Analysis Date2016-02-11 05:08:21
MD59fbd48eacbd7a4e815cc2ef6977c73e2
SHA1caf52f6ba572590343e376e4e7249d9f88a96c95

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 71c84693d28a0348027fe93e4e9ef837 sha1: 78f18132846a2f1a53a19622f980f2acf49b9a3a size: 307200
Section.rdata md5: 9f6c63cb3d034141d71228aecf9eb910 sha1: bf03cff6350673dc21d02810b9876cbac0df95d4 size: 26112
Section.data md5: 9cc2ddf415170806f66d08601f9d2e4d sha1: 6917a9c421a3c75df94acd137d0241f9ef695076 size: 21504
Section.reloc md5: fbd72426ba2360fb8b5f8fcb09c66cf7 sha1: 85b402b6f87e55374e3d1479a8e8e3c1f5347882 size: 33280
Timestamp2014-12-16 20:55:10
PackerMicrosoft Visual C++ 8
PEhash5d13e904197f24742ae1ccbabedfea0a8d194ce1
IMPhashba729b92610045ab64c78003be8bb0d2
AVCA (E-Trust Ino)Gen:Variant.Razy.15381
AVRising0x59ae0737
AVMcafeeTrojan-FHSQ!9FBD48EACBD7
AVAvira (antivir)TR/Taranis.2084
AVTwisterNo Virus
AVAd-AwareGen:Variant.Razy.15381
AVAlwil (avast)Win32:Malware-gen
AVEset (nod32)Win32/Bayrob.BJ
AVGrisoft (avg)Generic37.ACKE
AVSymantecNo Virus
AVFortinetW32/Bayrob.BJ!tr
AVBitDefenderGen:Variant.Razy.15381
AVK7Trojan ( 004dc2a31 )
AVMicrosoft Security EssentialsTrojanSpy:Win32/Nivdort.DI
AVMicroWorld (escan)Gen:Variant.Razy.15381
AVMalwareBytesNo Virus
AVAuthentiumW32/Nivdort.I.gen!Eldorado
AVEmsisoftGen:Variant.Razy.15381
AVFrisk (f-prot)W32/Nivdort.I.gen!Eldorado
AVIkarusTrojan-Spy.Win32.Nivdort
AVZillya!Trojan.SwizzorGen.Win32.1
AVKasperskyTrojan.Win32.Swizzor.e
AVTrend MicroNo Virus
AVVirusBlokAda (vba32)No Virus
AVCAT (quickheal)TrojanSpy.Nivdort.WR4
AVBullGuardGen:Variant.Razy.15381
AVArcabit (arcavir)Gen:Variant.Razy.15381
AVClamAVNo Virus
AVDr. WebNo Virus
AVF-SecureGen:Variant.Razy.15381

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates FileC:\WINDOWS\wseblhlhp\tcmdc1j2gfu
Creates FileC:\wseblhlhp\rupb1kreh0xnnfqbdk.exe
Creates FileC:\wseblhlhp\tcmdc1j2gfu
Deletes FileC:\WINDOWS\wseblhlhp\tcmdc1j2gfu
Creates ProcessC:\wseblhlhp\rupb1kreh0xnnfqbdk.exe

Process
↳ C:\wseblhlhp\rupb1kreh0xnnfqbdk.exe

RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Collector Counter Telephony Tools ➝
C:\wseblhlhp\hnabqqqyet.exe
Creates FileC:\WINDOWS\wseblhlhp\tcmdc1j2gfu
Creates FileC:\wseblhlhp\hnabqqqyet.exe
Creates FilePIPE\lsarpc
Creates FileC:\wseblhlhp\nwraweko
Creates FileC:\wseblhlhp\tcmdc1j2gfu
Deletes FileC:\WINDOWS\wseblhlhp\tcmdc1j2gfu
Creates ProcessC:\wseblhlhp\hnabqqqyet.exe
Creates ServiceReporting Defragmenter BitLocker - C:\wseblhlhp\hnabqqqyet.exe

Process
↳ C:\WINDOWS\system32\svchost.exe

Process
↳ Pid 820

Process
↳ Pid 864

Process
↳ C:\WINDOWS\System32\svchost.exe

Creates FileC:\WINDOWS\system32\WBEM\Logs\wbemess.log

Process
↳ Pid 1220

Process
↳ C:\WINDOWS\system32\spoolsv.exe

RegistryHKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\BeepEnabled ➝
NULL
RegistryHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\Print\TypesSupported ➝
7
RegistryHKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers\SymbolicLinkValue ➝
NULL
RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory ➝
C:\WINDOWS\System32\spool\PRINTERS\\x00

Process
↳ Pid 1864

Process
↳ Pid 1168

Process
↳ C:\wseblhlhp\hnabqqqyet.exe

Creates Filepipe\net\NtControlPipe10
Creates FileC:\wseblhlhp\vrtyseqwonz
Creates FileC:\WINDOWS\wseblhlhp\tcmdc1j2gfu
Creates File\Device\Afd\Endpoint
Creates FileC:\wseblhlhp\pelrflqcfie.exe
Creates FileC:\wseblhlhp\nwraweko
Creates FileC:\wseblhlhp\tcmdc1j2gfu
Deletes FileC:\WINDOWS\wseblhlhp\tcmdc1j2gfu
Creates Processxfvfyktq7pj5 "c:\wseblhlhp\hnabqqqyet.exe"

