Analysis Date2015-07-30 23:38:42
MD510b8a0840ca7396c230a9f47d4b7b4eb
SHA1cbe287eb7c13d7dd499e2544c39cf6099601fa99

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: fc30d63f44365ca70095f8fa4c791eea sha1: 4912ea659ff12134c2e89acae1d37b77f824dd7d size: 276480
Section.rdata md5: 3409adbe4dc91e3eeb8521289509a388 sha1: b45dafdb1603ac5f2f9f00c6ae7a8afeeb7ef2b2 size: 44032
Section.data md5: 5cc0eca7695bdf547445ef7010cbe92c sha1: 788f7c39581c401794099a700c75329f99e9f758 size: 6656
Section.reloc md5: 453b34edf79694f4f88c477b2c738be6 sha1: 1c89f2c85106f13f71be90dab2810969b71f048f size: 21504
Timestamp2015-05-21 04:30:59
PackerMicrosoft Visual C++ ?.?
PEhash2fe027e79dc39bbeb69a83ff9c1c7892bcb6d294
IMPhashc17d27556b048bca7849ccc37c518ea4
AVRisingno_virus
AVMcafeeRDN/Generic.dx!d2o
AVAvira (antivir)TR/Crypt.ZPACK.59977
AVTwisterno_virus
AVAd-AwareGen:Variant.Diley.1
AVAlwil (avast)Malware-gen:Win32:Malware-gen
AVEset (nod32)Win32/Bayrob.Y
AVGrisoft (avg)Win32/Cryptor
AVSymantecDownloader.Upatre!g15
AVFortinetW32/Babrob.Y!tr
AVBitDefenderGen:Variant.Diley.1
AVK7Trojan ( 004c2d921 )
AVMicrosoft Security Essentialsno_virus
AVMicroWorld (escan)Gen:Variant.Diley.1
AVMalwareBytesTrojan.Agent.KVTGen
AVAuthentiumW32/Scar.V.gen!Eldorado
AVFrisk (f-prot)no_virus
AVIkarusTrojan.Win32.Bayrob
AVEmsisoftGen:Variant.Diley.1
AVZillya!no_virus
AVKasperskyTrojan.Win32.Scar.kjzj
AVTrend MicroTROJ_BAYROB.SM0
AVCAT (quickheal)no_virus
AVVirusBlokAda (vba32)no_virus
AVPadvishno_virus
AVBullGuardGen:Variant.Diley.1
AVArcabit (arcavir)Gen:Variant.Diley.1
AVCA (E-Trust Ino)no_virus
AVClamAVno_virus
AVDr. WebTrojan.DownLoader14.33073
AVF-SecureGen:Variant.Diley.1

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates FileC:\WINDOWS\pobugbqgc\aino0psudk
Creates FileC:\pobugbqgc\cfi1m8cn2opviue1u.exe
Creates FileC:\pobugbqgc\aino0psudk
Deletes FileC:\WINDOWS\pobugbqgc\aino0psudk
Creates ProcessC:\pobugbqgc\cfi1m8cn2opviue1u.exe

Process
↳ C:\pobugbqgc\cfi1m8cn2opviue1u.exe

RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Sharing Background Backup Endpoint WWAN ➝
C:\pobugbqgc\epxmsdu.exe
Creates FileC:\pobugbqgc\vkcnis0e
Creates FileC:\WINDOWS\pobugbqgc\aino0psudk
Creates FileC:\pobugbqgc\aino0psudk
Creates FilePIPE\lsarpc
Creates FileC:\pobugbqgc\epxmsdu.exe
Deletes FileC:\WINDOWS\pobugbqgc\aino0psudk
Creates ProcessC:\pobugbqgc\epxmsdu.exe
Creates ServiceDrive Secondary Hardware Experience - C:\pobugbqgc\epxmsdu.exe

Process
↳ C:\WINDOWS\system32\svchost.exe

Process
↳ Pid 804

Process
↳ Pid 848

Process
↳ C:\WINDOWS\System32\svchost.exe

Creates FileC:\WINDOWS\system32\WBEM\Logs\wbemess.log

Process
↳ Pid 1204

Process
↳ C:\WINDOWS\system32\spoolsv.exe

RegistryHKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\BeepEnabled ➝
NULL
RegistryHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\Print\TypesSupported ➝
7
RegistryHKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers\SymbolicLinkValue ➝
NULL
RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory ➝
C:\WINDOWS\System32\spool\PRINTERS\\x00

