Hello,
We are currently testing out your honeyclient software and not sure if we are missing/misconfigured something(or possible no interpreting the ouput correctly), but any site that we navigate to is ID'd as having Compromised the VM. Second question what is the proper way to filter registry/system changes? I know we have to do it in the honeyclient.xml file but should we reattched the original clean image, make the changes there then disattached once again?
Thanks for the help in advance. Also below are two sample outputs from two sites that were navigated. We are using latest version and using the drone to input/queueu URLS.
www.hotmail.com
[user@miel honeyclient]# perl -Ilib bin/StartManager.pl
Starting new session...
2008-07-10 10:40:34 INFO [HoneyClient::Manager::VM::init] (lib/HoneyClient/Manager/VM.pm:757) - Initializing VM daemon at PID: 9402
2008-07-10 10:40:35 INFO [HoneyClient::Manager::VM::Clone::new] (lib/HoneyClient/Manager/VM/Clone.pm:885) - Setting VM (/vm/master/master.vmx) as master.
2008-07-10 10:40:47 INFO [HoneyClient::Manager::VM::Clone::_init] (lib/HoneyClient/Manager/VM/Clone.pm:580) - Quick cloning master VM (/vm/master/master.vmx).
2008-07-10 10:41:50 INFO [HoneyClient::Manager::VM::Clone::_init] (lib/HoneyClient/Manager/VM/Clone.pm:649) - Initialized clone VM (848e47dd4f38389c8f13db9705) using IP (10.0.0.137) and MAC (00:0c:29:25:e6:a8).
VM State Table:
$VAR1 = {
'848e47dd4f38389c8f13db9705' => {
'sources' => {
'00:0c:29:25:e6:a8' => {
'10.0.0.137' => {
'tcp' => [
80,
443
]
}
}
}
}
};
Cannot encode unnamed element as 'hash'. Will be encoded as 'map' instead
Cannot encode 'sources' element as 'hash'. Will be encoded as 'map' instead
Cannot encode 'value' element as 'hash'. Will be encoded as 'map' instead
2008-07-10 10:42:22 INFO [HoneyClient::Manager::get_urls] (lib/HoneyClient/Manager.pm:974) - Waiting for new URLs from database.
Calling updateState()...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 0,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
VM Integrity Check: OK!
Cannot encode unnamed element as 'hash'. Will be encoded as 'map' instead
Cannot encode 'sources' element as 'hash'. Will be encoded as 'map' instead
Cannot encode 'value' element as 'hash'. Will be encoded as 'map' instead
VM State Table:
$VAR1 = {
'848e47dd4f38389c8f13db9705' => {
'targets' => {
'hotmail.com' => {
'tcp' => [
80
]
}
},
'sources' => {
'00:0c:29:25:e6:a8' => {
'10.0.0.137' => {
'tcp' => [
80,
443
]
}
}
}
}
};
Cannot encode unnamed element as 'hash'. Will be encoded as 'map' instead
Cannot encode 'sources' element as 'hash'. Will be encoded as 'map' instead
Cannot encode 'value' element as 'hash'. Will be encoded as 'map' instead
Calling run()...
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 0,
'is_running' => 0,
'links_processed' => 1,
'percent_complete' => '100.00%',
'is_compromised' => 1,
'relative_links_remaining' => 0,
'links_total' => 1,
'fingerprint' => {
'last_resource' => 'http://hotmail.com/',
'time_at' => '2008-07-10 10:42:07.515',
'os_processes' => [
{
'pid' => '4',
'regkeys' => [
{
'value_type' => 'REG_SZ',
'value_name' => 'ActiveService',
'value' => 'HTTP',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Enum\\Root\\LEGACY_HTTP\\0000\\Control',
'time_at' => '2008-07-10 10:42:07.515',
'event' => 'SetValueKey'
}
],
'name' => 'System',
'process_files' => []
},
{
'pid' => '668',
'regkeys' => [
{
'value_type' => 'REG_SZ',
'value_name' => 'ActiveService',
'value' => 'SSDPSRV',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Enum\\Root\\LEGACY_SSDPSRV\\0000\\Control',
'time_at' => '2008-07-10 10:42:07.562',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_DWORD',
'value_name' => '',
'value' => '9',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Control\\ServiceCurrent',
'time_at' => '2008-07-10 10:42:07.937',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_SZ',
'value_name' => 'ActiveService',
'value' => 'ALG',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Enum\\Root\\LEGACY_ALG\\0000\\Control',
'time_at' => '2008-07-10 10:42:08.484',
'event' => 'SetValueKey'
}
],
'name' => 'C:\\WINDOWS\\system32\\services.exe',
'process_files' => []
},
{
'pid' => '1644',
'regkeys' => [
{
'value_type' => 'REG_SZ',
'value_name' => 'Cache',
'value' => 'C:\\Documents and Settings\\admin\\Local Settings\\Temporary Internet Files', 'name' => 'HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders',
'time_at' => '2008-07-10 10:42:07.640',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_SZ',
'value_name' => 'Cookies',
