Analysis Date | 2015-11-02 16:04:53 |
---|---|
MD5 | 546b3c9f3d028dd19d24c5a72d5347eb |
SHA1 | ea068ed2e734a3c725f2e525558eca705184b982 |
Static Details:
File type | PE32 executable for MS Windows (GUI) Intel 80386 32-bit | |
---|---|---|
Section | .text md5: 6f2669abb5f970b303b864ecc2300129 sha1: 70f29a41e2e460a1bc24abd78fb0d33695acacec size: 795136 | |
Section | .rdata md5: 51aefb23060a3658061f7194719d4962 sha1: f6e8888e0cf606e3b248b0588a6b1980d619e105 size: 57344 | |
Section | .data md5: a3473c75e28088ab38871bdca4a5d6fd sha1: 07c1945938c03eb054e50b4f64c3cb58ea01c7fb size: 398848 | |
Timestamp | 2014-09-05 10:45:05 | |
Packer | Microsoft Visual C++ ?.? | |
PEhash | f55cd038eac273f50d54d167105ee189ca0342b1 | |
IMPhash | 3572e80c027d3996c08819969b9e26af | |
AV | Ad-Aware | Gen:Variant.Symmi.22722 |
AV | Grisoft (avg) | Win32/Cryptor |
AV | CAT (quickheal) | no_virus |
AV | Ikarus | no_virus |
AV | Avira (antivir) | TR/Crypt.ZPACK.62933 |
AV | K7 | Trojan ( 004cd0081 ) |
AV | ClamAV | no_virus |
AV | Kaspersky | Trojan.Win32.Generic |
AV | Arcabit (arcavir) | Gen:Variant.Symmi.22722 |
AV | MalwareBytes | no_virus |
AV | Dr. Web | no_virus |
AV | Mcafee | no_virus |
AV | BitDefender | Gen:Variant.Symmi.22722 |
AV | Microsoft Security Essentials | TrojanSpy:Win32/Nivdort.AE |
AV | Emsisoft | Gen:Variant.Symmi.22722 |
AV | MicroWorld (escan) | Gen:Variant.Symmi.22722 |
AV | Alwil (avast) | Kryptik-OSY [Trj] |
AV | Padvish | no_virus |
AV | Eset (nod32) | Win32/Kryptik.CCLE |
AV | Rising | no_virus |
AV | BullGuard | Gen:Variant.Symmi.22722 |
AV | Fortinet | W32/Kryptik.DDQD!tr |
AV | Symantec | Downloader.Upatre!g15 |
AV | Authentium | W32/Nivdort.A.gen!Eldorado |
AV | Trend Micro | TROJ_WONTON.SMJ1 |
AV | Frisk (f-prot) | no_virus |
AV | Twister | no_virus |
AV | CA (E-Trust Ino) | no_virus |
AV | VirusBlokAda (vba32) | no_virus |
AV | F-Secure | Gen:Variant.Symmi.22722 |
AV | Zillya! | no_virus |
Runtime Details:
Screenshot | ![]() |
---|
Process
↳ C:\malware.exe
Creates File | C:\WINDOWS\system32\efbfbdsnhqj\tst |
---|---|
Creates File | C:\Documents and Settings\Administrator\Local Settings\Temp\qijvi61lsqjzmtpqpk.exe |
Creates Process | C:\Documents and Settings\Administrator\Local Settings\Temp\qijvi61lsqjzmtpqpk.exe |
Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\qijvi61lsqjzmtpqpk.exe
Registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Interactive Connections List Auto ➝ C:\WINDOWS\system32\seathvj.exe |
---|---|
Creates File | C:\WINDOWS\system32\drivers\etc\hosts |
Creates File | C:\WINDOWS\system32\efbfbdsnhqj\etc |
Creates File | C:\WINDOWS\system32\efbfbdsnhqj\lck |
Creates File | C:\WINDOWS\system32\efbfbdsnhqj\tst |
Creates File | C:\WINDOWS\system32\seathvj.exe |
Deletes File | C:\WINDOWS\system32\\drivers\etc\hosts |
Creates Process | C:\WINDOWS\system32\seathvj.exe |
Creates Service | Audio Driver DHCP Fax Link-Layer - C:\WINDOWS\system32\seathvj.exe |
Process
↳ C:\WINDOWS\system32\svchost.exe
Process
↳ Pid 804
Process
↳ Pid 852
Process
↳ C:\WINDOWS\System32\svchost.exe
Registry | HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM\List of event-active namespaces ➝ NULL |
---|---|
Creates File | PIPE\lsarpc |
Creates File | C:\WINDOWS\system32\WBEM\Repository\$WinMgmt.CFG |
Creates File | C:\WINDOWS\system32\WBEM\Logs\wbemess.log |
Process
↳ Pid 1208
Process
↳ C:\WINDOWS\system32\spoolsv.exe
Registry | HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\BeepEnabled ➝ NULL |
---|---|
Registry | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\Print\TypesSupported ➝ 7 |
Registry | HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers\SymbolicLinkValue ➝ NULL |
Registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory ➝ C:\WINDOWS\System32\spool\PRINTERS\\x00 |
Process
↳ Pid 1160
Process
↳ C:\WINDOWS\system32\seathvj.exe
Registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center\FirewallDisableNotify ➝ 1 |
---|---|
Creates File | C:\WINDOWS\TEMP\qijvi61rvhjz.exe |
Creates File | C:\WINDOWS\system32\efbfbdsnhqj\run |
Creates File | C:\WINDOWS\system32\efbfbdsnhqj\rng |
