Analysis Date2014-06-20 09:52:02
MD5c44eacd0793c6a572facf5d95c3edef9
SHA1eaca17a2bc7ae5b807aba7f9ec4443cc4b8219e8

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386
Section.text md5: 7f7fb18bb79feacb3c6f7e05c013335c sha1: 482571e430ec1c61a970483c6e17de2411646bec size: 180224
Section.rdata md5: c81fce2a2dab27738b6afdfc8ec760b9 sha1: 895827e7a4fd53ed450460b66633b695bad6d621 size: 2048
Section.data md5: 32d00aee31508ba08f78e77d60baf463 sha1: b7724c4f0b73c3a03ae7665a2d6e130f571b7ac8 size: 17408
Section.tls md5: c7469c71782551f86c26efa9c07ee837 sha1: 396cf0c0bb8158cc0db8ca1f4fd62ec757aa46b8 size: 512
Timestamp2005-09-08 11:59:06
VersionPrivateBuild: 1532
PEhash00d15c8d2fb331e4f12afb8e2013176165798a86
IMPhashff4354d01259d1fb5a2e7ea72a26420b

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝
1
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load ➝
C:\Documents and Settings\Administrator\Local Settings\Temp\csrss.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\csrss.exe
Creates FileC:\Documents and Settings\Administrator\Application Data\75DE.FFC
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates ProcessC:\Documents and Settings\Administrator\Application Data\dwm.exe
Creates ProcessC:\malware.exe startC:\Documents and Settings\Administrator\Application Data\dwm.exe%C:\Documents and Settings\Administrator\Application Data
Creates ProcessC:\malware.exe startC:\Documents and Settings\Administrator\Application Data\Microsoft\conhost.exe%C:\Documents and Settings\Administrator\Application Data\Microsoft
Creates Mutex{4D92BB9F-9A66-458f-ACA4-66172A7016D4}
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutex{61B98B86-5F44-42b3-BCA1-33904B067B81}
Creates Mutex{EEEB680D-AE62-4375-B93E-E9AE5FF585C1}
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates Mutex{B37C48AF-B05C-4520-8B38-2FE181D5DC78}
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Winsock DNSfolusho.com
Winsock DNS127.0.0.1
Winsock DNScofeeandteeshop.com

Process
↳ C:\malware.exe startC:\Documents and Settings\Administrator\Application Data\Microsoft\conhost.exe%C:\Documents and Settings\Administrator\Application Data\Microsoft

Creates ProcessC:\Documents and Settings\Administrator\Application Data\Microsoft\conhost.exe

Process
↳ C:\malware.exe startC:\Documents and Settings\Administrator\Application Data\dwm.exe%C:\Documents and Settings\Administrator\Application Data

Creates ProcessC:\Documents and Settings\Administrator\Application Data\dwm.exe

Process
↳ C:\Documents and Settings\Administrator\Application Data\dwm.exe

Network Details:

DNSfolusho.com
Type: A
67.222.55.143
DNSzonetf.com
Type: A
208.73.211.233
DNSzonetf.com
Type: A
208.73.211.235
DNSzonetf.com
Type: A
208.73.211.246
DNSzonetf.com
Type: A
208.73.210.219
DNSzonetf.com
Type: A
208.73.211.174
DNSzonetf.com
Type: A
208.73.211.233
DNSzonetf.com
Type: A
208.73.211.235
DNSzonetf.com
Type: A
208.73.211.246
DNSzonetf.com
Type: A
208.73.210.219
DNSzonetf.com
Type: A
208.73.211.174
DNScofeeandteeshop.com
Type: A
HTTP GEThttp://folusho.com/wp-content/uploads/2010/09/web-20-what-is-300x251.jpg?v72=93&tq=gJ4WK%2FSUh7TFkUR8oY%2BQtMWTUj26kJH7yZRSK%2B%2FbxWq1SfkIYUBM
User-Agent: mozilla/2.0
HTTP POSThttp://zonetf.com/index.html?tq=gKY0sHoL7L%2BN6yLhbz627sHdMfNsX%2BP9h%2BI0sDkX9PiwrWL2GUr0%2BbGpfvRsX%2BaIwb51gW1f447GrXf0eU2S%2BsSodOFuTLiv0agDh2xP6PLEqwaCGkrl%2F7LdBPNpPpTuxq00sD0OpLjRqAOhLgjh88BSr%2Fe%2BV5ZuRg%3D%3D
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
HTTP POSThttp://zonetf.com/index.html?tq=gKY0sHoL7L%2BN6yLhbz627sHdMfNsX%2BP9h%2BI0sDkX9PiwrWL2GUr0%2BbGpfvRsX%2BaIwb51gW1f447GrXf0eU2S%2BsSodOFuTLiv0agDh2xP6PLEqwaCGkrl%2F7LdBPNpPpTuxq00sD0OpLjRqAOhLgjh8sG%2BcoJsX%2BSNwlKv975Xlm5G
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Flows TCP192.168.1.1:1031 ➝ 67.222.55.143:80
Flows TCP192.168.1.1:1033 ➝ 208.73.211.233:80
Flows TCP192.168.1.1:1034 ➝ 208.73.211.233:80