'value' => 'C:\\Documents and Settings\\admin\\Cookies',
'name' => 'HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders',
'time_at' => '2008-07-10 10:42:07.656',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_SZ',
'value_name' => 'History',
'value' => 'C:\\Documents and Settings\\admin\\Local Settings\\History',
'name' => 'HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders',
'time_at' => '2008-07-10 10:42:07.656',
'event' => 'SetValueKey'
}
],
'name' => 'C:\\Program Files\\Messenger\\msmsgs.exe',
'process_files' => []
},
{
'pid' => '1024',
'regkeys' => [
{
'value_type' => 'REG_SZ',
'value_name' => 'PnpInstanceID',
'value' => 'PCI\\VEN_1022&DEV_2000&SUBSYS_20001022&REV_10\\3&61AAA01&0&88',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Control\\Network\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\{BA9EBA5F-172D-4013-90E5-59D0853B0A49}\\Connection',
'time_at' => '2008-07-10 10:42:07.640',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_SZ',
'value_name' => 'PnpInstanceID',
'value' => 'PCI\\VEN_1022&DEV_2000&SUBSYS_20001022&REV_10\\3&61AAA01&0&88',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Control\\Network\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\{BA9EBA5F-172D-4013-90E5-59D0853B0A49}\\Connection',
'time_at' => '2008-07-10 10:42:07.656',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_DWORD',
'value_name' => 'Epoch',
'value' => '4d',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Services\\SharedAccess\\Epoch',
'time_at' => '2008-07-10 10:42:10.328',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_DWORD',
'value_name' => 'Epoch',
'value' => '4e',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Services\\SharedAccess\\Epoch',
'time_at' => '2008-07-10 10:42:10.328',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_DWORD',
'value_name' => 'Epoch',
'value' => '4f',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Services\\SharedAccess\\Epoch',
'time_at' => '2008-07-10 10:42:10.406',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_SZ',
'value_name' => 'PnpInstanceID',
'value' => 'PCI\\VEN_1022&DEV_2000&SUBSYS_20001022&REV_10\\3&61AAA01&0&88',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Control\\Network\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\{BA9EBA5F-172D-4013-90E5-59D0853B0A49}\\Connection',
'time_at' => '2008-07-10 10:42:10.421',
'event' => 'SetValueKey'
}
],
'name' => 'C:\\WINDOWS\\system32\\svchost.exe',
'process_files' => []
},
{
'pid' => '1548',
'regkeys' => [
{
'value_type' => 'REG_BINARY',
'value_name' => 'LogonTime',
'value' => '8675ec249be2c81',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Control\\Print\\Providers',
'time_at' => '2008-07-10 10:42:14.734',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_LINK',
'value_name' => 'SymbolicLinkValue',
'value' => '\\Registry\\Machine\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Print\\Printers',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Control\\Print\\Printers',
'time_at' => '2008-07-10 10:42:14.765',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_DWORD',
'value_name' => 'TypesSupported',
'value' => '7',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Services\\Eventlog\\System\\Print',
'time_at' => '2008-07-10 10:42:14.765',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_DWORD',
'value_name' => 'TypesSupported',
'value' => '7',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Services\\Eventlog\\System\\TCPMon',
'time_at' => '2008-07-10 10:42:14.796',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_SZ',
'value_name' => 'EventMessageFile',
'value' => '%SystemRoot%\\System32\\tcpmon.dll',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Services\\Eventlog\\System\\TCPMon',
'time_at' => '2008-07-10 10:42:14.796',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_DWORD',
'value_name' => 'BeepEnabled',
'value' => '0',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Control\\Print',
'time_at' => '2008-07-10 10:42:14.796',
'event' => 'SetValueKey'
}
],
'name' => 'C:\\WINDOWS\\system32\\spoolsv.exe',
'process_files' => []
},
{
'pid' => '1660',
'regkeys' => [
{
'value_type' => 'REG_DWORD',
'value_name' => 'ProxyEnable',
'value' => '0',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Hardware Profiles\\0001\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings',
'time_at' => '2008-07-10 10:42:28.359',
'event' => 'SetValueKey'
}
],
'name' => 'C:\\Program Files\\Internet Explorer\\iexplore.exe',
'process_files' => []
}
]
}
};
WARNING: VM HAS BEEN COMPROMISED!
