Analysis Date2016-03-04 20:26:46
MD5292058b39e1878bda2e8adf904506c0e
SHA15254c6beb0d52104ae5e3aa5308aebac21357484

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: b2eba0b7093b63e776bb9b829393ed44 sha1: 91fd1d24a63e210077ede59d7e6d64049964ae0b size: 265216
Section.rdata md5: 83ca09fb5f652bf4f7ce610e9b33882c sha1: 2bf50dba575c11fc2bfc4c14e7d7ab9cc7b8a666 size: 39424
Section.data md5: b3a33ab243ba3061c78a5cab5e162a8a sha1: f772cf513b46977e0f7972618215a1f004f8663e size: 1536
Section.reloc md5: a84ea35fcc21cb9c52cfb09f6b0696cd sha1: d73ce38c264e9e5c5282199572b9bcf79ff613ab size: 51200
Timestamp2015-12-23 05:01:32
PackerBorland Delphi 3.0 (???)
PEhash0ac5a1f1ee5993498ebe9fd8dd6200cf8b07ce5a
IMPhash95321cab17ead5f632c0dcf95fdc7a22
AVVirusBlokAda (vba32)BScope.Malware-Cryptor.Msgfake
AVCA (E-Trust Ino)Gen:Variant.Razy.11545
AVTwisterNo Virus
AVAvira (antivir)TR/Crypt.Xpack.413666
AVCAT (quickheal)TrojanSpy.Nivdort.WR4
AVMicroWorld (escan)Gen:Variant.Razy.11545
AVRisingNo Virus
AVTrend MicroNo Virus
AVFrisk (f-prot)W32/Nivdort.F.gen!Eldorado
AVFortinetW32/Bayrob.AQ!tr
AVAlwil (avast)Win32:Malware-gen
AVAlwil (avast)Malware-gen
AVMicrosoft Security EssentialsTrojanSpy:Win32/Nivdort!rfn
AVAuthentiumW32/Nivdort.F.gen!Eldorado
AVKasperskyTrojan.Win32.Generic
AVEmsisoftGen:Variant.Razy.11545
AVSymantecTrojan.Bayrob!gen6
AVIkarusTrojan.Win32.Bayrob
AVZillya!No Virus
AVK7Trojan ( 004db0c61 )
AVDr. WebTrojan.DownLoader18.45341
AVClamAVNo Virus
AVGrisoft (avg)Win32/Heur
AVBitDefenderGen:Variant.Razy.11545
AVMalwareBytesNo Virus
AVArcabit (arcavir)Gen:Variant.Razy.11545
AVMcafeeTrojan-FHPD!292058B39E18
AVBullGuardGen:Variant.Razy.11545
AVF-SecureGen:Variant.Razy.11545
AVAd-AwareGen:Variant.Razy.11545
AVEset (nod32)Win32/Bayrob.AQ

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates FileC:\sjjlsfsfpvc\hhy2fnsho
Creates FileC:\WINDOWS\sjjlsfsfpvc\hhy2fnsho
Creates FileC:\sjjlsfsfpvc\ode1khus6vlust6xg.exe
Deletes FileC:\WINDOWS\sjjlsfsfpvc\hhy2fnsho
Creates ProcessC:\sjjlsfsfpvc\ode1khus6vlust6xg.exe

Process
↳ C:\sjjlsfsfpvc\ode1khus6vlust6xg.exe

RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Profile Connections Trap Config Agent ➝
C:\sjjlsfsfpvc\piljoky.exe
Creates FileC:\sjjlsfsfpvc\hhy2fnsho
Creates FileC:\sjjlsfsfpvc\icnebfvuy
Creates FileC:\WINDOWS\sjjlsfsfpvc\hhy2fnsho
Creates FileC:\sjjlsfsfpvc\piljoky.exe
Creates FilePIPE\lsarpc
Deletes FileC:\WINDOWS\sjjlsfsfpvc\hhy2fnsho
Creates ProcessC:\sjjlsfsfpvc\piljoky.exe
Creates ServiceControl Tablet Publication Search Secure - C:\sjjlsfsfpvc\piljoky.exe

