Analysis Date2016-02-11 22:01:01
MD5828c3194ca35fc3eef2eb1b21a0cf4de
SHA10c054e139288a15d2caf2a6f51f4bca4ab32541b

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 146bfaf10b13657e35b3832b010ed827 sha1: fc2c9ecd5e8c21122f4c5a1b4b4582dd455bd9c7 size: 182272
Section.rdata md5: 733a753b1068be6a328008513eaceb49 sha1: 787b23711365c334273f9da4d9cbb39ff48a6dc9 size: 2560
Section.data md5: dce7adba541e7662103a5ddf97c6e673 sha1: 95ff64f44e528b40c03da4b30f667ac9862c86b9 size: 15872
Section.reloc md5: 9ded0d066a43f5fb469a742e3ee0e6b6 sha1: 33487aacf280df95692772d64b0278bbc69bcebc size: 30208
Timestamp2014-09-12 05:32:04
PEhash36782d322a9d97075f7989f6fcd9960ca2187e69
IMPhash8c619bc4a3da0f34d08f850abe7c7459
AVCA (E-Trust Ino)Gen:Variant.Razy.15676
AVRisingNo Virus
AVMcafeeTrojan-FHQT!828C3194CA35
AVAvira (antivir)TR/Nivdort.A.34246
AVTwisterNo Virus
AVAd-AwareGen:Variant.Razy.15676
AVAlwil (avast)Vupa [Cryp]
AVEset (nod32)Win32/Bayrob.BA
AVGrisoft (avg)Generic37.AJJV
AVSymantecTrojan.Bayrob!gen6
AVFortinetW32/Bayrob.AQ!tr
AVBitDefenderGen:Variant.Razy.15676
AVK7Trojan ( 004dc2a31 )
AVMicrosoft Security EssentialsTrojanSpy:Win32/Nivdort.DG
AVMicroWorld (escan)Gen:Variant.Razy.15676
AVMalwareBytesNo Virus
AVAuthentiumW32/Nivdort.G.gen!Eldorado
AVEmsisoftGen:Variant.Razy.15676
AVFrisk (f-prot)W32/Nivdort.G.gen!Eldorado
AVIkarusTrojan.Win32.Bayrob
AVZillya!No Virus
AVKasperskyTrojan.Win32.Generic
AVTrend MicroNo Virus
AVVirusBlokAda (vba32)No Virus
AVCAT (quickheal)No Virus
AVBullGuardGen:Variant.Razy.15676
AVArcabit (arcavir)Gen:Variant.Razy.15676
AVClamAVNo Virus
AVDr. WebTrojan.DownLoader19.27359
AVF-SecureGen:Variant.Razy.15676

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates FileC:\rjiebkbafo\j8w81l34piptgwnxtsm.exe
Creates FileC:\rjiebkbafo\uftqsfwn1
Creates FileC:\WINDOWS\rjiebkbafo\uftqsfwn1
Deletes FileC:\WINDOWS\rjiebkbafo\uftqsfwn1
Creates ProcessC:\rjiebkbafo\j8w81l34piptgwnxtsm.exe

Process
↳ C:\rjiebkbafo\j8w81l34piptgwnxtsm.exe

RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Foundation iSCSI Collector File Builder Smart ➝
C:\rjiebkbafo\xgtvytmbifd.exe
Creates FileC:\rjiebkbafo\xgtvytmbifd.exe
Creates FileC:\rjiebkbafo\uftqsfwn1
Creates FilePIPE\lsarpc
Creates FileC:\rjiebkbafo\kypvcryvfp
Creates FileC:\WINDOWS\rjiebkbafo\uftqsfwn1
Deletes FileC:\WINDOWS\rjiebkbafo\uftqsfwn1
Creates ProcessC:\rjiebkbafo\xgtvytmbifd.exe
Creates ServiceLocation Host Center Endpoint Foundation - C:\rjiebkbafo\xgtvytmbifd.exe

