+ | 21-MAY-2016 21:46 | Payment Processing Server | Windows Server 2008 System Files | Modified | High | C:\Windows\shell.exe |
Attribute | Expected Value | Actual Value |
Attributes | Archive | Hidden, Archive |
Permissions |
DACL: D:AI(A;ID;FA;;;SY)(A;ID;FA;;;BA)(A;ID;0x1200a9;;;BU)
Account SID: S-1-5-18
Account Name: NT AUTHORITY\SYSTEM
Type: Allow
Inherited: Yes
Inheritance: None
Rights: FullControl
Account SID: S-1-5-32-544
Account Name: BUILTIN\Administrators
Type: Allow
Inherited: Yes
Inheritance: None
Rights: FullControl
Account SID: S-1-5-32-545
Account Name: BUILTIN\Users
Type: Allow
Inherited: Yes
Inheritance: None
Rights: ReadAndExecute, Synchronize |
DACL: D:(A;;FA;;;WD)(A;ID;FA;;;SY)(A;ID;FA;;;BA)(A;ID;0x1200a9;;;BU)
Account SID: S-1-1-0
Account Name: Everyone
Type: Allow
Inherited: No
Inheritance: None
Rights: FullControl
Account SID: S-1-5-18
Account Name: NT AUTHORITY\SYSTEM
Type: Allow
Inherited: Yes
Inheritance: None
Rights: FullControl
Account SID: S-1-5-32-544
Account Name: BUILTIN\Administrators
Type: Allow
Inherited: Yes
Inheritance: None
Rights: FullControl
Account SID: S-1-5-32-545
Account Name: BUILTIN\Users
Type: Allow
Inherited: Yes
Inheritance: None
Rights: ReadAndExecute, Synchronize |
|
+ | 21-MAY-2016 21:46 | Payment Processing Server | Windows Server 2008 System Files | Modified | High | C:\Windows\system32\comms.sys |
Attribute | Expected Value | Actual Value |
---|
Modified Time | 2015-06-07T19:56:00.0000000Z | 2016-05-21T20:46:04.3302659Z | Size | 38 | 127 | CRC | FC0C263E | FE4CA530 | Hash | 9B845F457388D9C34BB4F1C36C14B143FCEBD65FF034EC6F3C6CD41F632D5471 | C5369BFEB9367586342796BDAEDC6CE4A6E76616BE10BAB9402BD891392FF42D |
|
+ | 21-MAY-2016 21:46 | Payment Processing Server | Windows Server 2008 System Files | Modified | High | C:\Windows\system32\ip_stack.dll |
Attribute | Expected Value | Actual Value |
---|
Modified Time | 2015-06-07T19:56:00.0000000Z | 2016-05-21T20:46:04.3302659Z | Size | 38 | 127 | CRC | FC0C263E | FE4CA530 | Hash | 9B845F457388D9C34BB4F1C36C14B143FCEBD65FF034EC6F3C6CD41F632D5471 | C5369BFEB9367586342796BDAEDC6CE4A6E76616BE10BAB9402BD891392FF42D |
|
+ | 21-MAY-2016 21:46 | Payment Processing Server | Windows Server 2008 System Files | Added | High | C:\Windows\system32\keylogger.sys |
Attribute | Expected Value | Actual Value |
Created Time | | 2016-05-21T20:46:04.2834658Z | Modified Time | | 2016-05-21T20:46:04.2834658Z | Size | | 41 | CRC | | FD4BCF7E | Hash | | 15AD402CE3528BA48C2F10CC0E9AD8E7B7C6E0426B77CC4A15F86CD394A200D9 |
Owner | |
Account SID: S-1-5-32-544
Account Name: BUILTIN\Administrators |
Primary Group | |
Account SID: S-1-5-21-305035777-899029998-720635935-513
Account Name: KVAERNER-NO\Domain Users | Attributes | | Archive |
Permissions | |
DACL: D:AI(A;ID;FA;;;SY)(A;ID;FA;;;BA)(A;ID;0x1200a9;;;BU)
Account SID: S-1-5-18
Account Name: NT AUTHORITY\SYSTEM
Type: Allow
Inherited: Yes
Inheritance: None
Rights: FullControl
Account SID: S-1-5-32-544
Account Name: BUILTIN\Administrators
Type: Allow
Inherited: Yes
Inheritance: None
Rights: FullControl
Account SID: S-1-5-32-545
Account Name: BUILTIN\Users
Type: Allow
Inherited: Yes
Inheritance: None
Rights: ReadAndExecute, Synchronize | Audit Rules | | SACL: |
|
+ | 21-MAY-2016 21:46 | Payment Processing Server | Windows Server 2008 System Files | Modified | High | C:\Windows\system32\logon.exe |
Attribute | Expected Value | Actual Value |
---|