Process
↳ Pid 816

Process
↳ Pid 860

Process
↳ C:\WINDOWS\System32\svchost.exe

Creates FileC:\WINDOWS\system32\WBEM\Logs\wbemess.log

Process
↳ Pid 1120

Process
↳ Pid 1216

Process
↳ C:\WINDOWS\system32\spoolsv.exe

RegistryHKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\BeepEnabled ➝
NULL
RegistryHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\Print\TypesSupported ➝
7
RegistryHKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers\SymbolicLinkValue ➝
NULL
RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory ➝
C:\WINDOWS\System32\spool\PRINTERS\\x00
Creates FileWMIDataDevice

Process
↳ Pid 1864

Process
↳ Pid 1168

Process
↳ C:\sjjlsfsfpvc\piljoky.exe

Creates Filepipe\net\NtControlPipe10
Creates FileC:\sjjlsfsfpvc\hhy2fnsho
Creates FileC:\sjjlsfsfpvc\lwzix0e6jgi9
Creates FileC:\sjjlsfsfpvc\icnebfvuy
Creates FileC:\WINDOWS\sjjlsfsfpvc\hhy2fnsho
Creates File\Device\Afd\Endpoint
Creates FileC:\sjjlsfsfpvc\gdqidktsahxi.exe
Deletes FileC:\WINDOWS\sjjlsfsfpvc\hhy2fnsho
Creates Processasvdoodulsgq "c:\sjjlsfsfpvc\piljoky.exe"

Process
↳ C:\sjjlsfsfpvc\piljoky.exe

Creates FileC:\sjjlsfsfpvc\hhy2fnsho
Creates FileC:\WINDOWS\sjjlsfsfpvc\hhy2fnsho
Deletes FileC:\WINDOWS\sjjlsfsfpvc\hhy2fnsho

Process
↳ asvdoodulsgq "c:\sjjlsfsfpvc\piljoky.exe"

Creates FileC:\sjjlsfsfpvc\hhy2fnsho
Creates FileC:\WINDOWS\sjjlsfsfpvc\hhy2fnsho
Deletes FileC:\WINDOWS\sjjlsfsfpvc\hhy2fnsho

Network Details:

