Analysis Date2016-02-20 18:54:27
MD536b4984fe6236b2582f2296687663195
SHA1a08c83542bebca58c2fdb4bc661dafff5b2c5eb8

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: e6662127ed9385db00e7da4052f3e6d6 sha1: 826116b835619a41db5c41cf573f8deda895f92c size: 527872
Section.rdata md5: 125a11036e3e4a1e3212faacbdc6bbd4 sha1: 6e0cdd11f20a6b414096e7209007e93d6b4d70e8 size: 26112
Section.data md5: dd88f8ed1fa76de73ba975becae11ec9 sha1: bb9ca75609e08c2cb1620c480f021769b250ece4 size: 20480
Section.reloc md5: 8abf0809e25516dad316937afc6e86f4 sha1: e9ad153bb7cbf8844d2b904caa53295d1855744b size: 39424
Timestamp2014-12-25 03:28:12
PackerMicrosoft Visual C++ 8
PEhashc6f3c86599cb321189aa0efeff6481ac181d81e3
IMPhashdcad10b10a538892f692a13979e318d8
AVCA (E-Trust Ino)Gen:Variant.Razy.13928
AVF-SecureGen:Variant.Razy.13928
AVDr. WebNo Virus
AVClamAVNo Virus
AVArcabit (arcavir)Gen:Variant.Razy.13928
AVBullGuardGen:Variant.Razy.13928
AVCAT (quickheal)TrojanSpy.Nivdort.WR4
AVVirusBlokAda (vba32)No Virus
AVTrend MicroNo Virus
AVKasperskyTrojan.Win32.Generic
AVZillya!Trojan.SwizzorGen.Win32.1
AVIkarusTrojan.Bayrob
AVFrisk (f-prot)W32/Nivdort.E.gen!Eldorado
AVEmsisoftGen:Variant.Razy.13928
AVAuthentiumW32/Nivdort.E.gen!Eldorado
AVMalwareBytesNo Virus
AVMicroWorld (escan)Gen:Variant.Razy.13928
AVMicrosoft Security EssentialsTrojanSpy:Win32/Nivdort.DI
AVK7Trojan ( 004dc2a31 )
AVBitDefenderGen:Variant.Razy.13928
AVFortinetW32/Bayrob.BM!tr
AVSymantecNo Virus
AVGrisoft (avg)Generic37.ANQS
AVEset (nod32)Win32/Bayrob.BM
AVAlwil (avast)Win32:Malware-gen
AVRisingNo Virus
AVAd-AwareGen:Variant.Razy.13928
AVTwisterW32.Toolbar.CrossRider.AE.lfcr.mg
AVAvira (antivir)TR/Taranis.2112
AVMcafeeTrojan-FHSQ!36B4984FE623

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates FileC:\rkyzbrdat\lxyq1k3jkjlod0osrla.exe
Creates FileC:\WINDOWS\rkyzbrdat\q9ngwtlrsvm
Creates FileC:\rkyzbrdat\q9ngwtlrsvm
Deletes FileC:\WINDOWS\rkyzbrdat\q9ngwtlrsvm
Creates ProcessC:\rkyzbrdat\lxyq1k3jkjlod0osrla.exe

Process
↳ C:\rkyzbrdat\lxyq1k3jkjlod0osrla.exe

RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Base Cryptographic WMI Window ➝
C:\rkyzbrdat\zlumvgmctnz.exe
Creates FileC:\rkyzbrdat\zlumvgmctnz.exe
Creates FileC:\rkyzbrdat\dd0mgg
Creates FilePIPE\lsarpc
Creates FileC:\WINDOWS\rkyzbrdat\q9ngwtlrsvm
Creates FileC:\rkyzbrdat\q9ngwtlrsvm
Deletes FileC:\WINDOWS\rkyzbrdat\q9ngwtlrsvm
Creates ProcessC:\rkyzbrdat\zlumvgmctnz.exe
Creates ServiceAudio Registry Framework Visual - C:\rkyzbrdat\zlumvgmctnz.exe

Process
↳ Pid 800

Process
↳ Pid 848

Process
↳ C:\WINDOWS\System32\svchost.exe

Creates FileC:\WINDOWS\system32\WBEM\Logs\wbemess.log

Process
↳ Pid 1108

Process
↳ Pid 1204

Process
↳ C:\WINDOWS\system32\spoolsv.exe

RegistryHKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\BeepEnabled ➝
NULL
RegistryHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\Print\TypesSupported ➝
7
RegistryHKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers\SymbolicLinkValue ➝
NULL
RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory ➝
C:\WINDOWS\System32\spool\PRINTERS\\x00