2008-07-10 10:42:50 WARN [HoneyClient::Manager::runSession] (lib/HoneyClient/Manager.pm:760) - VM Compromised. Last Resource (http://hotmail.com/)
2008-07-10 10:42:50 INFO [HoneyClient::Manager::runSession] (lib/HoneyClient/Manager.pm:767) - Saving fingerprint to 'fingerprint.dump'.
2008-07-10 10:42:51 INFO [HoneyClient::Manager::runSession] (lib/HoneyClient/Manager.pm:779) - Archiving VM...
2008-07-10 10:43:02 INFO [HoneyClient::Manager::VM::snapshotVM] (lib/HoneyClient/Manager/VM.pm:4418) - Snapshotting VM (/vm/clones/848e47dd4f38389c8f13db9705/master.vmx) to (/vm/snapshots/848e47dd4f38389c8f13db9705-20080710T104302.tar.gz).
2008-07-10 10:43:02 INFO [HoneyClient::Manager::runSession] (lib/HoneyClient/Manager.pm:785) - Saving URL History to Database.
2008-07-10 10:43:03 INFO [HoneyClient::Manager::insert_url_history] (lib/HoneyClient/Manager.pm:926) - 1 URL(s) Inserted.
2008-07-10 10:43:04 INFO [HoneyClient::Manager::runSession] (lib/HoneyClient/Manager.pm:796) - Inserting Fingerprint Into Database.
2008-07-10 10:43:04 INFO [HoneyClient::Manager::runSession] (lib/HoneyClient/Manager.pm:805) - Database Insert Successful.
Starting new session...
2008-07-10 10:43:06 INFO [HoneyClient::Manager::VM::Clone::new] (lib/HoneyClient/Manager/VM/Clone.pm:885) - Setting VM (/vm/master/master.vmx) as master.
2008-07-10 10:43:20 INFO [HoneyClient::Manager::VM::Clone::_init] (lib/HoneyClient/Manager/VM/Clone.pm:580) - Quick cloning master VM (/vm/master/master.vmx).
/bin/tar: 848e47dd4f38389c8f13db9705/master.vmem: file changed as we read it
2008-07-10 10:44:12 INFO [HoneyClient::Manager::VM::Clone::_init] (lib/HoneyClient/Manager/VM/Clone.pm:649) - Initialized clone VM (31cc179d1ca6bf6fc59a6f5b14) using IP (10.0.0.138) and MAC (00:0c:29:e4:1e:dc).
VM State Table:
$VAR1 = {
'31cc179d1ca6bf6fc59a6f5b14' => {
'sources' => {
'00:0c:29:e4:1e:dc' => {
'10.0.0.138' => {
'tcp' => [
80,
443
]
}
}
}
}
};
Cannot encode unnamed element as 'hash'. Will be encoded as 'map' instead
Cannot encode 'sources' element as 'hash'. Will be encoded as 'map' instead
Cannot encode 'value' element as 'hash'. Will be encoded as 'map' instead
2008-07-10 10:44:45 INFO [HoneyClient::Manager::get_urls] (lib/HoneyClient/Manager.pm:974) - Waiting for new URLs from database.
www.google.com
2008-07-10 10:44:45 INFO [HoneyClient::Manager::get_urls] (lib/HoneyClient/Manager.pm:974) - Waiting for new URLs from database.
Calling updateState()...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 0,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
VM Integrity Check: OK!
Cannot encode unnamed element as 'hash'. Will be encoded as 'map' instead
Cannot encode 'sources' element as 'hash'. Will be encoded as 'map' instead
Cannot encode 'value' element as 'hash'. Will be encoded as 'map' instead
VM State Table:
$VAR1 = {
'31cc179d1ca6bf6fc59a6f5b14' => {
'targets' => {
'www.google.com' => {
'tcp' => [
80
]
}
},
'sources' => {
'00:0c:29:e4:1e:dc' => {
'10.0.0.138' => {
'tcp' => [
80,
443
]
}
}
}
}
};
Cannot encode unnamed element as 'hash'. Will be encoded as 'map' instead
Cannot encode 'sources' element as 'hash'. Will be encoded as 'map' instead
Cannot encode 'value' element as 'hash'. Will be encoded as 'map' instead
Calling run()...