DNScrowdschool.net
Type: A
59.106.167.73
DNSthoughtschool.net
Type: A
50.63.202.53
DNSmelbourneit.hotkeysparking.com
Type: A
8.5.1.16
DNSwomanschool.net
Type: A
121.254.178.252
DNSsmokeschool.net
Type: A
69.89.31.60
DNSpartyschool.net
Type: A
69.172.201.208
DNSexperiencetraining.net
Type: A
74.220.199.8
DNSsummertraining.net
Type: A
216.239.139.94
DNSsummerstorm.net
Type: A
72.52.4.119
DNScrowdstorm.net
Type: A
184.168.221.41
DNSsummerthrown.net
Type: A
208.100.26.234
DNSwatertraining.net
Type: A
216.21.239.197
DNSwomantraining.net
Type: A
208.91.197.66
DNSpartyhunger.net
Type: A
82.165.25.210
DNSfighthunger.net
Type: A
72.52.4.120
DNSfighttraining.net
Type: A
69.172.201.208
DNSmelbourneit.hotkeysparking.com
Type: A
8.5.1.16
DNSfollowquestion.net
Type: A
DNSmemberquestion.net
Type: A
DNSfollowtherefore.net
Type: A
DNSmembertherefore.net
Type: A
DNSbeginschool.net
Type: A
DNSknownschool.net
Type: A
DNSbeginwhile.net
Type: A
DNSknownwhile.net
Type: A
DNSbeginquestion.net
Type: A
DNSknownquestion.net
Type: A
DNSbegintherefore.net
Type: A
DNSknowntherefore.net
Type: A
DNSsummerschool.net
Type: A
DNSsummerwhile.net
Type: A
DNScrowdwhile.net
Type: A
DNSsummerquestion.net
Type: A
DNScrowdquestion.net
Type: A
DNSsummertherefore.net
Type: A
DNScrowdtherefore.net
Type: A
DNSwaterschool.net
Type: A
DNSthoughtwhile.net
Type: A
DNSwaterwhile.net
Type: A
DNSthoughtquestion.net
Type: A
DNSwaterquestion.net
Type: A
DNSthoughttherefore.net
Type: A
DNSwatertherefore.net
Type: A
DNSwomanwhile.net
Type: A
DNSsmokewhile.net
Type: A
DNSwomanquestion.net
Type: A
DNSsmokequestion.net
Type: A
DNSwomantherefore.net
Type: A
DNSsmoketherefore.net
Type: A
DNSfightschool.net
Type: A
DNSpartywhile.net
Type: A
DNSfightwhile.net
Type: A
DNSpartyquestion.net
Type: A
DNSfightquestion.net
Type: A
DNSpartytherefore.net
Type: A
DNSfighttherefore.net
Type: A
DNSfreshhunger.net
Type: A
DNSexperiencehunger.net
Type: A
DNSfreshtraining.net
Type: A
DNSfreshstorm.net
Type: A
DNSexperiencestorm.net
Type: A
DNSfreshthrown.net
Type: A
DNSexperiencethrown.net
Type: A
DNSgentlemanhunger.net
Type: A
DNSalreadyhunger.net
Type: A
DNSgentlemantraining.net
Type: A
DNSalreadytraining.net
Type: A
DNSgentlemanstorm.net
Type: A
DNSalreadystorm.net
Type: A
DNSgentlemanthrown.net
Type: A
DNSalreadythrown.net
Type: A
DNSfollowhunger.net
Type: A
DNSmemberhunger.net
Type: A
DNSfollowtraining.net
Type: A
DNSmembertraining.net
Type: A
DNSfollowstorm.net
Type: A
DNSmemberstorm.net
Type: A
DNSfollowthrown.net
Type: A
DNSmemberthrown.net
Type: A
DNSbeginhunger.net
Type: A
DNSknownhunger.net
Type: A
DNSbegintraining.net
Type: A
DNSknowntraining.net
Type: A
DNSbeginstorm.net
Type: A
DNSknownstorm.net
Type: A
DNSbeginthrown.net
Type: A
DNSknownthrown.net
Type: A
DNSsummerhunger.net
Type: A
DNScrowdhunger.net
Type: A
DNScrowdtraining.net
Type: A
DNScrowdthrown.net
Type: A
DNSthoughthunger.net
Type: A
DNSwaterhunger.net
Type: A
DNSthoughttraining.net
Type: A
DNSthoughtstorm.net
Type: A
DNSwaterstorm.net
Type: A
DNSthoughtthrown.net
Type: A
DNSwaterthrown.net
Type: A
DNSwomanhunger.net
Type: A
DNSsmokehunger.net
Type: A
DNSsmoketraining.net
Type: A
DNSwomanstorm.net
Type: A
DNSsmokestorm.net
Type: A
DNSwomanthrown.net
Type: A
DNSsmokethrown.net
Type: A
DNSpartytraining.net
Type: A
DNSpartystorm.net
Type: A
DNSfightstorm.net
Type: A
DNSpartythrown.net
Type: A
DNSfightthrown.net
Type: A
DNSfreshchoose.net
Type: A
DNSexperiencechoose.net
Type: A
