File MD5Sum | SHA1SUM | SHA256SUM | FUZZY HASH | File Size |
---|---|---|---|---|
fd6c07a166e91a17432e00c844c21229 | 67d3b84a906278557c2290b15902349993e9d5aa | 69c4913ff3cf3818cca02bad32516b231a0c0b86019285e28242fde27ed70784 | 3072:0cKHbAK0ShMF5/JT6JturegyGpHAdbNuASvQv/hQhUvL2duNB+Gw17MV:oe58JturegyPx2Qv6N | 225312 |
File Name |
---|
janh.exe |
Snort Class | Snort Alert | Count |
---|---|---|
N/A | No snort alerts generated | 0 |
AV Alert | AV Vendor |
---|---|
Backdoor.Trojan | Symantec |
N/A | McAfee |
Trojan.Win32.Midgare.amrd | Kaspersky |
Path | Folder Name |
---|---|
c:/Program Files/Common Files/System | systems |
Action | Path | File Name |
---|
Action | Path |
---|
Action | Path | Val_Name | Val_Data |
---|
Action | Path | Val_Name | Val_Type | Mod_Val_Type | Val_Data | Mod_Val_Data |
---|
Action | Path | Val_Name | Val_Data | Mod_Val_Data |
---|---|---|---|---|
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | DF 3B 55 20 B0 97 56 46 B8 95 0A C2 B1 CD 63 CE B1 FE 0A 67 C4 2E 07 69 27 27 6F | FD B4 62 FE C3 74 24 E5 94 E7 DF EB F4 5D E4 EA AB C6 E5 95 24 D8 01 A4 82 49 B |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformation | ProgramCount | 0x00000002 | 0x00000001 |
DNS | DNS Response |
---|---|
cp.rigotax.info | Standard query response CNAME web-forward.dnsexit.com A 67.214.175.92 |
DstIP | HTTP_HOST | HTTP_REQUEST_URI | HTTP_USER_AGENT | PROTOCOL |
---|---|---|---|---|
67.214.175.92 | cp.rigotax.info | / | 0x06 | |
239.255.255.250 | 239.255.255.250:1900 | * | --blank-- | 0x11 |
PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|
6 | 239 | 223 | 15236 | 57092 |
17 | 5 | 0 | 875 | 0 |
DPORT | PROTOCOL | SRC_PKTS | DST_PKTS | SRC_BYTES | DST_BYTES |
---|---|---|---|---|---|
80 | 6 | 239 | 223 | 15236 | 57092 |
1900 | 17 | 5 | 0 | 875 | 0 |
Time | Date | Protocol | SrcIP | DstIP | Dir | Flags | Sport | Dport | Pkts | Bytes |
---|---|---|---|---|---|---|---|---|---|---|
17:02:09 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 96 | 80 | 13 | 1930 |
17:02:14 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 96 | 80 | 11 | 2298 |
17:02:19 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 96 | 80 | 5 | 300 |
17:02:23 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 94 | 80 | 13 | 1930 |
17:02:28 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 94 | 80 | 11 | 2298 |
17:02:34 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 94 | 80 | 5 | 300 |
17:02:38 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 53 | 80 | 13 | 1930 |
17:02:43 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 53 | 80 | 10 | 1965 |
17:02:48 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 53 | 80 | 6 | 633 |
17:02:53 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 54 | 80 | 13 | 1930 |
17:02:58 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 54 | 80 | 11 | 2298 |
17:03:04 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 54 | 80 | 5 | 300 |
17:03:08 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 80 | 80 | 14 | 2263 |
17:03:14 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 80 | 80 | 11 | 2025 |
17:03:19 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 80 | 80 | 4 | 240 |
17:03:23 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 81 | 80 | 13 | 1930 |
17:03:28 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 81 | 80 | 11 | 2298 |
17:03:34 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 81 | 80 | 5 | 300 |
17:03:38 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 211 | 80 | 13 | 1930 |
17:03:43 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 211 | 80 | 10 | 1965 |
17:03:48 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 211 | 80 | 6 | 633 |
17:03:53 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 16 | 80 | 13 | 1930 |
17:03:58 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 16 | 80 | 10 | 1965 |
17:04:03 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 16 | 80 | 4 | 513 |
17:04:08 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 497 | 80 | 14 | 2263 |
17:04:08 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 16 | 80 | 2 | 120 |
17:04:14 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 497 | 80 | 11 | 2025 |
17:04:19 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 497 | 80 | 4 | 240 |
17:04:24 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 451 | 80 | 13 | 1930 |
17:04:29 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 451 | 80 | 11 | 2298 |
17:04:35 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 451 | 80 | 5 | 300 |
17:04:39 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 412 | 80 | 13 | 1930 |
17:04:44 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 412 | 80 | 11 | 2298 |
17:04:49 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 412 | 80 | 5 | 300 |
17:04:54 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 608 | 80 | 13 | 1930 |
17:04:59 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 608 | 80 | 10 | 1965 |
17:05:04 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 608 | 80 | 6 | 633 |
17:05:09 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 22 | 80 | 13 | 1930 |
17:05:14 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 22 | 80 | 10 | 1965 |
17:05:19 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 22 | 80 | 6 | 633 |
17:05:24 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 110 | 80 | 13 | 1930 |
17:05:29 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 110 | 80 | 10 | 1965 |
17:05:34 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 110 | 80 | 6 | 633 |
17:05:39 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 165 | 80 | 14 | 2263 |
17:05:44 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 165 | 80 | 10 | 1965 |
17:05:49 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 165 | 80 | 5 | 300 |
17:05:54 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 112 | 80 | 13 | 1930 |
17:05:59 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 112 | 80 | 11 | 2298 |
17:06:04 | 2010-05-06 | 6 | 10.10.10.7 | 67.214.175.92 | -> | e | 112 | 80 | 3 | 180 |
17:07:32 | 2010-05-06 | 17 | 10.10.10.7 | 239.255.255.250 | -> | e | 4002 | 1900 | 2 | 350 |
17:07:38 | 2010-05-06 | 17 | 10.10.10.7 | 239.255.255.250 | -> | e | 4002 | 1900 | 1 | 175 |
17:07:41 | 2010-05-06 | 17 | 10.10.10.7 | 239.255.255.250 | -> | e | 413 | 1900 | 2 | 350 |
Packer Name |
---|
Honey Trap Log File Location |
---|
PTFB Log File Location |
---|