Analysis Date2016-02-11 05:11:07
MD56652394a249a1f6c9a40069aa9c51564
SHA11df63b66063b3d90257f553d7f96388e65524500

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: cb51ce9274b7e982b7b09b1fdb6bdef1 sha1: 09b482b5cd7e5efb33bc824f124e7feaa0c61cdc size: 198144
Section.rdata md5: ba680e96c4c1ad43e516e0abeb1e9501 sha1: 65f297d39dc8fea0859c3630fe3c4c1a9c86cd1d size: 3072
Section.data md5: c3a46389fb6c939c2ba55c00863daa0d sha1: c271b36baea5f3ed3b2893aada6e449f146c8eea size: 15872
Section.reloc md5: 36b5ea2832a1ed857a894cd2aa810ec7 sha1: ed8ba91ebc4656819b8c4e26005b68153438b09b size: 30720
Timestamp2014-09-07 06:53:54
PEhash140ef827bc7cfb7f11807bde59b7267340d5f9b9
IMPhashac7b832f26281c6f898be6a7c93f1844
AVCA (E-Trust Ino)Gen:Variant.Razy.15460
AVRisingNo Virus
AVMcafeeTrojan-FHRG!6652394A249A
AVAvira (antivir)TR/Nivdort.A.35051
AVTwisterNo Virus
AVAd-AwareGen:Variant.Razy.15460
AVAlwil (avast)Vupa [Cryp]
AVEset (nod32)Win32/Bayrob.AT.gen
AVGrisoft (avg)Win32/Heur
AVSymantecTrojan.Bayrob!gen6
AVFortinetW32/Bayrob.AQ!tr
AVBitDefenderGen:Variant.Razy.15460
AVK7Trojan ( 004dc2a31 )
AVMicrosoft Security EssentialsTrojanSpy:Win32/Nivdort.DD
AVMicroWorld (escan)Gen:Variant.Razy.15460
AVMalwareBytesNo Virus
AVAuthentiumW32/Nivdort.H.gen!Eldorado
AVEmsisoftGen:Variant.Razy.15460
AVFrisk (f-prot)W32/Nivdort.H.gen!Eldorado
AVIkarusTrojan.Win32.Bayrob
AVZillya!No Virus
AVKasperskyTrojan.Win32.Generic
AVTrend MicroNo Virus
AVVirusBlokAda (vba32)No Virus
AVCAT (quickheal)TrojanSpy.Nivdort.r4
AVBullGuardGen:Variant.Razy.15460
AVArcabit (arcavir)Gen:Variant.Razy.15460
AVClamAVNo Virus
AVDr. WebTrojan.DownLoader19.26672
AVF-SecureGen:Variant.Razy.15460

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates FileC:\njsidajiufie\nujm1kosxu2moivdwy.exe
Creates FileC:\WINDOWS\njsidajiufie\epdd4y
Creates FileC:\njsidajiufie\epdd4y
Deletes FileC:\WINDOWS\njsidajiufie\epdd4y
Creates ProcessC:\njsidajiufie\nujm1kosxu2moivdwy.exe

Process
↳ C:\njsidajiufie\nujm1kosxu2moivdwy.exe

RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\NGEN Gateway File Grouping Themes Quality PC ➝
C:\njsidajiufie\ownbeet.exe
Creates FileC:\njsidajiufie\kfbxeixduvmp
Creates FilePIPE\lsarpc
Creates FileC:\WINDOWS\njsidajiufie\epdd4y
Creates FileC:\njsidajiufie\ownbeet.exe
Creates FileC:\njsidajiufie\epdd4y
Deletes FileC:\WINDOWS\njsidajiufie\epdd4y
Creates ProcessC:\njsidajiufie\ownbeet.exe
Creates ServiceReports BitLocker Health Process Counter - C:\njsidajiufie\ownbeet.exe

Process
↳ C:\WINDOWS\system32\svchost.exe

Process
↳ Pid 812

Process
↳ Pid 856

Process
↳ C:\WINDOWS\System32\svchost.exe

Creates FileC:\WINDOWS\system32\WBEM\Logs\wbemess.log

Process
↳ Pid 1212

Process
↳ C:\WINDOWS\system32\spoolsv.exe

Process
↳ Pid 1856

Process
↳ Pid 1172

Process
↳ C:\njsidajiufie\ownbeet.exe

Creates FileC:\njsidajiufie\kfbxeixduvmp
Creates Filepipe\net\NtControlPipe10
Creates FileC:\njsidajiufie\csqlxrytq
Creates File\Device\Afd\Endpoint
Creates FileC:\WINDOWS\njsidajiufie\epdd4y
Creates FileC:\njsidajiufie\vfyfwrmt.exe
Creates FileC:\njsidajiufie\epdd4y
Deletes FileC:\WINDOWS\njsidajiufie\epdd4y
Creates Processhvfgf6r2aaob "c:\njsidajiufie\ownbeet.exe"