Creates File | C:\WINDOWS\system32\efbfbdsnhqj\tst |
Creates File | C:\WINDOWS\system32\efbfbdsnhqj\cfg |
Creates File | pipe\net\NtControlPipe10 |
Creates File | C:\WINDOWS\system32\efbfbdsnhqj\lck |
Creates File | C:\WINDOWS\system32\vphxcvk.exe |
Creates File | \Device\Afd\Endpoint |
Creates Process | C:\WINDOWS\TEMP\qijvi61rvhjz.exe -r 46414 tcp |
Creates Process | WATCHDOGPROC "c:\windows\system32\seathvj.exe" |
Process
↳ C:\WINDOWS\system32\seathvj.exe
Creates File | C:\WINDOWS\system32\efbfbdsnhqj\tst |
---|
Process
↳ WATCHDOGPROC "c:\windows\system32\seathvj.exe"
Creates File | C:\WINDOWS\system32\efbfbdsnhqj\tst |
---|
Process
↳ C:\WINDOWS\TEMP\qijvi61rvhjz.exe -r 46414 tcp
Creates File | \Device\Afd\Endpoint |
---|---|
Winsock DNS | 239.255.255.250 |
Network Details:
DNS | saltsecond.net Type: A 74.220.199.6 |
---|---|
DNS | wishfish.net Type: A 50.63.202.55 |
DNS | deadwing.net Type: A 85.25.214.16 |
DNS | deadlady.net Type: A 195.22.26.253 |
DNS | deadlady.net Type: A 195.22.26.254 |
DNS | deadlady.net Type: A 195.22.26.231 |
DNS | deadlady.net Type: A 195.22.26.252 |
DNS | rocklady.net Type: A 64.61.199.44 |
DNS | deadfish.net Type: A 69.172.201.208 |
DNS | rockfish.net Type: A 96.45.82.90 |
DNS | rockfish.net Type: A 96.45.82.194 |
DNS | rockfish.net Type: A 96.45.83.91 |
DNS | rockfish.net Type: A 96.45.83.235 |
DNS | wronglady.net Type: A 208.100.26.234 |
DNS | southcity.net Type: A 207.148.248.143 |
DNS | spotcity.net Type: A 91.195.240.101 |
DNS | saltcity.net Type: A 184.168.221.55 |
DNS | gladcity.net Type: A 65.254.248.183 |
DNS | visitcity.net Type: A 104.193.110.28 |
DNS | watchcity.net Type: A 207.148.248.143 |
DNS | faircity.net Type: A 80.77.120.47 |
DNS | dreamgrow.net Type: A 213.180.31.141 |
DNS | dreamcity.net Type: A 72.52.4.119 |
DNS | thiscity.net Type: A 121.42.126.34 |
DNS | southblood.net Type: A |
DNS | enemydont.net Type: A |
DNS | sellsmall.net Type: A |
DNS | wheelreply.net Type: A |
DNS | joinfish.net Type: A |
DNS | rockwing.net Type: A |
DNS | deadpast.net Type: A |
DNS | rockpast.net Type: A |
DNS | wrongwing.net Type: A |
DNS | madewing.net Type: A |
DNS | wrongpast.net Type: A |
DNS | madepast.net Type: A |
DNS | madelady.net Type: A |
DNS | wrongfish.net Type: A |
DNS | madefish.net Type: A |
DNS | arivegrow.net Type: A |
DNS | southgrow.net Type: A |
DNS | arivetear.net Type: A |
DNS | southtear.net Type: A |
DNS | arivethank.net Type: A |
DNS | souththank.net Type: A |
DNS | arivecity.net Type: A |
DNS | upongrow.net Type: A |
DNS | whichgrow.net Type: A |
DNS | upontear.net Type: A |
DNS | whichtear.net Type: A |
DNS | uponthank.net Type: A |
DNS | whichthank.net Type: A |
DNS | uponcity.net Type: A |
DNS | whichcity.net Type: A |
DNS | spotgrow.net Type: A |
DNS | saltgrow.net Type: A |
DNS | spottear.net Type: A |
DNS | salttear.net Type: A |
DNS | spotthank.net Type: A |
DNS | saltthank.net Type: A |
DNS | gladgrow.net Type: A |
DNS | takengrow.net Type: A |
DNS | gladtear.net Type: A |
DNS | takentear.net Type: A |
DNS | gladthank.net Type: A |
DNS | takenthank.net Type: A |
DNS | takencity.net Type: A |
DNS | equalgrow.net Type: A |
DNS | groupgrow.net Type: A |
DNS | equaltear.net Type: A |
DNS | grouptear.net Type: A |
DNS | equalthank.net Type: A |
DNS | groupthank.net Type: A |
DNS | equalcity.net Type: A |
DNS | groupcity.net Type: A |
DNS | spokegrow.net Type: A |
DNS | visitgrow.net Type: A |
DNS | spoketear.net Type: A |
DNS | visittear.net Type: A |
DNS | spokethank.net Type: A |
DNS | visitthank.net Type: A |
DNS | spokecity.net Type: A |
DNS | watchgrow.net Type: A |
DNS | fairgrow.net Type: A |
DNS | watchtear.net Type: A |
DNS | fairtear.net Type: A |
DNS | watchthank.net Type: A |
DNS | fairthank.net Type: A |
DNS | thisgrow.net Type: A |
DNS | dreamtear.net Type: A |
DNS | thistear.net Type: A |
DNS | dreamthank.net Type: A |
DNS | thisthank.net Type: A |
DNS | arivepure.net Type: A |
DNS | southpure.net Type: A |
DNS | arivemarch.net Type: A |