Process
↳ C:\wseblhlhp\hnabqqqyet.exe

Creates FileC:\WINDOWS\wseblhlhp\tcmdc1j2gfu
Creates FileC:\wseblhlhp\tcmdc1j2gfu
Deletes FileC:\WINDOWS\wseblhlhp\tcmdc1j2gfu

Process
↳ xfvfyktq7pj5 "c:\wseblhlhp\hnabqqqyet.exe"

Creates FileC:\WINDOWS\wseblhlhp\tcmdc1j2gfu
Creates FileC:\wseblhlhp\tcmdc1j2gfu
Deletes FileC:\WINDOWS\wseblhlhp\tcmdc1j2gfu

Network Details:

DNSsweetwomen.net
Type: A
184.168.221.104
DNSmaterialpaint.net
Type: A
208.100.26.234
DNSsimplestream.net
Type: A
141.8.225.124
DNSmountainstream.net
Type: A
207.148.248.143
DNSmountainbottle.net
Type: A
195.22.28.197
DNSmountainbottle.net
Type: A
195.22.28.196
DNSmountainbottle.net
Type: A
195.22.28.199
DNSmountainbottle.net
Type: A
195.22.28.198
DNSwindowstream.net
Type: A
216.21.239.197
DNSsweetnothing.net
Type: A
72.52.4.119
DNSmotheranother.net
Type: A
50.63.202.39
DNSsimplebusiness.net
Type: A
72.52.4.119
DNSmountainmanner.net
Type: A
208.100.26.234
DNSsweetbusiness.net
Type: A
45.16.128.217
DNSprobablypaint.net
Type: A
DNSsweetcourse.net
Type: A
DNSprobablycourse.net
Type: A
DNSprobablywomen.net
Type: A
DNSseveralclean.net
Type: A
DNSmaterialclean.net
Type: A
DNSseveralpaint.net
Type: A
DNSseveralcourse.net
Type: A
DNSmaterialcourse.net
Type: A
DNSseveralwomen.net
Type: A
DNSmaterialwomen.net
Type: A
DNSseverastream.net
Type: A
DNSlaughstream.net
Type: A
DNSseveranothing.net
Type: A
DNSlaughnothing.net
Type: A
DNSseverabottle.net
Type: A
DNSlaughbottle.net
Type: A
DNSseveradivide.net
Type: A
DNSlaughdivide.net
Type: A
DNSmotherstream.net
Type: A
DNSsimplenothing.net
Type: A
DNSmothernothing.net
Type: A
DNSsimplebottle.net
Type: A
DNSmotherbottle.net
Type: A
DNSsimpledivide.net
Type: A
DNSmotherdivide.net
Type: A
DNSpossiblestream.net
Type: A
DNSmountainnothing.net
Type: A
DNSpossiblenothing.net
Type: A
DNSpossiblebottle.net
Type: A
DNSmountaindivide.net
Type: A
DNSpossibledivide.net
Type: A
DNSperhapsstream.net
Type: A
DNSperhapsnothing.net
Type: A
DNSwindownothing.net
Type: A
DNSperhapsbottle.net
Type: A
DNSwindowbottle.net
Type: A
DNSperhapsdivide.net
Type: A
DNSwindowdivide.net
Type: A
DNSwinterstream.net
Type: A
DNSsubjectstream.net
Type: A
DNSwinternothing.net
Type: A
DNSsubjectnothing.net
Type: A
DNSwinterbottle.net
Type: A
DNSsubjectbottle.net
Type: A
DNSwinterdivide.net
Type: A
DNSsubjectdivide.net
Type: A
DNSfinishstream.net
Type: A
DNSleavestream.net
Type: A
DNSfinishnothing.net
Type: A
DNSleavenothing.net
Type: A
DNSfinishbottle.net
Type: A
DNSleavebottle.net
Type: A
DNSfinishdivide.net
Type: A
DNSleavedivide.net
Type: A
DNSsweetstream.net
Type: A
DNSprobablystream.net
Type: A
DNSprobablynothing.net
Type: A
DNSsweetbottle.net
Type: A
DNSprobablybottle.net
Type: A
DNSsweetdivide.net
Type: A
DNSprobablydivide.net
Type: A
DNSseveralstream.net
Type: A
DNSmaterialstream.net
Type: A
DNSseveralnothing.net
Type: A
DNSmaterialnothing.net
Type: A
DNSseveralbottle.net
Type: A
DNSmaterialbottle.net
Type: A
DNSseveraldivide.net
Type: A
DNSmaterialdivide.net
Type: A
DNSseveramanner.net
Type: A
DNSlaughmanner.net
Type: A
DNSseveraanother.net
Type: A
DNSlaughanother.net
Type: A
DNSseverabusiness.net
Type: A
DNSlaughbusiness.net
Type: A
DNSseveraappear.net
Type: A
DNSlaughappear.net
Type: A
DNSsimplemanner.net
Type: A
DNSmothermanner.net
Type: A
DNSsimpleanother.net
Type: A
DNSmotherbusiness.net
Type: A
DNSsimpleappear.net
Type: A