Process
↳ Pid 1856

Process
↳ Pid 1132

Process
↳ C:\rkyzbrdat\zlumvgmctnz.exe

Creates Filepipe\net\NtControlPipe10
Creates FileC:\rkyzbrdat\nqqrnfhz.exe
Creates FileC:\rkyzbrdat\dd0mgg
Creates File\Device\Afd\Endpoint
Creates FileC:\WINDOWS\rkyzbrdat\q9ngwtlrsvm
Creates FileC:\rkyzbrdat\ggwcpuzyw
Creates FileC:\rkyzbrdat\q9ngwtlrsvm
Deletes FileC:\WINDOWS\rkyzbrdat\q9ngwtlrsvm
Creates Processirbjfcycfhre "c:\rkyzbrdat\zlumvgmctnz.exe"

Process
↳ C:\rkyzbrdat\zlumvgmctnz.exe

Creates FileC:\WINDOWS\rkyzbrdat\q9ngwtlrsvm
Creates FileC:\rkyzbrdat\q9ngwtlrsvm
Deletes FileC:\WINDOWS\rkyzbrdat\q9ngwtlrsvm

Process
↳ irbjfcycfhre "c:\rkyzbrdat\zlumvgmctnz.exe"

Creates FileC:\WINDOWS\rkyzbrdat\q9ngwtlrsvm
Creates FileC:\rkyzbrdat\q9ngwtlrsvm
Deletes FileC:\WINDOWS\rkyzbrdat\q9ngwtlrsvm

Network Details:

DNSbuildingdinner.net
Type: A
195.22.28.199
DNSbuildingdinner.net
Type: A
195.22.28.196
DNSbuildingdinner.net
Type: A
195.22.28.197
DNSbuildingdinner.net
Type: A
195.22.28.198
DNSbuildingafraid.net
Type: A
195.22.28.198
DNSbuildingafraid.net
Type: A
195.22.28.199
DNSbuildingafraid.net
Type: A
195.22.28.196
DNSbuildingafraid.net
Type: A
195.22.28.197
DNSbrokencircle.net
Type: A
184.168.221.41
DNSmightanger.net
Type: A
208.100.26.234
DNSdoctoralways.net
Type: A
195.22.28.198
DNSdoctoralways.net
Type: A
195.22.28.199
DNSdoctoralways.net
Type: A
195.22.28.196
DNSdoctoralways.net
Type: A
195.22.28.197
DNSfw.ename.net
Type: A
198.148.92.56
DNSfw.ename.net
Type: A
198.148.92.57
DNSfw.ename.net
Type: A
198.148.92.58
DNSbuildingschool.net
Type: A
72.167.232.36
DNSeveningschool.net
Type: A
50.63.202.50
DNSmelbourneit.hotkeysparking.com
Type: A
8.5.1.16
DNSmovementmeasure.net
Type: A
DNSoutsidemeasure.net
Type: A
DNSmovementdinner.net
Type: A
DNSoutsidedinner.net
Type: A
DNSmovementafraid.net
Type: A
DNSoutsideafraid.net
Type: A
DNSmovementcircle.net
Type: A
DNSoutsidecircle.net
Type: A
DNSbuildingmeasure.net
Type: A
DNSeveningmeasure.net
Type: A
DNSeveningdinner.net
Type: A
DNSeveningafraid.net
Type: A
DNSbuildingcircle.net
Type: A
DNSeveningcircle.net
Type: A
DNSstoremeasure.net
Type: A
DNSmightmeasure.net
Type: A
DNSstoredinner.net
Type: A
DNSmightdinner.net
Type: A
DNSstoreafraid.net
Type: A
DNSmightafraid.net
Type: A
DNSstorecircle.net
Type: A
DNSmightcircle.net
Type: A
DNSdoctormeasure.net
Type: A
DNSprettymeasure.net
Type: A
DNSdoctordinner.net
Type: A
DNSprettydinner.net
Type: A
DNSdoctorafraid.net
Type: A
DNSprettyafraid.net
Type: A
DNSdoctorcircle.net
Type: A
DNSprettycircle.net
Type: A
DNSfellowmeasure.net
Type: A
DNSdoublemeasure.net
Type: A
DNSfellowdinner.net
Type: A
DNSdoubledinner.net
Type: A
DNSfellowafraid.net
Type: A
DNSdoubleafraid.net
Type: A
DNSfellowcircle.net
Type: A
DNSdoublecircle.net
Type: A
DNSbrokenmeasure.net
Type: A
DNSresultmeasure.net
Type: A
DNSbrokendinner.net
Type: A
DNSresultdinner.net
Type: A
DNSbrokenafraid.net
Type: A
DNSresultafraid.net
Type: A
DNSresultcircle.net
Type: A
DNSpreparemeasure.net
Type: A
DNSdesiremeasure.net
Type: A
DNSpreparedinner.net
Type: A
DNSdesiredinner.net
Type: A
DNSprepareafraid.net
Type: A
DNSdesireafraid.net
Type: A
DNSpreparecircle.net
Type: A
DNSdesirecircle.net
Type: A
DNSstrengthmeasure.net
Type: A
DNSstillmeasure.net
Type: A
DNSstrengthdinner.net
Type: A
DNSstilldinner.net
Type: A
DNSstrengthafraid.net
Type: A
DNSstillafraid.net
Type: A
DNSstrengthcircle.net
Type: A
DNSstillcircle.net
Type: A
DNSmovementwheat.net
Type: A
DNSoutsidewheat.net
Type: A
DNSmovementanger.net
Type: A
DNSoutsideanger.net
Type: A
DNSmovementalways.net
Type: A
DNSoutsidealways.net
Type: A
DNSmovementforest.net
Type: A
DNSoutsideforest.net
Type: A
DNSbuildingwheat.net
Type: A
DNSeveningwheat.net
Type: A
DNSbuildinganger.net
Type: A
DNSeveninganger.net
Type: A
DNSbuildingalways.net
Type: A
DNSeveningalways.net
Type: A
DNSbuildingforest.net
Type: A
DNSeveningforest.net
Type: A
DNSstorewheat.net
Type: A
DNSmightwheat.net
Type: A
DNSstoreanger.net
Type: A
DNSstorealways.net
Type: A
DNSmightalways.net
Type: A
DNSstoreforest.net
Type: A
DNSmightforest.net
Type: A
DNSdoctorwheat.net
Type: A
DNSprettywheat.net
Type: A
DNSdoctoranger.net
Type: A
DNSprettyanger.net
Type: A
DNSprettyalways.net
Type: A
DNSdoctorforest.net
Type: A
DNSprettyforest.net
Type: A
DNSfellowwheat.net
Type: A
DNSdoublewheat.net
Type: A
DNSfellowanger.net
Type: A
DNSdoubleanger.net
Type: A
DNSfellowalways.net
Type: A
DNSdoublealways.net
Type: A
DNSfellowforest.net
Type: A
DNSdoubleforest.net
Type: A
DNSbrokenwheat.net
Type: A
DNSresultwheat.net
Type: A
DNSbrokenanger.net
Type: A
DNSresultanger.net
Type: A
DNSbrokenalways.net
Type: A
DNSresultalways.net
Type: A
DNSbrokenforest.net
Type: A
DNSresultforest.net
Type: A
DNSpreparewheat.net
Type: A
DNSdesirewheat.net
Type: A
DNSprepareanger.net
Type: A
DNSdesireanger.net
Type: A
DNSpreparealways.net
Type: A
DNSdesirealways.net
Type: A
DNSprepareforest.net
Type: A
DNSdesireforest.net
Type: A
DNSstrengthwheat.net
Type: A
DNSstillwheat.net
Type: A
DNSstrengthanger.net
Type: A
DNSstillanger.net
Type: A
DNSstrengthalways.net
Type: A
DNSstillalways.net
Type: A
DNSstrengthforest.net
Type: A
DNSstillforest.net
Type: A
DNSmovementschool.net
Type: A
DNSoutsideschool.net
Type: A
DNSmovementwhile.net
Type: A
DNSoutsidewhile.net
Type: A
DNSmovementquestion.net
Type: A
DNSoutsidequestion.net
Type: A
DNSmovementtherefore.net
Type: A
DNSoutsidetherefore.net
Type: A
DNSbuildingwhile.net
Type: A
DNSeveningwhile.net
Type: A
DNSbuildingquestion.net
Type: A
DNSeveningquestion.net
Type: A
DNSbuildingtherefore.net
Type: A
DNSeveningtherefore.net
Type: A
DNSstoreschool.net
Type: A
DNSmightschool.net
Type: A
DNSstorewhile.net
Type: A
DNSmightwhile.net
Type: A
DNSstorequestion.net
Type: A
DNSmightquestion.net
Type: A
DNSstoretherefore.net
Type: A
DNSmighttherefore.net
Type: A
DNSdoctorschool.net
Type: A
DNSprettyschool.net
Type: A
DNSdoctorwhile.net
Type: A
DNSprettywhile.net
Type: A
DNSdoctorquestion.net
Type: A
DNSprettyquestion.net
Type: A
DNSdoctortherefore.net
Type: A
DNSprettytherefore.net
Type: A
DNSfellowschool.net
Type: A
DNSdoubleschool.net
Type: A
DNSfellowwhile.net
Type: A
DNSdoublewhile.net
Type: A
DNSfellowquestion.net
Type: A
DNSdoublequestion.net
Type: A
DNSfellowtherefore.net
Type: A
DNSdoubletherefore.net
Type: A
DNSbrokenschool.net
Type: A
DNSresultschool.net
Type: A
HTTP GEThttp://buildingdinner.net/index.php
User-Agent:
HTTP GEThttp://buildingafraid.net/index.php
User-Agent:
HTTP GEThttp://brokencircle.net/index.php
User-Agent:
HTTP GEThttp://mightanger.net/index.php
User-Agent:
HTTP GEThttp://doctoralways.net/index.php
User-Agent:
HTTP GEThttp://outsideschool.net/index.php
User-Agent:
HTTP GEThttp://buildingschool.net/index.php
User-Agent:
HTTP GEThttp://eveningschool.net/index.php
User-Agent:
HTTP GEThttp://doctorschool.net/index.php
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 195.22.28.199:80
Flows TCP192.168.1.1:1032 ➝ 195.22.28.198:80
Flows TCP192.168.1.1:1033 ➝ 184.168.221.41:80
Flows TCP192.168.1.1:1034 ➝ 208.100.26.234:80
Flows TCP192.168.1.1:1035 ➝ 195.22.28.198:80
Flows TCP192.168.1.1:1036 ➝ 198.148.92.56:80
Flows TCP192.168.1.1:1037 ➝ 72.167.232.36:80
Flows TCP192.168.1.1:1038 ➝ 50.63.202.50:80
Flows TCP192.168.1.1:1039 ➝ 8.5.1.16:80