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 1,
'is_running' => 1,
'links_processed' => 0,
'percent_complete' => '0.00%',
'is_compromised' => 0,
'relative_links_remaining' => 1,
'links_total' => 1
};
Sleeping for 2s...
Calling getStatus()...
Result:
$VAR1 = {
'links_remaining' => 0,
'is_running' => 0,
'links_processed' => 1,
'percent_complete' => '100.00%',
'is_compromised' => 1,
'relative_links_remaining' => 0,
'links_total' => 1,
'fingerprint' => {
'last_resource' => 'http://www.google.com/',
'time_at' => '2008-07-10 10:44:31.781',
'os_processes' => [
{
'pid' => '4',
'regkeys' => [
{
'value_type' => 'REG_SZ',
'value_name' => 'ActiveService',
'value' => 'HTTP',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Enum\\Root\\LEGACY_HTTP\\0000\\Control',
'time_at' => '2008-07-10 10:44:31.781',
'event' => 'SetValueKey'
}
],
'name' => 'System',
'process_files' => []
},
{
'pid' => '668',
'regkeys' => [
{
'value_type' => 'REG_SZ',
'value_name' => 'ActiveService',
'value' => 'SSDPSRV',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Enum\\Root\\LEGACY_SSDPSRV\\0000\\Control',
'time_at' => '2008-07-10 10:44:31.890',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_DWORD',
'value_name' => '',
'value' => '9',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Control\\ServiceCurrent',
'time_at' => '2008-07-10 10:44:32.62',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_SZ',
'value_name' => 'ActiveService',
'value' => 'ALG',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Enum\\Root\\LEGACY_ALG\\0000\\Control',
'time_at' => '2008-07-10 10:44:32.328',
'event' => 'SetValueKey'
}
],
'name' => 'C:\\WINDOWS\\system32\\services.exe',
'process_files' => []
},
{
'pid' => '1040',
'regkeys' => [
{
'value_type' => 'REG_SZ',
'value_name' => 'PnpInstanceID',
'value' => 'PCI\\VEN_1022&DEV_2000&SUBSYS_20001022&REV_10\\3&61AAA01&0&88',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Control\\Network\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\{BA9EBA5F-172D-4013-90E5-59D0853B0A49}\\Connection',
'time_at' => '2008-07-10 10:44:31.906',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_SZ',
'value_name' => 'PnpInstanceID',
'value' => 'PCI\\VEN_1022&DEV_2000&SUBSYS_20001022&REV_10\\3&61AAA01&0&88',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Control\\Network\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\{BA9EBA5F-172D-4013-90E5-59D0853B0A49}\\Connection',
'time_at' => '2008-07-10 10:44:31.906',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_DWORD',
'value_name' => 'Epoch',
'value' => '4d',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Services\\SharedAccess\\Epoch',
'time_at' => '2008-07-10 10:44:33.78',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_DWORD',
'value_name' => 'Epoch',
'value' => '4e',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Services\\SharedAccess\\Epoch',
'time_at' => '2008-07-10 10:44:33.93',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_DWORD',
'value_name' => 'Epoch',
'value' => '4f',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Services\\SharedAccess\\Epoch',
'time_at' => '2008-07-10 10:44:33.93',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_DWORD',
'value_name' => 'Epoch',
'value' => '50',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Services\\SharedAccess\\Epoch',
'time_at' => '2008-07-10 10:44:33.468',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_DWORD',
'value_name' => 'Epoch',
'value' => '51',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Services\\SharedAccess\\Epoch',
'time_at' => '2008-07-10 10:44:33.750',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_SZ',
'value_name' => 'PnpInstanceID',
'value' => 'PCI\\VEN_1022&DEV_2000&SUBSYS_20001022&REV_10\\3&61AAA01&0&88',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Control\\Network\\{4D36E972-E325-11CE-BFC1-08002BE10318}\\{BA9EBA5F-172D-4013-90E5-59D0853B0A49}\\Connection',
'time_at' => '2008-07-10 10:44:33.765',
'event' => 'SetValueKey'
}
],
'name' => 'C:\\WINDOWS\\system32\\svchost.exe',
'process_files' => []
},
{
'pid' => '1648',
'regkeys' => [
{