Process
↳ C:\njsidajiufie\ownbeet.exe

Creates FileC:\WINDOWS\njsidajiufie\epdd4y
Creates FileC:\njsidajiufie\epdd4y
Deletes FileC:\WINDOWS\njsidajiufie\epdd4y

Process
↳ hvfgf6r2aaob "c:\njsidajiufie\ownbeet.exe"

Creates FileC:\WINDOWS\njsidajiufie\epdd4y
Creates FileC:\njsidajiufie\epdd4y
Deletes FileC:\WINDOWS\njsidajiufie\epdd4y

Network Details:

DNSsweetwomen.net
Type: A
184.168.221.104
DNSmaterialpaint.net
Type: A
208.100.26.234
DNSsimplestream.net
Type: A
141.8.225.124
DNSmountainstream.net
Type: A
207.148.248.143
DNSmountainbottle.net
Type: A
195.22.28.198
DNSmountainbottle.net
Type: A
195.22.28.197
DNSmountainbottle.net
Type: A
195.22.28.196
DNSmountainbottle.net
Type: A
195.22.28.199
DNSwindowstream.net
Type: A
216.21.239.197
DNSsweetnothing.net
Type: A
72.52.4.119
DNSmotheranother.net
Type: A
50.63.202.39
DNSsimplebusiness.net
Type: A
72.52.4.119
DNSmountainmanner.net
Type: A
208.100.26.234
DNSsweetbusiness.net
Type: A
50.240.78.247
DNSprofiles.dexknows.com
Type: A
204.133.117.26
DNSprobablycourse.net
Type: A
DNSprobablywomen.net
Type: A
DNSseveralclean.net
Type: A
DNSmaterialclean.net
Type: A
DNSseveralpaint.net
Type: A
DNSseveralcourse.net
Type: A
DNSmaterialcourse.net
Type: A
DNSseveralwomen.net
Type: A
DNSmaterialwomen.net
Type: A
DNSseverastream.net
Type: A
DNSlaughstream.net
Type: A
DNSseveranothing.net
Type: A
DNSlaughnothing.net
Type: A
DNSseverabottle.net
Type: A
DNSlaughbottle.net
Type: A
DNSseveradivide.net
Type: A
DNSlaughdivide.net
Type: A
DNSmotherstream.net
Type: A
DNSsimplenothing.net
Type: A
DNSmothernothing.net
Type: A
DNSsimplebottle.net
Type: A
DNSmotherbottle.net
Type: A
DNSsimpledivide.net
Type: A
DNSmotherdivide.net
Type: A
DNSpossiblestream.net
Type: A
DNSmountainnothing.net
Type: A
DNSpossiblenothing.net
Type: A
DNSpossiblebottle.net
Type: A
DNSmountaindivide.net
Type: A
DNSpossibledivide.net
Type: A
DNSperhapsstream.net
Type: A
DNSperhapsnothing.net
Type: A
DNSwindownothing.net
Type: A
DNSperhapsbottle.net
Type: A
DNSwindowbottle.net
Type: A
DNSperhapsdivide.net
Type: A
DNSwindowdivide.net
Type: A
DNSwinterstream.net
Type: A
DNSsubjectstream.net
Type: A
DNSwinternothing.net
Type: A
DNSsubjectnothing.net
Type: A
DNSwinterbottle.net
Type: A
DNSsubjectbottle.net
Type: A
DNSwinterdivide.net
Type: A
DNSsubjectdivide.net
Type: A
DNSfinishstream.net
Type: A
DNSleavestream.net
Type: A
DNSfinishnothing.net
Type: A
DNSleavenothing.net
Type: A
DNSfinishbottle.net
Type: A
DNSleavebottle.net
Type: A
DNSfinishdivide.net
Type: A
DNSleavedivide.net
Type: A
DNSsweetstream.net
Type: A
DNSprobablystream.net
Type: A
DNSprobablynothing.net
Type: A
DNSsweetbottle.net
Type: A
DNSprobablybottle.net
Type: A
DNSsweetdivide.net
Type: A
DNSprobablydivide.net
Type: A
DNSseveralstream.net
Type: A
DNSmaterialstream.net
Type: A
DNSseveralnothing.net
Type: A
DNSmaterialnothing.net
Type: A
DNSseveralbottle.net
Type: A
DNSmaterialbottle.net
Type: A
DNSseveraldivide.net
Type: A
DNSmaterialdivide.net
Type: A
DNSseveramanner.net
Type: A
DNSlaughmanner.net
Type: A
DNSseveraanother.net
Type: A
DNSlaughanother.net
Type: A
DNSseverabusiness.net
Type: A
DNSlaughbusiness.net
Type: A
DNSseveraappear.net
Type: A
DNSlaughappear.net
Type: A
DNSsimplemanner.net
Type: A
DNSmothermanner.net
Type: A
DNSsimpleanother.net
Type: A
DNSmotherbusiness.net
Type: A
DNSsimpleappear.net
Type: A
DNSmotherappear.net
Type: A
DNSpossiblemanner.net
Type: A
DNSmountainanother.net
Type: A
