Analysis Date2016-01-29 07:55:33
MD581c7c4a774ce03aebcb873b4bbe8cb81
SHA1c41657442932143b10940753cd4891597dd488a2

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 70d3b6bc5910d0b7d2a7504f3ca035a5 sha1: a113504b2680b89a26ed6467f2ca48efab49bd08 size: 304640
Section.rdata md5: e52e7022ee08d3249af55261bca09700 sha1: 16da0d9b4aa36d8f32cfc0200352173fd64a7fef size: 26112
Section.data md5: e6f1fd8a8943b1d3235ec9b2741a4448 sha1: d472538489fad049fa9e498eb923d07d1fa77746 size: 20480
Section.reloc md5: ec8d28cc63b95d8512f206084a1f3374 sha1: 3df89c9b8f122e6c7fda6dd617ab87aee287329a size: 32768
Timestamp2014-11-15 08:44:32
PackerMicrosoft Visual C++ 8
PEhashd6aba6e9e666ffeec8a0e57867e6bc3e7acfd212
IMPhash887a5273c6b6af8b3425c855428df7b4
AVCA (E-Trust Ino)No Virus
AVF-SecureGen:Variant.Zusy.141475
AVDr. WebNo Virus
AVClamAVNo Virus
AVArcabit (arcavir)Gen:Variant.Zusy.141475
AVBullGuardGen:Variant.Zusy.141475
AVCAT (quickheal)No Virus
AVVirusBlokAda (vba32)No Virus
AVTrend MicroNo Virus
AVKasperskyTrojan.Win32.Generic
AVZillya!No Virus
AVIkarusTrojan-Spy.Win32.Nivdort
AVFrisk (f-prot)W32/Nivdort.I.gen!Eldorado
AVEmsisoftGen:Variant.Zusy.141475
AVAuthentiumW32/Nivdort.I.gen!Eldorado
AVMalwareBytesNo Virus
AVMicroWorld (escan)Gen:Variant.Zusy.141475
AVMicrosoft Security EssentialsTrojanSpy:Win32/Nivdort.DI
AVK7Trojan ( 004dc2a31 )
AVBitDefenderGen:Variant.Zusy.141475
AVFortinetW32/Bayrob.BJ!tr
AVSymantecNo Virus
AVGrisoft (avg)Generic37.ABHX
AVEset (nod32)Win32/Bayrob.BJ
AVAlwil (avast)No Virus
AVRisingNo Virus
AVAd-AwareGen:Variant.Zusy.141475
AVTwisterNo Virus
AVAvira (antivir)TR/Nivdort.A.30771
AVMcafeeTrojan-FHSQ!81C7C4A774CE

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates FileC:\lvadmnybvj\gwm5dppuaqatddnoehcxd.exe
Creates FileC:\WINDOWS\lvadmnybvj\lbv1yq
Creates FileC:\lvadmnybvj\lbv1yq
Deletes FileC:\WINDOWS\lvadmnybvj\lbv1yq
Creates ProcessC:\lvadmnybvj\gwm5dppuaqatddnoehcxd.exe

Process
↳ C:\lvadmnybvj\gwm5dppuaqatddnoehcxd.exe

RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Portable Configuration Card COM+ ➝
C:\lvadmnybvj\puctlyrv.exe
Creates FileC:\lvadmnybvj\puctlyrv.exe
Creates FileC:\WINDOWS\lvadmnybvj\lbv1yq
Creates FilePIPE\lsarpc
Creates FileC:\lvadmnybvj\wlz2tfha3sba
Creates FileC:\lvadmnybvj\lbv1yq
Deletes FileC:\WINDOWS\lvadmnybvj\lbv1yq
Creates ProcessC:\lvadmnybvj\puctlyrv.exe
Creates ServiceThemes Alerts Internet Copy Spooler - C:\lvadmnybvj\puctlyrv.exe

