Analysis Date2016-02-11 04:58:15
MD5f7d29f5a987dac650074b1e0fe8507ca
SHA1b5249d39ab2903661168aafdd71ebeb930ac629a

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: d04f65aca8ce498d4039039abb54f536 sha1: 61c6289c4433d3b2d71150c63b5ae676ab3c6f3c size: 307200
Section.rdata md5: 612b1ef8a7102faa3630396b95e74842 sha1: f5efe3b94d0926914d104f53248e660d7ae09f24 size: 26112
Section.data md5: 58199fd0c0173bbcf677a12b0277c1ad sha1: 90e359e0695fc91c6e3dba6e09569b91214be109 size: 20992
Section.reloc md5: 5c2718aebce9967f63aefca784929a9d sha1: 1c607fc8b1c97ef3b862d7179773aca87afb3a70 size: 33280
Timestamp2014-02-17 00:17:22
PackerMicrosoft Visual C++ 8
PEhash24105d12959a94f2e27e02218db29b9a187215ad
IMPhash657c12aba29014b2b7030fa94b6a0cef
AVCA (E-Trust Ino)No Virus
AVRisingNo Virus
AVMcafeeTrojan-FHSQ!F7D29F5A987D
AVAvira (antivir)TR/Taranis.2081
AVTwisterNo Virus
AVAd-AwareGen:Variant.Kazy.611656
AVAlwil (avast)No Virus
AVEset (nod32)Win32/Bayrob.BJ
AVGrisoft (avg)No Virus
AVSymantecNo Virus
AVFortinetW32/Bayrob.BJ!tr
AVBitDefenderGen:Variant.Kazy.611656
AVK7Trojan ( 004dc2a31 )
AVMicrosoft Security EssentialsTrojanSpy:Win32/Nivdort.DI
AVMicroWorld (escan)Gen:Variant.Kazy.611656
AVMalwareBytesNo Virus
AVAuthentiumW32/Nivdort.I.gen!Eldorado
AVEmsisoftGen:Variant.Kazy.611656
AVFrisk (f-prot)W32/Nivdort.I.gen!Eldorado
AVIkarusTrojan-Spy.Win32.Nivdort
AVZillya!No Virus
AVKasperskyTrojan.Win32.Swizzor.e
AVTrend MicroNo Virus
AVVirusBlokAda (vba32)No Virus
AVCAT (quickheal)TrojanSpy.Nivdort.WR4
AVBullGuardGen:Variant.Kazy.611656
AVArcabit (arcavir)Gen:Variant.Kazy.611656
AVClamAVNo Virus
AVDr. WebNo Virus
AVF-SecureGen:Variant.Kazy.611656

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates FileC:\WINDOWS\ebbymslquxutz\p8doqn
Creates FileC:\ebbymslquxutz\p8doqn
Creates FileC:\ebbymslquxutz\txte1m71xdh0nibswki1.exe
Deletes FileC:\WINDOWS\ebbymslquxutz\p8doqn
Creates ProcessC:\ebbymslquxutz\txte1m71xdh0nibswki1.exe

Process
↳ C:\ebbymslquxutz\txte1m71xdh0nibswki1.exe

RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Protected Human Problem ➝
C:\ebbymslquxutz\imvlqlqlttk.exe
Creates FileC:\ebbymslquxutz\djrgfc
Creates FileC:\WINDOWS\ebbymslquxutz\p8doqn
Creates FilePIPE\lsarpc
Creates FileC:\ebbymslquxutz\p8doqn
Creates FileC:\ebbymslquxutz\imvlqlqlttk.exe
Deletes FileC:\WINDOWS\ebbymslquxutz\p8doqn
Creates ProcessC:\ebbymslquxutz\imvlqlqlttk.exe
Creates ServiceAuto-Discovery Multimedia Drive VC Identity - C:\ebbymslquxutz\imvlqlqlttk.exe

Process
↳ C:\WINDOWS\system32\svchost.exe

Process
↳ Pid 804

Process
↳ Pid 852

Process
↳ C:\WINDOWS\System32\svchost.exe

Creates FileC:\WINDOWS\system32\WBEM\Logs\wbemess.log

Process
↳ Pid 1208

Process
↳ C:\WINDOWS\system32\spoolsv.exe

Process
↳ Pid 1852

Process
↳ Pid 1140

Process
↳ C:\ebbymslquxutz\imvlqlqlttk.exe

Creates Filepipe\net\NtControlPipe10
Creates FileC:\ebbymslquxutz\lctapkr
Creates FileC:\ebbymslquxutz\fwlxmtdwbi.exe
Creates FileC:\ebbymslquxutz\djrgfc
Creates FileC:\WINDOWS\ebbymslquxutz\p8doqn
Creates File\Device\Afd\Endpoint
Creates FileC:\ebbymslquxutz\p8doqn
Deletes FileC:\WINDOWS\ebbymslquxutz\p8doqn
Creates Processcledxzzjfuzy "c:\ebbymslquxutz\imvlqlqlttk.exe"