Process
↳ C:\WINDOWS\system32\svchost.exe

Process
↳ Pid 804

Process
↳ Pid 848

Process
↳ C:\WINDOWS\System32\svchost.exe

Creates FileC:\WINDOWS\system32\WBEM\Logs\wbemess.log

Process
↳ Pid 1204

Process
↳ C:\WINDOWS\system32\spoolsv.exe

RegistryHKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\BeepEnabled ➝
NULL
RegistryHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\Print\TypesSupported ➝
7
RegistryHKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers\SymbolicLinkValue ➝
NULL
RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory ➝
C:\WINDOWS\System32\spool\PRINTERS\\x00

Process
↳ Pid 1864

Process
↳ Pid 1144

Process
↳ C:\rjiebkbafo\xgtvytmbifd.exe

Creates Filepipe\net\NtControlPipe10
Creates FileC:\rjiebkbafo\oqi35azfnmgh
Creates FileC:\rjiebkbafo\uftqsfwn1
Creates FileC:\rjiebkbafo\kqwtxmp.exe
Creates FileC:\rjiebkbafo\kypvcryvfp
Creates File\Device\Afd\Endpoint
Creates FileC:\WINDOWS\rjiebkbafo\uftqsfwn1
Deletes FileC:\WINDOWS\rjiebkbafo\uftqsfwn1
Creates Processwrgo9rrgmuur "c:\rjiebkbafo\xgtvytmbifd.exe"

Process
↳ C:\rjiebkbafo\xgtvytmbifd.exe

Creates FileC:\rjiebkbafo\uftqsfwn1
Creates FileC:\WINDOWS\rjiebkbafo\uftqsfwn1
Deletes FileC:\WINDOWS\rjiebkbafo\uftqsfwn1

Process
↳ wrgo9rrgmuur "c:\rjiebkbafo\xgtvytmbifd.exe"

Creates FileC:\rjiebkbafo\uftqsfwn1
Creates FileC:\WINDOWS\rjiebkbafo\uftqsfwn1
Deletes FileC:\WINDOWS\rjiebkbafo\uftqsfwn1

Network Details:

DNSfinishanother.net
Type: A
195.22.28.199
DNSfinishanother.net
Type: A
195.22.28.196
DNSfinishanother.net
Type: A
195.22.28.197
DNSfinishanother.net
Type: A
195.22.28.198
DNSsweetbusiness.net
Type: A
50.240.78.247
DNSprofiles.dexknows.com
Type: A
204.133.117.26
DNSwinterbright.net
Type: A
173.233.77.122
DNSsubjectbright.net
Type: A
208.100.26.234
DNSmelbourneit.hotkeysparking.com
Type: A
8.5.1.16
DNSmotherdaughter.net
Type: A
208.91.197.26
DNSmountainbrown.net
Type: A
195.22.28.199
DNSmountainbrown.net
Type: A
195.22.28.196
DNSmountainbrown.net
Type: A
195.22.28.197
DNSmountainbrown.net
Type: A
195.22.28.198
DNSwindowpeople.net
Type: A
208.93.105.60
DNSwinterready.net
Type: A
184.168.221.47
DNSsweetbrown.net
Type: A
50.62.102.1
DNSsweetpeople.net
Type: A
184.168.221.104
DNSlaughnation.net
Type: A
216.21.239.197
DNSsimplenation.net
Type: A
74.220.199.6
DNSwindowappear.net
Type: A
DNSwintermanner.net
Type: A
DNSsubjectmanner.net
Type: A
DNSwinteranother.net
Type: A
DNSsubjectanother.net
Type: A
DNSwinterbusiness.net
Type: A
DNSsubjectbusiness.net
Type: A
DNSwinterappear.net
Type: A
DNSsubjectappear.net
Type: A
DNSfinishmanner.net
Type: A
DNSleavemanner.net
Type: A
DNSleaveanother.net
Type: A
DNSfinishbusiness.net
Type: A
DNSleavebusiness.net
Type: A
DNSfinishappear.net
Type: A
DNSleaveappear.net
Type: A
DNSsweetmanner.net
Type: A
DNSprobablymanner.net
Type: A
DNSsweetanother.net
Type: A
DNSprobablyanother.net
Type: A
DNSprobablybusiness.net
Type: A
DNSsweetappear.net
Type: A
DNSprobablyappear.net
Type: A
DNSseveralmanner.net
Type: A
DNSmaterialmanner.net
Type: A
DNSseveralanother.net
Type: A
DNSmaterialanother.net
Type: A
DNSseveralbusiness.net
Type: A
DNSmaterialbusiness.net
Type: A
DNSseveralappear.net
Type: A
DNSmaterialappear.net
Type: A
DNSseverainstead.net
Type: A
DNSlaughinstead.net
Type: A
DNSseveraexplain.net
Type: A
DNSlaughexplain.net
Type: A
DNSseverabright.net
Type: A
DNSlaughbright.net
Type: A
DNSseverainside.net
Type: A
DNSlaughinside.net
Type: A
DNSsimpleinstead.net
Type: A
DNSmotherinstead.net
Type: A
DNSsimpleexplain.net
Type: A
DNSmotherexplain.net
Type: A
DNSsimplebright.net
Type: A
DNSmotherbright.net
Type: A
DNSsimpleinside.net
Type: A
DNSmotherinside.net
Type: A
DNSmountaininstead.net
Type: A
DNSpossibleinstead.net
Type: A
DNSmountainexplain.net
Type: A
DNSpossibleexplain.net
Type: A
DNSmountainbright.net
Type: A
DNSpossiblebright.net
Type: A
DNSmountaininside.net
Type: A
DNSpossibleinside.net
Type: A
DNSperhapsinstead.net
Type: A
DNSwindowinstead.net
Type: A
DNSperhapsexplain.net
Type: A
DNSwindowexplain.net
Type: A
DNSperhapsbright.net
Type: A
DNSwindowbright.net
Type: A
DNSperhapsinside.net
Type: A
DNSwindowinside.net
Type: A
DNSwinterinstead.net
Type: A
DNSsubjectinstead.net
Type: A
DNSwinterexplain.net
Type: A
DNSsubjectexplain.net
Type: A
DNSwinterinside.net
Type: A
DNSsubjectinside.net
Type: A
DNSfinishinstead.net
Type: A
DNSleaveinstead.net
Type: A
DNSfinishexplain.net
Type: A
DNSleaveexplain.net
Type: A
DNSfinishbright.net
Type: A
DNSleavebright.net
Type: A
DNSfinishinside.net
Type: A
DNSleaveinside.net
Type: A
DNSsweetinstead.net
Type: A
DNSprobablyinstead.net
Type: A
DNSsweetexplain.net
Type: A
DNSprobablyexplain.net
Type: A
DNSsweetbright.net
Type: A
DNSprobablybright.net
Type: A
DNSsweetinside.net
Type: A
DNSprobablyinside.net
Type: A
DNSseveralinstead.net
Type: A
DNSmaterialinstead.net
Type: A
DNSseveralexplain.net
Type: A