Process
↳ C:\WINDOWS\system32\svchost.exe

Process
↳ Pid 804

Process
↳ Pid 848

Process
↳ C:\WINDOWS\System32\svchost.exe

RegistryHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX}\DhcpNameServer ➝
192.168.254.254\\x00
RegistryHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX}\Parameters\Tcpip\DhcpDefaultGateway ➝
NULL
RegistryHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer ➝
192.168.254.254\\x00
Creates FileC:\WINDOWS\Prefetch\RUNDLL32.EXE-1BC69D2D.pf
Creates FileC:\WINDOWS\Prefetch\GWM5DPPUAQATDDNOEHCXD.EXE-2EF39862.pf
Creates FileNDIS
Creates FileC:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf
Creates FileC:\WINDOWS\Prefetch\NET1.EXE-029B9DB4.pf
Creates FileC:\WINDOWS\Prefetch\PUCTLYRV.EXE-335FCB11.pf
Creates FileC:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf
Creates FileC:\WINDOWS\Prefetch\monitor.exe-1949D260.pf
Creates FileC:\WINDOWS\Prefetch\USERINIT.EXE-30B18140.pf
Creates FileC:\WINDOWS\Prefetch\READER_SL.EXE-3614FA6E.pf
Creates FileC:\WINDOWS\Prefetch\C41657442932143B10940753CD489-0713C317.pf
Creates File\Device\Afd\Endpoint
Creates FileC:\WINDOWS\system32\WBEM\Logs\wbemess.log
Creates FileC:\WINDOWS\Prefetch\WOLPKKVT.EXE-19F22F96.pf
Creates FileC:\WINDOWS\Prefetch\svchost.EXE-0C867EC1.pf

Process
↳ Pid 1204

Process
↳ Pid 1320

Process
↳ Pid 1856

Process
↳ Pid 456

Process
↳ C:\lvadmnybvj\puctlyrv.exe

Creates Filepipe\net\NtControlPipe10
Creates FileC:\WINDOWS\lvadmnybvj\lbv1yq
Creates FileC:\lvadmnybvj\wolpkkvt.exe
Creates File\Device\Afd\Endpoint
Creates FileC:\lvadmnybvj\sn6iu8tsh
Creates FileC:\lvadmnybvj\wlz2tfha3sba
Creates FileC:\lvadmnybvj\lbv1yq
Deletes FileC:\WINDOWS\lvadmnybvj\lbv1yq
Creates Processekga9qx9qmro "c:\lvadmnybvj\puctlyrv.exe"

Process
↳ C:\lvadmnybvj\puctlyrv.exe

Creates FileC:\WINDOWS\lvadmnybvj\lbv1yq
Creates FileC:\lvadmnybvj\lbv1yq
Deletes FileC:\WINDOWS\lvadmnybvj\lbv1yq

Process
↳ ekga9qx9qmro "c:\lvadmnybvj\puctlyrv.exe"

Creates FileC:\WINDOWS\lvadmnybvj\lbv1yq
Creates FileC:\lvadmnybvj\lbv1yq
Deletes FileC:\WINDOWS\lvadmnybvj\lbv1yq

Network Details:

DNSbuildingpower.net
Type: A
188.40.84.184
DNSdoctorcentury.net
Type: A
195.22.28.196
DNSdoctorcentury.net
Type: A
195.22.28.197
DNSdoctorcentury.net
Type: A
195.22.28.198
DNSdoctorcentury.net
Type: A
195.22.28.199
DNSprettypower.net
Type: A
208.91.197.23
DNSdoublefamous.net
Type: A
210.157.1.134
DNSfellowpower.net
Type: A
98.139.135.129
DNSbrokenfamous.net
Type: A
208.100.26.234
DNSbrokenpower.net
Type: A
72.167.131.57
DNSstillpower.net
Type: A
184.168.221.34
DNSdoctorletter.net
Type: A
162.255.119.251
DNSdoctordifferent.net
Type: A
184.168.221.43
DNSprettydifferent.net
Type: A
23.236.62.147
DNSstillsurprise.net
Type: A
98.139.135.129
DNSstrengthdifferent.net
Type: A
208.100.26.234
DNSmachineclean.net
Type: A
208.109.181.40
DNSdesirecondition.net
Type: A
DNSstrengthnation.net
Type: A
DNSstillnation.net
Type: A
DNSstrengthsoldier.net
Type: A
DNSstillsoldier.net
Type: A
DNSstrengthplease.net
Type: A
DNSstillplease.net
Type: A
DNSstrengthcondition.net
Type: A
DNSstillcondition.net
Type: A
DNSmovementcentury.net
Type: A
DNSoutsidecentury.net
Type: A
DNSmovementfamous.net
Type: A
DNSoutsidefamous.net
Type: A
DNSmovementpower.net
Type: A
DNSoutsidepower.net
Type: A
DNSmovementcountry.net
Type: A
DNSoutsidecountry.net
Type: A
DNSbuildingcentury.net
Type: A
DNSeveningcentury.net
Type: A
DNSbuildingfamous.net
Type: A
DNSeveningfamous.net
Type: A
DNSeveningpower.net
Type: A
DNSbuildingcountry.net
Type: A
DNSeveningcountry.net
Type: A
DNSstorecentury.net
Type: A
DNSmightcentury.net
Type: A
DNSstorefamous.net
Type: A
DNSmightfamous.net
Type: A
DNSstorepower.net
Type: A
DNSmightpower.net
Type: A
DNSstorecountry.net
Type: A
DNSmightcountry.net
Type: A
DNSprettycentury.net
Type: A
DNSdoctorfamous.net
Type: A
DNSprettyfamous.net
Type: A
DNSdoctorpower.net
Type: A
DNSdoctorcountry.net
Type: A
DNSprettycountry.net
Type: A
DNSfellowcentury.net
Type: A
DNSdoublecentury.net
Type: A
DNSfellowfamous.net
Type: A
DNSdoublepower.net
Type: A
DNSfellowcountry.net
Type: A
DNSdoublecountry.net
Type: A
DNSbrokencentury.net
Type: A
DNSresultcentury.net
Type: A
DNSresultfamous.net
Type: A
DNSresultpower.net
Type: A
DNSbrokencountry.net
Type: A
DNSresultcountry.net
Type: A
DNSpreparecentury.net
Type: A
DNSdesirecentury.net
Type: A
DNSpreparefamous.net
Type: A
DNSdesirefamous.net
Type: A
DNSpreparepower.net
Type: A
DNSdesirepower.net
Type: A
DNSpreparecountry.net
Type: A
DNSdesirecountry.net
Type: A
DNSstrengthcentury.net
Type: A
DNSstillcentury.net
Type: A
DNSstrengthfamous.net
Type: A
DNSstillfamous.net
Type: A
DNSstrengthpower.net
Type: A
DNSstrengthcountry.net
Type: A
DNSstillcountry.net
Type: A
DNSmovementsurprise.net
Type: A
DNSoutsidesurprise.net
Type: A
DNSmovementbeside.net
Type: A
DNSoutsidebeside.net
Type: A
DNSmovementletter.net
Type: A
DNSoutsideletter.net
Type: A
DNSmovementdifferent.net
Type: A
DNSoutsidedifferent.net
Type: A
DNSbuildingsurprise.net
Type: A
DNSeveningsurprise.net
Type: A
DNSbuildingbeside.net
Type: A
DNSeveningbeside.net
Type: A
DNSbuildingletter.net
Type: A
DNSeveningletter.net
Type: A
DNSbuildingdifferent.net
Type: A
DNSeveningdifferent.net