Process
↳ Pid 1844

Process
↳ Pid 1132

Process
↳ C:\pobugbqgc\epxmsdu.exe

Creates FileC:\pobugbqgc\vkcnis0e
Creates FileC:\WINDOWS\pobugbqgc\aino0psudk
Creates Filepipe\net\NtControlPipe10
Creates FileC:\pobugbqgc\ghn0oig6g
Creates FileC:\pobugbqgc\aino0psudk
Creates File\Device\Afd\Endpoint
Creates FileC:\pobugbqgc\ohcuvjjpi.exe
Deletes FileC:\WINDOWS\pobugbqgc\aino0psudk
Creates Processkhrpuggjsgdg "c:\pobugbqgc\epxmsdu.exe"

Process
↳ C:\pobugbqgc\epxmsdu.exe

Creates FileC:\WINDOWS\pobugbqgc\aino0psudk
Creates FileC:\pobugbqgc\aino0psudk
Deletes FileC:\WINDOWS\pobugbqgc\aino0psudk

Process
↳ khrpuggjsgdg "c:\pobugbqgc\epxmsdu.exe"

Creates FileC:\WINDOWS\pobugbqgc\aino0psudk
Creates FileC:\pobugbqgc\aino0psudk
Deletes FileC:\WINDOWS\pobugbqgc\aino0psudk

Network Details:

DNSfreshpower.net
Type: A
195.149.84.101
DNSfreshpower.net
Type: A
195.149.84.100
DNScrowdfamous.net
Type: A
95.211.230.75
DNScrowdpower.net
Type: A
162.244.253.60
DNSthoughtpower.net
Type: A
23.229.204.192
DNSwaterpower.net
Type: A
72.52.4.120
DNSwomanpower.net
Type: A
72.52.4.120
DNSpartypower.net
Type: A
66.151.181.49
DNSfightpower.net
Type: A
64.99.80.30
DNSmelbourneit.hotkeysparking.com
Type: A
8.5.1.16
DNSfightcountry.net
Type: A
184.168.221.55
DNSexperiencefamous.net
Type: A
DNSexperiencepower.net
Type: A
DNSfreshcountry.net
Type: A
DNSexperiencecountry.net
Type: A
DNSgentlemancentury.net
Type: A
DNSalreadycentury.net
Type: A
DNSgentlemanfamous.net
Type: A
DNSalreadyfamous.net
Type: A
DNSgentlemanpower.net
Type: A
DNSalreadypower.net
Type: A
DNSgentlemancountry.net
Type: A
DNSalreadycountry.net
Type: A
DNSfollowcentury.net
Type: A
DNSmembercentury.net
Type: A
DNSfollowfamous.net
Type: A
DNSmemberfamous.net
Type: A
DNSfollowpower.net
Type: A
DNSmemberpower.net
Type: A
DNSfollowcountry.net
Type: A
DNSmembercountry.net
Type: A
DNSbegincentury.net
Type: A
DNSknowncentury.net
Type: A
DNSbeginfamous.net
Type: A
DNSknownfamous.net
Type: A
DNSbeginpower.net
Type: A
DNSknownpower.net
Type: A
DNSbegincountry.net
Type: A
DNSknowncountry.net
Type: A
DNSsummercentury.net
Type: A
DNScrowdcentury.net
Type: A
DNSsummerfamous.net
Type: A
DNSsummerpower.net
Type: A
DNSsummercountry.net
Type: A
DNScrowdcountry.net
Type: A
DNSthoughtcentury.net
Type: A
DNSwatercentury.net
Type: A
DNSthoughtfamous.net
Type: A
DNSwaterfamous.net
Type: A
DNSthoughtcountry.net
Type: A
DNSwatercountry.net
Type: A
DNSwomancentury.net
Type: A
DNSsmokecentury.net
Type: A
DNSwomanfamous.net
Type: A
DNSsmokefamous.net
Type: A
DNSsmokepower.net
Type: A
DNSwomancountry.net
Type: A
DNSsmokecountry.net
Type: A
DNSpartycentury.net
Type: A
DNSfightcentury.net
Type: A
DNSpartyfamous.net
Type: A
DNSfightfamous.net
Type: A
DNSpartycountry.net
Type: A
DNSfreshsurprise.net
Type: A
DNSexperiencesurprise.net
Type: A
DNSfreshbeside.net
Type: A
DNSexperiencebeside.net
Type: A
DNSfreshletter.net
Type: A
DNSexperienceletter.net
Type: A
DNSfreshdifferent.net
Type: A
DNSexperiencedifferent.net
Type: A
DNSgentlemansurprise.net
Type: A
DNSalreadysurprise.net
Type: A
DNSgentlemanbeside.net
Type: A
DNSalreadybeside.net
Type: A
DNSgentlemanletter.net
Type: A
DNSalreadyletter.net
Type: A
DNSgentlemandifferent.net
Type: A
DNSalreadydifferent.net
Type: A
DNSfollowsurprise.net
Type: A
DNSmembersurprise.net
Type: A
DNSfollowbeside.net
Type: A
DNSmemberbeside.net
Type: A
DNSfollowletter.net
Type: A
DNSmemberletter.net
Type: A
DNSfollowdifferent.net
Type: A
DNSmemberdifferent.net
Type: A
HTTP GEThttp://freshpower.net/index.php
User-Agent:
HTTP GEThttp://crowdfamous.net/index.php
User-Agent:
HTTP GEThttp://crowdpower.net/index.php
User-Agent:
HTTP GEThttp://thoughtpower.net/index.php
User-Agent:
HTTP GEThttp://waterpower.net/index.php
User-Agent:
HTTP GEThttp://womanpower.net/index.php
User-Agent:
HTTP GEThttp://partypower.net/index.php
User-Agent:
HTTP GEThttp://fightpower.net/index.php
User-Agent:
HTTP GEThttp://partycountry.net/index.php
User-Agent:
HTTP GEThttp://fightcountry.net/index.php
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 195.149.84.101:80
Flows TCP192.168.1.1:1032 ➝ 95.211.230.75:80
Flows TCP192.168.1.1:1033 ➝ 162.244.253.60:80
Flows TCP192.168.1.1:1034 ➝ 23.229.204.192:80
Flows TCP192.168.1.1:1035 ➝ 72.52.4.120:80
Flows TCP192.168.1.1:1036 ➝ 72.52.4.120:80
Flows TCP192.168.1.1:1037 ➝ 66.151.181.49:80
Flows TCP192.168.1.1:1038 ➝ 64.99.80.30:80
Flows TCP192.168.1.1:1039 ➝ 8.5.1.16:80
Flows TCP192.168.1.1:1040 ➝ 184.168.221.55:80

