Analysis Date2015-10-06 10:37:08
MD564f7a646a79da1b297354a9ec47a845a
SHA1cff5266e564c942f01d4aa5cce6f7dc4bba5fd54

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 2f6eacb07afedaedf4e5126b6436bd1e sha1: f996df4d5b3f7c92ac1448c134bd771d2f170f92 size: 252928
Section.rdata md5: 7588ddbf2f86663f4026fcfab6ccd866 sha1: 3723dadd9c32b902e0d31204817cdb477e43b7e4 size: 40448
Section.data md5: 92db6f61df1dfd3d1bfe44517464d330 sha1: e1408512e3688ab0aac457bf7e09b556a92c3f33 size: 7168
Section.reloc md5: 056f91090e15a8017bc2a6b03db0375a sha1: d6d7eea79fe3aaee3c69b3d5738e790da33a17f5 size: 16384
Timestamp2015-05-21 04:48:35
PackerMicrosoft Visual C++ ?.?
PEhash303c29e2b97a3a56940de18ec1ef35460fa41d9b
IMPhash3987042cdb859403e65a38356cc09ca4
AVCA (E-Trust Ino)no_virus
AVRisingno_virus
AVMcafeeTrojan-FGIJ!64F7A646A79D
AVAvira (antivir)TR/Crypt.ZPACK.83430
AVTwisterno_virus
AVAd-AwareGen:Variant.Diley.1
AVAlwil (avast)Malware-gen:Win32:Malware-gen
AVEset (nod32)Win32/Bayrob.Y
AVGrisoft (avg)Win32/Cryptor
AVSymantecDownloader.Upatre!g15
AVFortinetW32/Babrob.Y!tr
AVBitDefenderGen:Variant.Diley.1
AVK7Trojan ( 004c77f41 )
AVMicrosoft Security EssentialsError Scanning File
AVMicroWorld (escan)Gen:Variant.Diley.1
AVMalwareBytesno_virus
AVAuthentiumW32/Trojan.FPOZ-8300
AVFrisk (f-prot)no_virus
AVIkarusTrojan.Win32.Bayrob
AVEmsisoftGen:Variant.Diley.1
AVZillya!no_virus
AVKasperskyTrojan.Win32.Generic
AVTrend Microno_virus
AVCAT (quickheal)no_virus
AVVirusBlokAda (vba32)no_virus
AVPadvishno_virus
AVBullGuardGen:Variant.Diley.1
AVArcabit (arcavir)Gen:Variant.Diley.1
AVClamAVno_virus
AVDr. WebTrojan.DownLoader16.39594
AVF-SecureGen:Variant.Diley.1

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates FileC:\gtthfvqozamke\eqvshxywap
Creates FileC:\gtthfvqozamke\u9n1m8cew3smadepaytu.exe
Creates FileC:\WINDOWS\gtthfvqozamke\eqvshxywap
Deletes FileC:\WINDOWS\gtthfvqozamke\eqvshxywap
Creates ProcessC:\gtthfvqozamke\u9n1m8cew3smadepaytu.exe

Process
↳ C:\gtthfvqozamke\u9n1m8cew3smadepaytu.exe

RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Adapter Smart Auto Upgrade Registrar ➝
C:\gtthfvqozamke\mmvfugf.exe
Creates FileC:\gtthfvqozamke\mmvfugf.exe
Creates FileC:\gtthfvqozamke\eqvshxywap
Creates FilePIPE\lsarpc
Creates FileC:\WINDOWS\gtthfvqozamke\eqvshxywap
Creates FileC:\gtthfvqozamke\hgqgk8ej4
Deletes FileC:\WINDOWS\gtthfvqozamke\eqvshxywap
Creates ProcessC:\gtthfvqozamke\mmvfugf.exe
Creates ServiceRegistry Helper Disk Browser Workstation - C:\gtthfvqozamke\mmvfugf.exe

Process
↳ C:\WINDOWS\system32\svchost.exe

Process
↳ Pid 804

Process
↳ Pid 848

Process
↳ C:\WINDOWS\System32\svchost.exe

Process
↳ Pid 1204

Process
↳ C:\WINDOWS\system32\spoolsv.exe

Process
↳ Pid 1868

Process
↳ Pid 1128

Process
↳ C:\gtthfvqozamke\mmvfugf.exe

Creates Filepipe\net\NtControlPipe10
Creates FileC:\gtthfvqozamke\kubtzjeyi.exe
Creates FileC:\gtthfvqozamke\eqvshxywap
Creates FileC:\WINDOWS\gtthfvqozamke\eqvshxywap
Creates File\Device\Afd\Endpoint
Creates FileC:\gtthfvqozamke\v1bqlksy
Creates FileC:\gtthfvqozamke\hgqgk8ej4
Deletes FileC:\WINDOWS\gtthfvqozamke\eqvshxywap
Creates Processgc1ncwfitnye "c:\gtthfvqozamke\mmvfugf.exe"

Process
↳ C:\gtthfvqozamke\mmvfugf.exe

Creates FileC:\gtthfvqozamke\eqvshxywap
Creates FileC:\WINDOWS\gtthfvqozamke\eqvshxywap
Deletes FileC:\WINDOWS\gtthfvqozamke\eqvshxywap

Process
↳ gc1ncwfitnye "c:\gtthfvqozamke\mmvfugf.exe"

Creates FileC:\gtthfvqozamke\eqvshxywap
Creates FileC:\WINDOWS\gtthfvqozamke\eqvshxywap
Deletes FileC:\WINDOWS\gtthfvqozamke\eqvshxywap

Network Details:

DNSstreetshoulder.net
Type: A
95.211.230.75
DNSgatherabove.net
Type: A
72.52.4.90
DNSmelbourneit.hotkeysparking.com
Type: A
8.5.1.16
DNSbreadabove.net
Type: A
195.22.26.253
DNSbreadabove.net
Type: A
195.22.26.254
DNSbreadabove.net
Type: A
195.22.26.231
DNSbreadabove.net
Type: A
195.22.26.252
DNSchiefshore.net
Type: A
162.255.119.250
DNSchiefwritten.net
Type: A
98.139.135.129
DNScollegewritten.net
Type: A
162.255.119.250
DNScollegedollar.net
Type: A
162.255.119.250
DNSchiefrealize.net
Type: A
72.52.4.90
DNSalonedollar.net
Type: A
208.100.26.234
DNSmorningdollar.net
Type: A
50.63.202.48
DNScaptainuntil.net
Type: A
DNSlargeabove.net
Type: A
DNScaptainabove.net
Type: A
DNSlargeshoulder.net
Type: A
DNScaptainshoulder.net
Type: A
DNSlargefinger.net
Type: A
DNScaptainfinger.net
Type: A
DNSrecorduntil.net
Type: A
DNSelectricuntil.net
Type: A
DNSrecordabove.net
Type: A
DNSelectricabove.net
Type: A
DNSrecordshoulder.net
Type: A
DNSelectricshoulder.net
Type: A
DNSrecordfinger.net
Type: A
DNSelectricfinger.net
Type: A
DNSstreetuntil.net
Type: A
DNStradeuntil.net
Type: A
DNSstreetabove.net
Type: A
DNStradeabove.net
Type: A
DNStradeshoulder.net
Type: A
DNSstreetfinger.net
Type: A
DNStradefinger.net
Type: A
DNSbetteruntil.net
Type: A
DNSgatheruntil.net
Type: A
DNSbetterabove.net
Type: A
DNSbettershoulder.net
Type: A
DNSgathershoulder.net
Type: A
DNSbetterfinger.net
Type: A
DNSgatherfinger.net
Type: A
DNSflieruntil.net
Type: A
DNSbreaduntil.net
Type: A
DNSflierabove.net
Type: A
DNSfliershoulder.net
Type: A
DNSbreadshoulder.net
Type: A
DNSflierfinger.net
Type: A
DNSbreadfinger.net
Type: A
DNSquietuntil.net
Type: A
DNSseasonuntil.net
Type: A
DNSquietabove.net
Type: A
DNSseasonabove.net
Type: A
DNSquietshoulder.net
Type: A
DNSseasonshoulder.net
Type: A
DNSquietfinger.net
Type: A
DNSseasonfinger.net
Type: A
DNSthinkshore.net
Type: A
DNSpresentshore.net
Type: A
DNSthinkwritten.net
Type: A
DNSpresentwritten.net
Type: A
DNSthinkdollar.net
Type: A
DNSpresentdollar.net
Type: A
DNSthinkrealize.net
Type: A
DNSpresentrealize.net
Type: A
DNScollegeshore.net
Type: A
DNSchiefdollar.net
Type: A
DNScollegerealize.net
Type: A
DNSoftenshore.net
Type: A
DNSaloneshore.net
Type: A
DNSoftenwritten.net
Type: A
DNSalonewritten.net
Type: A
DNSoftendollar.net
Type: A
DNSoftenrealize.net
Type: A
DNSalonerealize.net
Type: A
DNSmiddleshore.net
Type: A
DNStwelveshore.net
Type: A
DNSmiddlewritten.net
Type: A
DNStwelvewritten.net
Type: A
DNSmiddledollar.net
Type: A
DNStwelvedollar.net
Type: A
DNSmiddlerealize.net
Type: A
DNStwelverealize.net
Type: A
DNSrathershore.net
Type: A
DNSmorningshore.net
Type: A
DNSratherwritten.net
Type: A
DNSmorningwritten.net
Type: A
DNSratherdollar.net
Type: A
HTTP GEThttp://streetshoulder.net/index.php
User-Agent:
HTTP GEThttp://gatherabove.net/index.php
User-Agent:
HTTP GEThttp://gatherfinger.net/index.php
User-Agent:
HTTP GEThttp://breadabove.net/index.php
User-Agent:
HTTP GEThttp://chiefshore.net/index.php
User-Agent:
HTTP GEThttp://chiefwritten.net/index.php
User-Agent:
HTTP GEThttp://collegewritten.net/index.php
User-Agent:
HTTP GEThttp://collegedollar.net/index.php
User-Agent:
HTTP GEThttp://chiefrealize.net/index.php
User-Agent:
HTTP GEThttp://alonedollar.net/index.php
User-Agent:
HTTP GEThttp://morningdollar.net/index.php
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 95.211.230.75:80
Flows TCP192.168.1.1:1032 ➝ 72.52.4.90:80
Flows TCP192.168.1.1:1033 ➝ 8.5.1.16:80
Flows TCP192.168.1.1:1034 ➝ 195.22.26.253:80
Flows TCP192.168.1.1:1035 ➝ 162.255.119.250:80
Flows TCP192.168.1.1:1036 ➝ 98.139.135.129:80
Flows TCP192.168.1.1:1037 ➝ 162.255.119.250:80
Flows TCP192.168.1.1:1038 ➝ 162.255.119.250:80
Flows TCP192.168.1.1:1039 ➝ 72.52.4.90:80
Flows TCP192.168.1.1:1040 ➝ 208.100.26.234:80
Flows TCP192.168.1.1:1041 ➝ 50.63.202.48:80

Raw Pcap

Strings