Type: A
DNSstoresurprise.net
Type: A
DNSmightsurprise.net
Type: A
DNSstorebeside.net
Type: A
DNSmightbeside.net
Type: A
DNSstoreletter.net
Type: A
DNSmightletter.net
Type: A
DNSstoredifferent.net
Type: A
DNSmightdifferent.net
Type: A
DNSdoctorsurprise.net
Type: A
DNSprettysurprise.net
Type: A
DNSdoctorbeside.net
Type: A
DNSprettybeside.net
Type: A
DNSprettyletter.net
Type: A
DNSfellowsurprise.net
Type: A
DNSdoublesurprise.net
Type: A
DNSfellowbeside.net
Type: A
DNSdoublebeside.net
Type: A
DNSfellowletter.net
Type: A
DNSdoubleletter.net
Type: A
DNSfellowdifferent.net
Type: A
DNSdoubledifferent.net
Type: A
DNSbrokensurprise.net
Type: A
DNSresultsurprise.net
Type: A
DNSbrokenbeside.net
Type: A
DNSresultbeside.net
Type: A
DNSbrokenletter.net
Type: A
DNSresultletter.net
Type: A
DNSbrokendifferent.net
Type: A
DNSresultdifferent.net
Type: A
DNSpreparesurprise.net
Type: A
DNSdesiresurprise.net
Type: A
DNSpreparebeside.net
Type: A
DNSdesirebeside.net
Type: A
DNSprepareletter.net
Type: A
DNSdesireletter.net
Type: A
DNSpreparedifferent.net
Type: A
DNSdesiredifferent.net
Type: A
DNSstrengthsurprise.net
Type: A
DNSstrengthbeside.net
Type: A
DNSstillbeside.net
Type: A
DNSstrengthletter.net
Type: A
DNSstillletter.net
Type: A
DNSstilldifferent.net
Type: A
DNSexpectclean.net
Type: A
DNSbecauseclean.net
Type: A
DNSexpectpaint.net
Type: A
DNSbecausepaint.net
Type: A
DNSexpectcourse.net
Type: A
DNSbecausecourse.net
Type: A
DNSexpectwomen.net
Type: A
DNSbecausewomen.net
Type: A
DNSpersonclean.net
Type: A
DNSpersonpaint.net
Type: A
DNSmachinepaint.net
Type: A
DNSpersoncourse.net
Type: A
DNSmachinecourse.net
Type: A
DNSpersonwomen.net
Type: A
HTTP GEThttp://buildingpower.net/index.php
User-Agent:
HTTP GEThttp://doctorcentury.net/index.php
User-Agent:
HTTP GEThttp://prettypower.net/index.php
User-Agent:
HTTP GEThttp://doublefamous.net/index.php
User-Agent:
HTTP GEThttp://fellowpower.net/index.php
User-Agent:
HTTP GEThttp://brokenfamous.net/index.php
User-Agent:
HTTP GEThttp://brokenpower.net/index.php
User-Agent:
HTTP GEThttp://stillpower.net/index.php
User-Agent:
HTTP GEThttp://doctorletter.net/index.php
User-Agent:
HTTP GEThttp://doctordifferent.net/index.php
User-Agent:
HTTP GEThttp://prettydifferent.net/index.php
User-Agent:
HTTP GEThttp://stillsurprise.net/index.php
User-Agent:
HTTP GEThttp://strengthdifferent.net/index.php
User-Agent:
HTTP GEThttp://machineclean.net/index.php
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 188.40.84.184:80
Flows TCP192.168.1.1:1032 ➝ 195.22.28.196:80
Flows TCP192.168.1.1:1033 ➝ 208.91.197.23:80
Flows TCP192.168.1.1:1036 ➝ 210.157.1.134:80
Flows TCP192.168.1.1:1037 ➝ 98.139.135.129:80
Flows TCP192.168.1.1:1038 ➝ 208.100.26.234:80
Flows TCP192.168.1.1:1039 ➝ 72.167.131.57:80
Flows TCP192.168.1.1:1040 ➝ 184.168.221.34:80
Flows TCP192.168.1.1:1041 ➝ 162.255.119.251:80
Flows TCP192.168.1.1:1042 ➝ 184.168.221.43:80
Flows TCP192.168.1.1:1043 ➝ 23.236.62.147:80
Flows TCP192.168.1.1:1044 ➝ 98.139.135.129:80
Flows TCP192.168.1.1:1045 ➝ 208.100.26.234:80
Flows TCP192.168.1.1:1046 ➝ 208.109.181.40:80

Raw Pcap

Strings