Process
↳ C:\ebbymslquxutz\imvlqlqlttk.exe

Creates FileC:\WINDOWS\ebbymslquxutz\p8doqn
Creates FileC:\ebbymslquxutz\p8doqn
Deletes FileC:\WINDOWS\ebbymslquxutz\p8doqn

Process
↳ cledxzzjfuzy "c:\ebbymslquxutz\imvlqlqlttk.exe"

Creates FileC:\WINDOWS\ebbymslquxutz\p8doqn
Creates FileC:\ebbymslquxutz\p8doqn
Deletes FileC:\WINDOWS\ebbymslquxutz\p8doqn

Network Details:

DNSsweetwomen.net
Type: A
184.168.221.104
DNSmaterialpaint.net
Type: A
208.100.26.234
DNSsimplestream.net
Type: A
141.8.225.124
DNSmountainstream.net
Type: A
207.148.248.143
DNSmountainbottle.net
Type: A
195.22.28.199
DNSmountainbottle.net
Type: A
195.22.28.196
DNSmountainbottle.net
Type: A
195.22.28.197
DNSmountainbottle.net
Type: A
195.22.28.198
DNSwindowstream.net
Type: A
216.21.239.197
DNSsweetnothing.net
Type: A
72.52.4.119
DNSmotheranother.net
Type: A
50.63.202.39
DNSsimplebusiness.net
Type: A
72.52.4.119
DNSmountainmanner.net
Type: A
208.100.26.234
DNSsweetbusiness.net
Type: A
45.16.128.217
DNSprobablyclean.net
Type: A
DNSsweetpaint.net
Type: A
DNSprobablypaint.net
Type: A
DNSsweetcourse.net
Type: A
DNSprobablycourse.net
Type: A
DNSprobablywomen.net
Type: A
DNSseveralclean.net
Type: A
DNSmaterialclean.net
Type: A
DNSseveralpaint.net
Type: A
DNSseveralcourse.net
Type: A
DNSmaterialcourse.net
Type: A
DNSseveralwomen.net
Type: A
DNSmaterialwomen.net
Type: A
DNSseverastream.net
Type: A
DNSlaughstream.net
Type: A
DNSseveranothing.net
Type: A
DNSlaughnothing.net
Type: A
DNSseverabottle.net
Type: A
DNSlaughbottle.net
Type: A
DNSseveradivide.net
Type: A
DNSlaughdivide.net
Type: A
DNSmotherstream.net
Type: A
DNSsimplenothing.net
Type: A
DNSmothernothing.net
Type: A
DNSsimplebottle.net
Type: A
DNSmotherbottle.net
Type: A
DNSsimpledivide.net
Type: A
DNSmotherdivide.net
Type: A
DNSpossiblestream.net
Type: A
DNSmountainnothing.net
Type: A
DNSpossiblenothing.net
Type: A
DNSpossiblebottle.net
Type: A
DNSmountaindivide.net
Type: A
DNSpossibledivide.net
Type: A
DNSperhapsstream.net
Type: A
DNSperhapsnothing.net
Type: A
DNSwindownothing.net
Type: A
DNSperhapsbottle.net
Type: A
DNSwindowbottle.net
Type: A
DNSperhapsdivide.net
Type: A
DNSwindowdivide.net
Type: A
DNSwinterstream.net
Type: A
DNSsubjectstream.net
Type: A
DNSwinternothing.net
Type: A
DNSsubjectnothing.net
Type: A
DNSwinterbottle.net
Type: A
DNSsubjectbottle.net
Type: A
DNSwinterdivide.net
Type: A
DNSsubjectdivide.net
Type: A
DNSfinishstream.net
Type: A
DNSleavestream.net
Type: A
DNSfinishnothing.net
Type: A
DNSleavenothing.net
Type: A
DNSfinishbottle.net
Type: A
DNSleavebottle.net
Type: A
DNSfinishdivide.net
Type: A
DNSleavedivide.net
Type: A
DNSsweetstream.net
Type: A
DNSprobablystream.net
Type: A
DNSprobablynothing.net
Type: A
DNSsweetbottle.net
Type: A
DNSprobablybottle.net
Type: A
DNSsweetdivide.net
Type: A
DNSprobablydivide.net
Type: A
DNSseveralstream.net
Type: A
DNSmaterialstream.net
Type: A
DNSseveralnothing.net
Type: A
DNSmaterialnothing.net
Type: A
DNSseveralbottle.net
Type: A
DNSmaterialbottle.net
Type: A
DNSseveraldivide.net
Type: A
DNSmaterialdivide.net
Type: A
DNSseveramanner.net
Type: A
DNSlaughmanner.net
Type: A
DNSseveraanother.net
Type: A
DNSlaughanother.net
Type: A
DNSseverabusiness.net
Type: A
DNSlaughbusiness.net
Type: A
DNSseveraappear.net
Type: A
DNSlaughappear.net
Type: A
DNSsimplemanner.net
Type: A
DNSmothermanner.net
Type: A
DNSsimpleanother.net
Type: A