DNSpossibleanother.net
Type: A
DNSmountainbusiness.net
Type: A
DNSpossiblebusiness.net
Type: A
DNSmountainappear.net
Type: A
DNSpossibleappear.net
Type: A
DNSperhapsmanner.net
Type: A
DNSwindowmanner.net
Type: A
DNSperhapsanother.net
Type: A
DNSwindowanother.net
Type: A
DNSperhapsbusiness.net
Type: A
DNSwindowbusiness.net
Type: A
DNSperhapsappear.net
Type: A
DNSwindowappear.net
Type: A
DNSwintermanner.net
Type: A
DNSsubjectmanner.net
Type: A
DNSwinteranother.net
Type: A
DNSsubjectanother.net
Type: A
DNSwinterbusiness.net
Type: A
DNSsubjectbusiness.net
Type: A
DNSwinterappear.net
Type: A
DNSsubjectappear.net
Type: A
DNSfinishmanner.net
Type: A
DNSleavemanner.net
Type: A
DNSfinishanother.net
Type: A
DNSleaveanother.net
Type: A
DNSfinishbusiness.net
Type: A
DNSleavebusiness.net
Type: A
DNSfinishappear.net
Type: A
DNSleaveappear.net
Type: A
DNSsweetmanner.net
Type: A
DNSprobablymanner.net
Type: A
DNSsweetanother.net
Type: A
DNSprobablyanother.net
Type: A
DNSprobablybusiness.net
Type: A
DNSsweetappear.net
Type: A
DNSprobablyappear.net
Type: A
DNSseveralmanner.net
Type: A
DNSmaterialmanner.net
Type: A
DNSseveralanother.net
Type: A
DNSmaterialanother.net
Type: A
DNSseveralbusiness.net
Type: A
DNSmaterialbusiness.net
Type: A
DNSseveralappear.net
Type: A
DNSmaterialappear.net
Type: A
DNSseverainstead.net
Type: A
DNSlaughinstead.net
Type: A
DNSseveraexplain.net
Type: A
DNSlaughexplain.net
Type: A
DNSseverabright.net
Type: A
DNSlaughbright.net
Type: A
DNSseverainside.net
Type: A
DNSlaughinside.net
Type: A
DNSsimpleinstead.net
Type: A
DNSmotherinstead.net
Type: A
DNSsimpleexplain.net
Type: A
DNSmotherexplain.net
Type: A
DNSsimplebright.net
Type: A
DNSmotherbright.net
Type: A
DNSsimpleinside.net
Type: A
DNSmotherinside.net
Type: A
DNSmountaininstead.net
Type: A
DNSpossibleinstead.net
Type: A
DNSmountainexplain.net
Type: A
DNSpossibleexplain.net
Type: A
DNSmountainbright.net
Type: A
DNSpossiblebright.net
Type: A
DNSmountaininside.net
Type: A
DNSpossibleinside.net
Type: A
DNSperhapsinstead.net
Type: A
DNSwindowinstead.net
Type: A
DNSperhapsexplain.net
Type: A
DNSwindowexplain.net
Type: A
DNSperhapsbright.net
Type: A
DNSwindowbright.net
Type: A
DNSperhapsinside.net
Type: A
HTTP GEThttp://sweetwomen.net/index.php
User-Agent:
HTTP GEThttp://materialpaint.net/index.php
User-Agent:
HTTP GEThttp://simplestream.net/index.php
User-Agent:
HTTP GEThttp://mountainstream.net/index.php
User-Agent:
HTTP GEThttp://mountainbottle.net/index.php
User-Agent:
HTTP GEThttp://windowstream.net/index.php
User-Agent:
HTTP GEThttp://sweetnothing.net/index.php
User-Agent:
HTTP GEThttp://motheranother.net/index.php
User-Agent:
HTTP GEThttp://simplebusiness.net/index.php
User-Agent:
HTTP GEThttp://mountainmanner.net/index.php
User-Agent:
HTTP GEThttp://sweetbusiness.net/index.php
User-Agent:
HTTP GEThttp://windowbright.net/index.php
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 184.168.221.104:80
Flows TCP192.168.1.1:1032 ➝ 208.100.26.234:80
Flows TCP192.168.1.1:1033 ➝ 141.8.225.124:80
Flows TCP192.168.1.1:1034 ➝ 207.148.248.143:80
Flows TCP192.168.1.1:1035 ➝ 195.22.28.198:80
Flows TCP192.168.1.1:1036 ➝ 216.21.239.197:80
Flows TCP192.168.1.1:1037 ➝ 72.52.4.119:80
Flows TCP192.168.1.1:1038 ➝ 50.63.202.39:80
Flows TCP192.168.1.1:1039 ➝ 72.52.4.119:80
Flows TCP192.168.1.1:1040 ➝ 208.100.26.234:80
Flows TCP192.168.1.1:1041 ➝ 50.240.78.247:80
Flows TCP192.168.1.1:1042 ➝ 204.133.117.26:80

Raw Pcap

Strings