DNSmotherappear.net
Type: A
DNSpossiblemanner.net
Type: A
DNSmountainanother.net
Type: A
DNSpossibleanother.net
Type: A
DNSmountainbusiness.net
Type: A
DNSpossiblebusiness.net
Type: A
DNSmountainappear.net
Type: A
DNSpossibleappear.net
Type: A
DNSperhapsmanner.net
Type: A
DNSwindowmanner.net
Type: A
DNSperhapsanother.net
Type: A
DNSwindowanother.net
Type: A
DNSperhapsbusiness.net
Type: A
DNSwindowbusiness.net
Type: A
DNSperhapsappear.net
Type: A
DNSwindowappear.net
Type: A
DNSwintermanner.net
Type: A
DNSsubjectmanner.net
Type: A
DNSwinteranother.net
Type: A
DNSsubjectanother.net
Type: A
DNSwinterbusiness.net
Type: A
DNSsubjectbusiness.net
Type: A
DNSwinterappear.net
Type: A
DNSsubjectappear.net
Type: A
DNSfinishmanner.net
Type: A
DNSleavemanner.net
Type: A
DNSfinishanother.net
Type: A
DNSleaveanother.net
Type: A
DNSfinishbusiness.net
Type: A
DNSleavebusiness.net
Type: A
DNSfinishappear.net
Type: A
DNSleaveappear.net
Type: A
DNSsweetmanner.net
Type: A
DNSprobablymanner.net
Type: A
DNSsweetanother.net
Type: A
DNSprobablyanother.net
Type: A
DNSprobablybusiness.net
Type: A
DNSsweetappear.net
Type: A
DNSprobablyappear.net
Type: A
DNSseveralmanner.net
Type: A
DNSmaterialmanner.net
Type: A
DNSseveralanother.net
Type: A
DNSmaterialanother.net
Type: A
DNSseveralbusiness.net
Type: A
DNSmaterialbusiness.net
Type: A
DNSseveralappear.net
Type: A
DNSmaterialappear.net
Type: A
DNSseverainstead.net
Type: A
DNSlaughinstead.net
Type: A
DNSseveraexplain.net
Type: A
DNSlaughexplain.net
Type: A
DNSseverabright.net
Type: A
DNSlaughbright.net
Type: A
DNSseverainside.net
Type: A
DNSlaughinside.net
Type: A
DNSsimpleinstead.net
Type: A
DNSmotherinstead.net
Type: A
DNSsimpleexplain.net
Type: A
DNSmotherexplain.net
Type: A
DNSsimplebright.net
Type: A
DNSmotherbright.net
Type: A
DNSsimpleinside.net
Type: A
DNSmotherinside.net
Type: A
DNSmountaininstead.net
Type: A
DNSpossibleinstead.net
Type: A
DNSmountainexplain.net
Type: A
DNSpossibleexplain.net
Type: A
DNSmountainbright.net
Type: A
DNSpossiblebright.net
Type: A
DNSmountaininside.net
Type: A
DNSpossibleinside.net
Type: A
DNSperhapsinstead.net
Type: A
DNSwindowinstead.net
Type: A
DNSperhapsexplain.net
Type: A
DNSwindowexplain.net
Type: A
DNSperhapsbright.net
Type: A
HTTP GEThttp://sweetwomen.net/index.php
User-Agent:
HTTP GEThttp://materialpaint.net/index.php
User-Agent:
HTTP GEThttp://simplestream.net/index.php
User-Agent:
HTTP GEThttp://mountainstream.net/index.php
User-Agent:
HTTP GEThttp://mountainbottle.net/index.php
User-Agent:
HTTP GEThttp://windowstream.net/index.php
User-Agent:
HTTP GEThttp://sweetnothing.net/index.php
User-Agent:
HTTP GEThttp://motheranother.net/index.php
User-Agent:
HTTP GEThttp://simplebusiness.net/index.php
User-Agent:
HTTP GEThttp://mountainmanner.net/index.php
User-Agent:
HTTP GEThttp://sweetbusiness.net/index.php
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 184.168.221.104:80
Flows TCP192.168.1.1:1032 ➝ 208.100.26.234:80
Flows TCP192.168.1.1:1033 ➝ 141.8.225.124:80
Flows TCP192.168.1.1:1034 ➝ 207.148.248.143:80
Flows TCP192.168.1.1:1035 ➝ 195.22.28.197:80
Flows TCP192.168.1.1:1036 ➝ 216.21.239.197:80
Flows TCP192.168.1.1:1037 ➝ 72.52.4.119:80
Flows TCP192.168.1.1:1038 ➝ 50.63.202.39:80
Flows TCP192.168.1.1:1039 ➝ 72.52.4.119:80
Flows TCP192.168.1.1:1040 ➝ 208.100.26.234:80
Flows TCP192.168.1.1:1041 ➝ 45.16.128.217:80

Raw Pcap

Strings