Modified Time | 2015-06-07T19:56:00.0000000Z | 2016-05-21T20:46:04.3458659Z | Size | 38 | 127 | CRC | FC0C263E | FE4CA530 | Hash | 9B845F457388D9C34BB4F1C36C14B143FCEBD65FF034EC6F3C6CD41F632D5471 | C5369BFEB9367586342796BDAEDC6CE4A6E76616BE10BAB9402BD891392FF42D | Attributes | Archive | ReadOnly, Archive |
|
+ | 21-MAY-2016 21:46 | Payment Processing Server | Windows Server 2008 Network Files | Modified | Medium | C:\Windows\system32\drivers\etc\hosts |
Attribute | Expected Value | Actual Value |
Modified Time | 2015-06-07T19:56:00.0000000Z | 2016-05-21T20:46:04.2834658Z | Size | 26 | 28 | CRC | FE16DFAE | FF18C403 | Hash | F0EF3092BE99D84879D21FF98A32EFCBD9BC27A901AB01E719B9386E005FFD18 | 4EE7C8230D51DFDF604045FCA3F3F17C87067C008314EA8CB2DF42ED1E0E1C87 |
Permissions |
DACL: D:AI(A;ID;FA;;;SY)(A;ID;FA;;;BA)(A;ID;0x1200a9;;;BU)
Account SID: S-1-5-18
Account Name: NT AUTHORITY\SYSTEM
Type: Allow
Inherited: Yes
Inheritance: None
Rights: FullControl
Account SID: S-1-5-32-544
Account Name: BUILTIN\Administrators
Type: Allow
Inherited: Yes
Inheritance: None
Rights: FullControl
Account SID: S-1-5-32-545
Account Name: BUILTIN\Users
Type: Allow
Inherited: Yes
Inheritance: None
Rights: ReadAndExecute, Synchronize |
DACL: D:(A;;FA;;;WD)(A;ID;FA;;;SY)(A;ID;FA;;;BA)(A;ID;0x1200a9;;;BU)
Account SID: S-1-1-0
Account Name: Everyone
Type: Allow
Inherited: No
Inheritance: None
Rights: FullControl
Account SID: S-1-5-18
Account Name: NT AUTHORITY\SYSTEM
Type: Allow
Inherited: Yes
Inheritance: None
Rights: FullControl
Account SID: S-1-5-32-544
Account Name: BUILTIN\Administrators
Type: Allow
Inherited: Yes
Inheritance: None
Rights: FullControl
Account SID: S-1-5-32-545
Account Name: BUILTIN\Users
Type: Allow
Inherited: Yes
Inheritance: None
Rights: ReadAndExecute, Synchronize |
|
+ | 21-MAY-2016 21:46 | File Server | Windows Server 2012 System Files | Modified | High | C:\Windows\system32\ip_stack.dll |
Attribute | Expected Value | Actual Value |
---|
Modified Time | 2015-06-07T19:56:00.0000000Z | 2016-05-21T20:46:04.4238661Z | Size | 38 | 127 | CRC | FC0C263E | FE4CA530 | Hash | 9B845F457388D9C34BB4F1C36C14B143FCEBD65FF034EC6F3C6CD41F632D5471 | C5369BFEB9367586342796BDAEDC6CE4A6E76616BE10BAB9402BD891392FF42D | Attributes | Archive | Hidden, Archive |
|
+ | 21-MAY-2016 21:46 | File Server | Windows Server 2012 Network Files | Modified | Medium | C:\Windows\system32\drivers\etc\hosts |
Attribute | Expected Value | Actual Value |
Permissions |
DACL: D:AI(A;ID;FA;;;SY)(A;ID;FA;;;BA)(A;ID;0x1200a9;;;BU)
Account SID: S-1-5-18
Account Name: NT AUTHORITY\SYSTEM
Type: Allow
Inherited: Yes
Inheritance: None
Rights: FullControl
Account SID: S-1-5-32-544
Account Name: BUILTIN\Administrators
Type: Allow
Inherited: Yes
Inheritance: None
Rights: FullControl
Account SID: S-1-5-32-545
Account Name: BUILTIN\Users
Type: Allow
Inherited: Yes
Inheritance: None
Rights: ReadAndExecute, Synchronize |
DACL: D:(A;;FA;;;WD)(A;ID;FA;;;SY)(A;ID;FA;;;BA)(A;ID;0x1200a9;;;BU)
Account SID: S-1-1-0
Account Name: Everyone
Type: Allow
Inherited: No
Inheritance: None
Rights: FullControl
Account SID: S-1-5-18
Account Name: NT AUTHORITY\SYSTEM
Type: Allow
Inherited: Yes
Inheritance: None
Rights: FullControl
Account SID: S-1-5-32-544
Account Name: BUILTIN\Administrators
Type: Allow
Inherited: Yes
Inheritance: None
Rights: FullControl
Account SID: S-1-5-32-545
Account Name: BUILTIN\Users
Type: Allow
Inherited: Yes
Inheritance: None
Rights: ReadAndExecute, Synchronize |
|