Raw Pcap
0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2066   : close..Host: f
0x00000040 (00064)   72657368 706f7765 722e6e65 740d0a0d   reshpower.net...
0x00000050 (00080)   0a                                    .

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2063   : close..Host: c
0x00000040 (00064)   726f7764 66616d6f 75732e6e 65740d0a   rowdfamous.net..
0x00000050 (00080)   0d0a                                  ..

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2063   : close..Host: c
0x00000040 (00064)   726f7764 706f7765 722e6e65 740d0a0d   rowdpower.net...
0x00000050 (00080)   0a0a                                  ..

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2074   : close..Host: t
0x00000040 (00064)   686f7567 6874706f 7765722e 6e65740d   houghtpower.net.
0x00000050 (00080)   0a0d0a                                ...

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2077   : close..Host: w
0x00000040 (00064)   61746572 706f7765 722e6e65 740d0a0d   aterpower.net...
0x00000050 (00080)   0a0d0a                                ...

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2077   : close..Host: w
0x00000040 (00064)   6f6d616e 706f7765 722e6e65 740d0a0d   omanpower.net...
0x00000050 (00080)   0a0d0a                                ...

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2070   : close..Host: p
0x00000040 (00064)   61727479 706f7765 722e6e65 740d0a0d   artypower.net...
0x00000050 (00080)   0a0d0a                                ...

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2066   : close..Host: f
0x00000040 (00064)   69676874 706f7765 722e6e65 740d0a0d   ightpower.net...
0x00000050 (00080)   0a0d0a                                ...

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2070   : close..Host: p
0x00000040 (00064)   61727479 636f756e 7472792e 6e65740d   artycountry.net.
0x00000050 (00080)   0a0d0a                                ...

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2066   : close..Host: f
0x00000040 (00064)   69676874 636f756e 7472792e 6e65740d   ightcountry.net.
0x00000050 (00080)   0a0d0a                                ...


Strings