'value_type' => 'REG_SZ',
'value_name' => 'Cache',
'value' => 'C:\\Documents and Settings\\admin\\Local Settings\\Temporary Internet Files', 'name' => 'HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders',
'time_at' => '2008-07-10 10:44:32.15',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_SZ',
'value_name' => 'Cookies',
'value' => 'C:\\Documents and Settings\\admin\\Cookies',
'name' => 'HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders',
'time_at' => '2008-07-10 10:44:32.78',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_SZ',
'value_name' => 'History',
'value' => 'C:\\Documents and Settings\\admin\\Local Settings\\History',
'name' => 'HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders',
'time_at' => '2008-07-10 10:44:32.78',
'event' => 'SetValueKey'
}
],
'name' => 'C:\\Program Files\\Messenger\\msmsgs.exe',
'process_files' => []
},
{
'pid' => '1540',
'regkeys' => [
{
'value_type' => 'REG_BINARY',
'value_name' => 'LogonTime',
'value' => 'f4f170799be2c81',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Control\\Print\\Providers',
'time_at' => '2008-07-10 10:44:36.531',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_LINK',
'value_name' => 'SymbolicLinkValue',
'value' => '\\Registry\\Machine\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Print\\Printers',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Control\\Print\\Printers',
'time_at' => '2008-07-10 10:44:36.578',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_DWORD',
'value_name' => 'TypesSupported',
'value' => '7',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Services\\Eventlog\\System\\Print',
'time_at' => '2008-07-10 10:44:36.578',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_DWORD',
'value_name' => 'TypesSupported',
'value' => '7',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Services\\Eventlog\\System\\TCPMon',
'time_at' => '2008-07-10 10:44:36.609',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_SZ',
'value_name' => 'EventMessageFile',
'value' => '%SystemRoot%\\System32\\tcpmon.dll',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Services\\Eventlog\\System\\TCPMon',
'time_at' => '2008-07-10 10:44:36.609',
'event' => 'SetValueKey'
},
{
'value_type' => 'REG_DWORD',
'value_name' => 'BeepEnabled',
'value' => '0',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Control\\Print',
'time_at' => '2008-07-10 10:44:36.609',
'event' => 'SetValueKey'
}
],
'name' => 'C:\\WINDOWS\\system32\\spoolsv.exe',
'process_files' => []
},
{
'pid' => '544',
'regkeys' => [
{
'value_type' => 'REG_DWORD',
'value_name' => 'ProxyEnable',
'value' => '0',
'name' => 'HKLM\\SYSTEM\\ControlSet003\\Hardware Profiles\\0001\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings',
'time_at' => '2008-07-10 10:47:26.890',
'event' => 'SetValueKey'
}
],
'name' => 'C:\\Program Files\\Internet Explorer\\iexplore.exe',
'process_files' => []
}
]
}
};
WARNING: VM HAS BEEN COMPROMISED!
2008-07-10 10:47:48 WARN [HoneyClient::Manager::runSession] (lib/HoneyClient/Manager.pm:760) - VM Compromised. Last Resource (http://www.google.com/)
2008-07-10 10:47:48 INFO [HoneyClient::Manager::runSession] (lib/HoneyClient/Manager.pm:767) - Saving fingerprint to 'fingerprint.dump'.
2008-07-10 10:47:49 INFO [HoneyClient::Manager::runSession] (lib/HoneyClient/Manager.pm:779) - Archiving VM...
2008-07-10 10:48:00 INFO [HoneyClient::Manager::VM::snapshotVM] (lib/HoneyClient/Manager/VM.pm:4418) - Snapshotting VM (/vm/clones/31cc179d1ca6bf6fc59a6f5b14/master.vmx) to (/vm/snapshots/31cc179d1ca6bf6fc59a6f5b14-20080710T104800.tar.gz).
2008-07-10 10:48:00 INFO [HoneyClient::Manager::runSession] (lib/HoneyClient/Manager.pm:785) - Saving URL History to Database.
2008-07-10 10:48:01 INFO [HoneyClient::Manager::insert_url_history] (lib/HoneyClient/Manager.pm:926) - 1 URL(s) Inserted.
2008-07-10 10:48:02 INFO [HoneyClient::Manager::runSession] (lib/HoneyClient/Manager.pm:796) - Inserting Fingerprint Into Database.
2008-07-10 10:48:02 INFO [HoneyClient::Manager::runSession] (lib/HoneyClient/Manager.pm:805) - Database Insert Successful.
Starting new session...