Raw Pcap

Strings
.H.\rl_.(./...s.
.
..]GN.l
.5.UyU
(.*
>.m..
....s.....
.
8.7}..._..x.>.E
u.3........jwn
k"n..
.s..
p.&.......1.
.ep$...'...
g.w)
Z.
 .F.r..FT)n.C.
.
./.a!<<
.^.H..).
......u|.O
..7.A.(O..7./.j
Q.....
.
_.

040904b0
1532
PrivateBuild
StringFileInfo
TIMES NEW ROMAN
Translation
VarFileInfo
VS_VERSION_INFO
0,`H0a
1a\r0QZ!
4d[t/$
5+)L?|S
6\\5K8g
+	87=kJy6
8ot?Jx
8Y+8i.
8Y_ij:O9
ADVAPI32.dll
C4vk8*p
=C)9~\[
CM_Get_DevNode_Status
CMP_WaitNoPendingInstallEvents
CreateDialogParamA
CreateFiberEx
CreateSemaphoreA
CryptCreateHash
CryptDestroyHash
CryptDestroyKey
CryptEncrypt
CryptGetHashParam
CryptHashData
CryptImportKey
CryptReleaseContext
@.data
dB1t}i
DestroyWindow
DispatchMessageA
d-I.XnD
?;>;,E
:/EC{e
EnumResourceNamesW
FlushFileBuffers
GetACP
GetCurrentThread
GetCurrentThreadId
GetDesktopWindow
GetDevicePowerState
GetLastError
GetQueueStatus
GetSystemTime
GetThreadPriority
GetTickCount
GetUserNameA
HYH9^|
InternetCloseHandle
InternetOpenA
InternetOpenUrlA
InternetReadFile
IO#(Ce
IsBadReadPtr
{j>\>*
J`1Efr(
J}[;N)w
JRichu
Juio4K
JV^M^t
K	9v;J!
KERNEL32.dll
kHY,Y/tn
kN>c(c
KOwyOU
k	=|TC
'L,V)%d0#V
l|~.V(Y
mMWpZZ
MRN<Jn\A]
MsgWaitForMultipleObjects
)mXZoc
NZ/$n{H
~O-]{'
@PazJ9
PeekMessageA
PostThreadMessageA
pPq#Ru
		^%Pu
Q+R=4f
`.rdata
RealGetWindowClassA
RegCloseKey
RegCreateKeyExA
RegDeleteValueA
RegEnumKeyExA
RegEnumValueA
RegisterWindowMessageA
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
ReleaseDC
SetThreadPriority
SETUPAPI.dll
SetupDiGetDeviceRegistryPropertyW
ShowWindow
!This program cannot be run in DOS mode.
|THu)v
timeGetTime
timeSetEvent
tL<+U!
USER32.dll
VirtualFree
@=V+t`
WaitForMultipleObjects
WININET.dll
WINMM.dll
wsprintfA
wvsprintfA
wznt-m
x9~Z	5
&y@2no
YCgqyv
Y)>wZ?6