DNSmaterialexplain.net
Type: A
DNSseveralbright.net
Type: A
DNSmaterialbright.net
Type: A
DNSseveralinside.net
Type: A
DNSmaterialinside.net
Type: A
DNSseveraready.net
Type: A
DNSlaughready.net
Type: A
DNSseverabrown.net
Type: A
DNSlaughbrown.net
Type: A
DNSseverapeople.net
Type: A
DNSlaughpeople.net
Type: A
DNSseveradaughter.net
Type: A
DNSlaughdaughter.net
Type: A
DNSsimpleready.net
Type: A
DNSmotherready.net
Type: A
DNSsimplebrown.net
Type: A
DNSmotherbrown.net
Type: A
DNSsimplepeople.net
Type: A
DNSmotherpeople.net
Type: A
DNSsimpledaughter.net
Type: A
DNSmountainready.net
Type: A
DNSpossibleready.net
Type: A
DNSpossiblebrown.net
Type: A
DNSmountainpeople.net
Type: A
DNSpossiblepeople.net
Type: A
DNSmountaindaughter.net
Type: A
DNSpossibledaughter.net
Type: A
DNSperhapsready.net
Type: A
DNSwindowready.net
Type: A
DNSperhapsbrown.net
Type: A
DNSwindowbrown.net
Type: A
DNSperhapspeople.net
Type: A
DNSperhapsdaughter.net
Type: A
DNSwindowdaughter.net
Type: A
DNSsubjectready.net
Type: A
DNSwinterbrown.net
Type: A
DNSsubjectbrown.net
Type: A
DNSwinterpeople.net
Type: A
DNSsubjectpeople.net
Type: A
DNSwinterdaughter.net
Type: A
DNSsubjectdaughter.net
Type: A
DNSfinishready.net
Type: A
DNSleaveready.net
Type: A
DNSfinishbrown.net
Type: A
DNSleavebrown.net
Type: A
DNSfinishpeople.net
Type: A
DNSleavepeople.net
Type: A
DNSfinishdaughter.net
Type: A
DNSleavedaughter.net
Type: A
DNSsweetready.net
Type: A
DNSprobablyready.net
Type: A
DNSprobablybrown.net
Type: A
DNSprobablypeople.net
Type: A
DNSsweetdaughter.net
Type: A
DNSprobablydaughter.net
Type: A
DNSseveralready.net
Type: A
DNSmaterialready.net
Type: A
DNSseveralbrown.net
Type: A
DNSmaterialbrown.net
Type: A
DNSseveralpeople.net
Type: A
DNSmaterialpeople.net
Type: A
DNSseveraldaughter.net
Type: A
DNSmaterialdaughter.net
Type: A
DNSseveranation.net
Type: A
DNSseverasoldier.net
Type: A
DNSlaughsoldier.net
Type: A
DNSseveraplease.net
Type: A
DNSlaughplease.net
Type: A
DNSseveracondition.net
Type: A
DNSlaughcondition.net
Type: A
HTTP GEThttp://finishanother.net/index.php
User-Agent:
HTTP GEThttp://sweetbusiness.net/index.php
User-Agent:
HTTP GEThttp://windowbright.net/index.php
User-Agent:
HTTP GEThttp://winterbright.net/index.php
User-Agent:
HTTP GEThttp://subjectbright.net/index.php
User-Agent:
HTTP GEThttp://sweetinside.net/index.php
User-Agent:
HTTP GEThttp://motherdaughter.net/index.php
User-Agent:
HTTP GEThttp://mountainbrown.net/index.php
User-Agent:
HTTP GEThttp://windowpeople.net/index.php
User-Agent:
HTTP GEThttp://winterready.net/index.php
User-Agent:
HTTP GEThttp://sweetbrown.net/index.php
User-Agent:
HTTP GEThttp://sweetpeople.net/index.php
User-Agent:
HTTP GEThttp://laughnation.net/index.php
User-Agent:
HTTP GEThttp://simplenation.net/index.php
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 195.22.28.199:80
Flows TCP192.168.1.1:1032 ➝ 50.240.78.247:80
Flows TCP192.168.1.1:1033 ➝ 204.133.117.26:80
Flows TCP192.168.1.1:1034 ➝ 173.233.77.122:80
Flows TCP192.168.1.1:1035 ➝ 208.100.26.234:80
Flows TCP192.168.1.1:1036 ➝ 8.5.1.16:80
Flows TCP192.168.1.1:1037 ➝ 208.91.197.26:80
Flows TCP192.168.1.1:1038 ➝ 195.22.28.199:80
Flows TCP192.168.1.1:1039 ➝ 208.93.105.60:80
Flows TCP192.168.1.1:1040 ➝ 184.168.221.47:80
Flows TCP192.168.1.1:1041 ➝ 50.62.102.1:80
Flows TCP192.168.1.1:1042 ➝ 184.168.221.104:80
Flows TCP192.168.1.1:1043 ➝ 216.21.239.197:80
Flows TCP192.168.1.1:1044 ➝ 74.220.199.6:80

Raw Pcap

Strings