Raw Pcap
0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2062   : close..Host: b
0x00000040 (00064)   75696c64 696e6764 696e6e65 722e6e65   uildingdinner.ne
0x00000050 (00080)   740d0a0d 0a                           t....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2062   : close..Host: b
0x00000040 (00064)   75696c64 696e6761 66726169 642e6e65   uildingafraid.ne
0x00000050 (00080)   740d0a0d 0a                           t....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2062   : close..Host: b
0x00000040 (00064)   726f6b65 6e636972 636c652e 6e65740d   rokencircle.net.
0x00000050 (00080)   0a0d0a0d 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a206d   : close..Host: m
0x00000040 (00064)   69676874 616e6765 722e6e65 740d0a0d   ightanger.net...
0x00000050 (00080)   0a0d0a0d 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2064   : close..Host: d
0x00000040 (00064)   6f63746f 72616c77 6179732e 6e65740d   octoralways.net.
0x00000050 (00080)   0a0d0a0d 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a206f   : close..Host: o
0x00000040 (00064)   75747369 64657363 686f6f6c 2e6e6574   utsideschool.net
0x00000050 (00080)   0d0a0d0a 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2062   : close..Host: b
0x00000040 (00064)   75696c64 696e6773 63686f6f 6c2e6e65   uildingschool.ne
0x00000050 (00080)   740d0a0d 0a                           t....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2065   : close..Host: e
0x00000040 (00064)   76656e69 6e677363 686f6f6c 2e6e6574   veningschool.net
0x00000050 (00080)   0d0a0d0a 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2064   : close..Host: d
0x00000040 (00064)   6f63746f 72736368 6f6f6c2e 6e65740d   octorschool.net.
0x00000050 (00080)   0a0d0a0a 0a                           .....


Strings