HTTP GET | http://saltsecond.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://wishfish.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://deadwing.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://deadlady.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://rocklady.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://deadfish.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://rockfish.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://wronglady.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://southcity.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://spotcity.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://saltcity.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://gladcity.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://visitcity.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://watchcity.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://faircity.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://dreamgrow.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://dreamcity.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://thiscity.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://saltsecond.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://wishfish.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://deadwing.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://deadlady.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://rocklady.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://deadfish.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://rockfish.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://wronglady.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://southcity.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://spotcity.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://saltcity.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://gladcity.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://visitcity.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://watchcity.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://faircity.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://dreamgrow.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://dreamcity.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
HTTP GET | http://thiscity.net/index.php?method=validate&mode=sox&v=031&sox=3c18da00 User-Agent: |
Flows TCP | 192.168.1.1:1036 ➝ 74.220.199.6:80 |
Flows TCP | 192.168.1.1:1037 ➝ 50.63.202.55:80 |
Flows TCP | 192.168.1.1:1038 ➝ 85.25.214.16:80 |
Flows TCP | 192.168.1.1:1040 ➝ 195.22.26.253:80 |
Flows TCP | 192.168.1.1:1041 ➝ 64.61.199.44:80 |
Flows TCP | 192.168.1.1:1042 ➝ 69.172.201.208:80 |
Flows TCP | 192.168.1.1:1043 ➝ 96.45.82.90:80 |
Flows TCP | 192.168.1.1:1044 ➝ 208.100.26.234:80 |
Flows TCP | 192.168.1.1:1045 ➝ 207.148.248.143:80 |
Flows TCP | 192.168.1.1:1046 ➝ 91.195.240.101:80 |
Flows TCP | 192.168.1.1:1047 ➝ 184.168.221.55:80 |
Flows TCP | 192.168.1.1:1048 ➝ 65.254.248.183:80 |
Flows TCP | 192.168.1.1:1049 ➝ 104.193.110.28:80 |
Flows TCP | 192.168.1.1:1050 ➝ 207.148.248.143:80 |
Flows TCP | 192.168.1.1:1051 ➝ 80.77.120.47:80 |
Flows TCP | 192.168.1.1:1052 ➝ 213.180.31.141:80 |
Flows TCP | 192.168.1.1:1053 ➝ 72.52.4.119:80 |
Flows TCP | 192.168.1.1:1054 ➝ 121.42.126.34:80 |
Flows TCP | 192.168.1.1:1055 ➝ 74.220.199.6:80 |
Flows TCP | 192.168.1.1:1056 ➝ 50.63.202.55:80 |
Flows TCP | 192.168.1.1:1057 ➝ 85.25.214.16:80 |
Flows TCP | 192.168.1.1:1058 ➝ 195.22.26.253:80 |
Flows TCP | 192.168.1.1:1059 ➝ 64.61.199.44:80 |
Flows TCP | 192.168.1.1:1060 ➝ 69.172.201.208:80 |
Flows TCP | 192.168.1.1:1061 ➝ 96.45.82.90:80 |
Flows TCP | 192.168.1.1:1062 ➝ 208.100.26.234:80 |
Flows TCP | 192.168.1.1:1063 ➝ 207.148.248.143:80 |
Flows TCP | 192.168.1.1:1064 ➝ 91.195.240.101:80 |
Flows TCP | 192.168.1.1:1065 ➝ 184.168.221.55:80 |
Flows TCP | 192.168.1.1:1066 ➝ 65.254.248.183:80 |
Flows TCP | 192.168.1.1:1067 ➝ 104.193.110.28:80 |
Flows TCP | 192.168.1.1:1068 ➝ 207.148.248.143:80 |
Flows TCP | 192.168.1.1:1069 ➝ 80.77.120.47:80 |
Flows TCP | 192.168.1.1:1070 ➝ 213.180.31.141:80 |
Flows TCP | 192.168.1.1:1071 ➝ 72.52.4.119:80 |
Flows TCP | 192.168.1.1:1072 ➝ 121.42.126.34:80 |
Raw Pcap
Strings