DNSmotherbusiness.net
Type: A
DNSsimpleappear.net
Type: A
DNSmotherappear.net
Type: A
DNSpossiblemanner.net
Type: A
DNSmountainanother.net
Type: A
DNSpossibleanother.net
Type: A
DNSmountainbusiness.net
Type: A
DNSpossiblebusiness.net
Type: A
DNSmountainappear.net
Type: A
DNSpossibleappear.net
Type: A
DNSperhapsmanner.net
Type: A
DNSwindowmanner.net
Type: A
DNSperhapsanother.net
Type: A
DNSwindowanother.net
Type: A
DNSperhapsbusiness.net
Type: A
DNSwindowbusiness.net
Type: A
DNSperhapsappear.net
Type: A
DNSwindowappear.net
Type: A
DNSwintermanner.net
Type: A
DNSsubjectmanner.net
Type: A
DNSwinteranother.net
Type: A
DNSsubjectanother.net
Type: A
DNSwinterbusiness.net
Type: A
DNSsubjectbusiness.net
Type: A
DNSwinterappear.net
Type: A
DNSsubjectappear.net
Type: A
DNSfinishmanner.net
Type: A
DNSleavemanner.net
Type: A
DNSfinishanother.net
Type: A
DNSleaveanother.net
Type: A
DNSfinishbusiness.net
Type: A
DNSleavebusiness.net
Type: A
DNSfinishappear.net
Type: A
DNSleaveappear.net
Type: A
DNSsweetmanner.net
Type: A
DNSprobablymanner.net
Type: A
DNSsweetanother.net
Type: A
DNSprobablyanother.net
Type: A
DNSprobablybusiness.net
Type: A
DNSsweetappear.net
Type: A
DNSprobablyappear.net
Type: A
DNSseveralmanner.net
Type: A
DNSmaterialmanner.net
Type: A
DNSseveralanother.net
Type: A
DNSmaterialanother.net
Type: A
DNSseveralbusiness.net
Type: A
DNSmaterialbusiness.net
Type: A
DNSseveralappear.net
Type: A
DNSmaterialappear.net
Type: A
DNSseverainstead.net
Type: A
DNSlaughinstead.net
Type: A
DNSseveraexplain.net
Type: A
DNSlaughexplain.net
Type: A
DNSseverabright.net
Type: A
DNSlaughbright.net
Type: A
DNSseverainside.net
Type: A
DNSlaughinside.net
Type: A
DNSsimpleinstead.net
Type: A
DNSmotherinstead.net
Type: A
DNSsimpleexplain.net
Type: A
DNSmotherexplain.net
Type: A
DNSsimplebright.net
Type: A
DNSmotherbright.net
Type: A
DNSsimpleinside.net
Type: A
DNSmotherinside.net
Type: A
DNSmountaininstead.net
Type: A
DNSpossibleinstead.net
Type: A
DNSmountainexplain.net
Type: A
DNSpossibleexplain.net
Type: A
DNSmountainbright.net
Type: A
DNSpossiblebright.net
Type: A
DNSmountaininside.net
Type: A
DNSpossibleinside.net
Type: A
DNSperhapsinstead.net
Type: A
DNSwindowinstead.net
Type: A
DNSperhapsexplain.net
Type: A
HTTP GEThttp://sweetwomen.net/index.php
User-Agent:
HTTP GEThttp://materialpaint.net/index.php
User-Agent:
HTTP GEThttp://simplestream.net/index.php
User-Agent:
HTTP GEThttp://mountainstream.net/index.php
User-Agent:
HTTP GEThttp://mountainbottle.net/index.php
User-Agent:
HTTP GEThttp://windowstream.net/index.php
User-Agent:
HTTP GEThttp://sweetnothing.net/index.php
User-Agent:
HTTP GEThttp://motheranother.net/index.php
User-Agent:
HTTP GEThttp://simplebusiness.net/index.php
User-Agent:
HTTP GEThttp://mountainmanner.net/index.php
User-Agent:
HTTP GEThttp://sweetbusiness.net/index.php
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 184.168.221.104:80
Flows TCP192.168.1.1:1032 ➝ 208.100.26.234:80
Flows TCP192.168.1.1:1033 ➝ 141.8.225.124:80
Flows TCP192.168.1.1:1034 ➝ 207.148.248.143:80
Flows TCP192.168.1.1:1035 ➝ 195.22.28.199:80
Flows TCP192.168.1.1:1036 ➝ 216.21.239.197:80
Flows TCP192.168.1.1:1037 ➝ 72.52.4.119:80
Flows TCP192.168.1.1:1038 ➝ 50.63.202.39:80
Flows TCP192.168.1.1:1039 ➝ 72.52.4.119:80
Flows TCP192.168.1.1:1040 ➝ 208.100.26.234:80
Flows TCP192.168.1.1:1041 ➝ 45.16.128.217:80

Raw Pcap

Strings