 10.10.10.7 | 121.14.152.137 | -> | e | 106 | 72 | 6 | 360 |
20:19:41 | 2011-06-10 | 6 | 10.10.10.7 | 121.14.152.137 | -> | e | 11 | 72 | 6 | 360 |
20:19:42 | 2011-06-10 | 6 | 10.10.10.7 | 122.224.7.220 | -> | e | 115 | 88 | 4 | 240 |
20:24:40 | 2011-06-10 | 17 | 10.10.10.7 | 239.255.255.250 | -> | e | 4002 | 1900 | 2 | 350 |
20:24:46 | 2011-06-10 | 17 | 10.10.10.7 | 239.255.255.250 | -> | e | 4002 | 1900 | 1 | 175 |
20:24:49 | 2011-06-10 | 17 | 10.10.10.7 | 239.255.255.250 | -> | e | 413 | 1900 | 2 | 350 |
Packer Name |
---|
Honey Trap Log File Location |
---|
PTFB Log File Location |
---|