DNSfreshalthough.net
Type: A
DNSexperiencealthough.net
Type: A
DNSfreshperiod.net
Type: A
DNSexperienceperiod.net
Type: A
DNSfreshhowever.net
Type: A
DNSexperiencehowever.net
Type: A
DNSgentlemanchoose.net
Type: A
DNSalreadychoose.net
Type: A
DNSgentlemanalthough.net
Type: A
DNSalreadyalthough.net
Type: A
DNSgentlemanperiod.net
Type: A
DNSalreadyperiod.net
Type: A
DNSgentlemanhowever.net
Type: A
DNSalreadyhowever.net
Type: A
DNSfollowchoose.net
Type: A
DNSmemberchoose.net
Type: A
DNSfollowalthough.net
Type: A
DNSmemberalthough.net
Type: A
DNSfollowperiod.net
Type: A
DNSmemberperiod.net
Type: A
DNSfollowhowever.net
Type: A
DNSmemberhowever.net
Type: A
DNSbeginchoose.net
Type: A
DNSknownchoose.net
Type: A
DNSbeginalthough.net
Type: A
DNSknownalthough.net
Type: A
DNSbeginperiod.net
Type: A
DNSknownperiod.net
Type: A
DNSbeginhowever.net
Type: A
DNSknownhowever.net
Type: A
DNSsummerchoose.net
Type: A
DNScrowdchoose.net
Type: A
DNSsummeralthough.net
Type: A
DNScrowdalthough.net
Type: A
DNSsummerperiod.net
Type: A
DNScrowdperiod.net
Type: A
DNSsummerhowever.net
Type: A
DNScrowdhowever.net
Type: A
DNSthoughtchoose.net
Type: A
DNSwaterchoose.net
Type: A
DNSthoughtalthough.net
Type: A
DNSwateralthough.net
Type: A
DNSthoughtperiod.net
Type: A
DNSwaterperiod.net
Type: A
DNSthoughthowever.net
Type: A
DNSwaterhowever.net
Type: A
DNSwomanchoose.net
Type: A
DNSsmokechoose.net
Type: A
DNSwomanalthough.net
Type: A
DNSsmokealthough.net
Type: A
DNSwomanperiod.net
Type: A
DNSsmokeperiod.net
Type: A
DNSwomanhowever.net
Type: A
DNSsmokehowever.net
Type: A
DNSpartychoose.net
Type: A
DNSfightchoose.net
Type: A
DNSpartyalthough.net
Type: A
DNSfightalthough.net
Type: A
DNSpartyperiod.net
Type: A
DNSfightperiod.net
Type: A
HTTP GEThttp://crowdschool.net/index.php
User-Agent:
HTTP GEThttp://thoughtschool.net/index.php
User-Agent:
HTTP GEThttp://thoughttherefore.net/index.php
User-Agent:
HTTP GEThttp://womanschool.net/index.php
User-Agent:
HTTP GEThttp://smokeschool.net/index.php
User-Agent:
HTTP GEThttp://partyschool.net/index.php
User-Agent:
HTTP GEThttp://experiencetraining.net/index.php
User-Agent:
HTTP GEThttp://summertraining.net/index.php
User-Agent:
HTTP GEThttp://summerstorm.net/index.php
User-Agent:
HTTP GEThttp://crowdstorm.net/index.php
User-Agent:
HTTP GEThttp://summerthrown.net/index.php
User-Agent:
HTTP GEThttp://watertraining.net/index.php
User-Agent:
HTTP GEThttp://womantraining.net/index.php
User-Agent:
HTTP GEThttp://partyhunger.net/index.php
User-Agent:
HTTP GEThttp://fighthunger.net/index.php
User-Agent:
HTTP GEThttp://fighttraining.net/index.php
User-Agent:
HTTP GEThttp://alreadyperiod.net/index.php
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 59.106.167.73:80
Flows TCP192.168.1.1:1032 ➝ 50.63.202.53:80
Flows TCP192.168.1.1:1033 ➝ 8.5.1.16:80
Flows TCP192.168.1.1:1034 ➝ 121.254.178.252:80
Flows TCP192.168.1.1:1035 ➝ 69.89.31.60:80
Flows TCP192.168.1.1:1036 ➝ 69.172.201.208:80
Flows TCP192.168.1.1:1037 ➝ 74.220.199.8:80
Flows TCP192.168.1.1:1038 ➝ 216.239.139.94:80
Flows TCP192.168.1.1:1039 ➝ 72.52.4.119:80
Flows TCP192.168.1.1:1040 ➝ 184.168.221.41:80
Flows TCP192.168.1.1:1041 ➝ 208.100.26.234:80
Flows TCP192.168.1.1:1042 ➝ 216.21.239.197:80
Flows TCP192.168.1.1:1043 ➝ 208.91.197.66:80
Flows TCP192.168.1.1:1044 ➝ 82.165.25.210:80
Flows TCP192.168.1.1:1045 ➝ 72.52.4.120:80
Flows TCP192.168.1.1:1046 ➝ 69.172.201.208:80
Flows TCP192.168.1.1:1047 ➝ 8.5.1.16:80

Raw Pcap

Strings