Analysis Date2016-02-11 04:36:32
MD570808f33d8ed2766b687c3ab83d30a78
SHA1ebd33b6abc9db4e141e08278fb6082a33ce3cb0c

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 6d4fc963ea29ebb6a6b32e33fb577c82 sha1: 5e8161328db7340a71dc10220d11baa1386d0f37 size: 183808
Section.rdata md5: efc7173109b99c0252a26344db64a399 sha1: 6dbb173d79b34e4b8ae91ea2fb3138d9811600f2 size: 2560
Section.data md5: 22a25ff53369d01f98f1c082be1157d3 sha1: 1927e1cf2d89900a79cceb9533dc3a913e79d137 size: 16896
Section.reloc md5: 1c6ca2b268c659535caa682c933b24ad sha1: 480c6b1bc66a261f510016b4d82db6afd5a5663d size: 30208
Timestamp2014-12-30 14:21:05
PEhash56a2f2f2a58f81d10bd792f4b7941e09e868c225
IMPhash7e0b10c4d2459ea65ffe7aeecdf6e249
AVCA (E-Trust Ino)No Virus
AVRisingNo Virus
AVMcafeeTrojan-FHQT!70808F33D8ED
AVAvira (antivir)No Virus
AVTwisterNo Virus
AVAd-AwareGen:Variant.Kazy.790778
AVAlwil (avast)Vupa [Cryp]
AVEset (nod32)Win32/Bayrob.BA
AVGrisoft (avg)Generic_r.GTB
AVSymantecTrojan.Bayrob!gen6
AVFortinetW32/Bayrob.AQ!tr
AVBitDefenderGen:Variant.Kazy.790778
AVK7Trojan ( 004dc2a31 )
AVMicrosoft Security EssentialsTrojanSpy:Win32/Nivdort.DA
AVMicroWorld (escan)Gen:Variant.Kazy.790778
AVMalwareBytesNo Virus
AVAuthentiumW32/Nivdort.G.gen!Eldorado
AVEmsisoftGen:Variant.Kazy.790778
AVFrisk (f-prot)W32/Nivdort.G.gen!Eldorado
AVIkarusTrojan.Win32.Bayrob
AVZillya!No Virus
AVKasperskyTrojan.Win32.Generic
AVTrend MicroNo Virus
AVVirusBlokAda (vba32)No Virus
AVCAT (quickheal)TrojanSpy.Nivdort.r4
AVBullGuardGen:Variant.Kazy.790778
AVArcabit (arcavir)Gen:Variant.Kazy.790778
AVClamAVNo Virus
AVDr. WebNo Virus
AVF-SecureGen:Variant.Kazy.790778

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates FileC:\WINDOWS\aelmiczesrjuxf\p9wsfsemcya
Creates FileC:\aelmiczesrjuxf\u81k9lw79fwa5y5bwzu.exe
Creates FileC:\aelmiczesrjuxf\p9wsfsemcya
Deletes FileC:\WINDOWS\aelmiczesrjuxf\p9wsfsemcya
Creates ProcessC:\aelmiczesrjuxf\u81k9lw79fwa5y5bwzu.exe

Process
↳ C:\aelmiczesrjuxf\u81k9lw79fwa5y5bwzu.exe

RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Extensible Call Alerts Driver ➝
C:\aelmiczesrjuxf\brzuqgz.exe
Creates FileC:\aelmiczesrjuxf\rqogpnmgecrz
Creates FileC:\WINDOWS\aelmiczesrjuxf\p9wsfsemcya
Creates FilePIPE\lsarpc
Creates FileC:\aelmiczesrjuxf\brzuqgz.exe
Creates FileC:\aelmiczesrjuxf\p9wsfsemcya
Deletes FileC:\WINDOWS\aelmiczesrjuxf\p9wsfsemcya
Creates ProcessC:\aelmiczesrjuxf\brzuqgz.exe

Process
↳ C:\aelmiczesrjuxf\brzuqgz.exe

Creates FileC:\aelmiczesrjuxf\rqogpnmgecrz
Creates FileC:\WINDOWS\aelmiczesrjuxf\p9wsfsemcya
Creates FileC:\aelmiczesrjuxf\hknmxotqsmy.exe
Creates FilePIPE\lsarpc
Creates File\Device\Afd\Endpoint
Creates FileC:\aelmiczesrjuxf\h24q3j
Creates FileC:\aelmiczesrjuxf\p9wsfsemcya
Deletes FileC:\WINDOWS\aelmiczesrjuxf\p9wsfsemcya
Deletes FileC:\aelmiczesrjuxf\u81k9lw79fwa5y5bwzu.exe
Creates Processrloepo7ppcnc "c:\aelmiczesrjuxf\brzuqgz.exe"

Process
↳ rloepo7ppcnc "c:\aelmiczesrjuxf\brzuqgz.exe"

Creates FileC:\WINDOWS\aelmiczesrjuxf\p9wsfsemcya
Creates FileC:\aelmiczesrjuxf\p9wsfsemcya
Deletes FileC:\WINDOWS\aelmiczesrjuxf\p9wsfsemcya

Network Details:

DNSsweetwomen.net
Type: A
184.168.221.104
DNSmaterialpaint.net
Type: A
208.100.26.234
DNSsimplestream.net
Type: A
141.8.225.124
DNSmountainstream.net
Type: A
207.148.248.143
DNSwindowstream.net
Type: A
216.21.239.197
DNSsweetnothing.net
Type: A
72.52.4.119
DNSmotheranother.net
Type: A
50.63.202.39
DNSsimplebusiness.net
Type: A
72.52.4.119
DNSmountainmanner.net
Type: A
208.100.26.234
DNSsweetbusiness.net
Type: A
50.240.78.247
DNSleavecourse.net
Type: A
DNSfinishwomen.net
Type: A
DNSleavewomen.net
Type: A
DNSsweetclean.net
Type: A
DNSprobablyclean.net
Type: A
DNSsweetpaint.net
Type: A
DNSprobablypaint.net
Type: A
DNSsweetcourse.net
Type: A
DNSprobablycourse.net
Type: A
DNSprobablywomen.net
Type: A
DNSseveralclean.net
Type: A
DNSmaterialclean.net
Type: A
DNSseveralpaint.net
Type: A
DNSseveralcourse.net
Type: A
DNSmaterialcourse.net
Type: A
DNSseveralwomen.net
Type: A
DNSmaterialwomen.net
Type: A
DNSseverastream.net
Type: A
DNSlaughstream.net
Type: A
DNSseveranothing.net
Type: A
DNSlaughnothing.net
Type: A
DNSseverabottle.net
Type: A
DNSlaughbottle.net
Type: A
DNSseveradivide.net
Type: A
DNSlaughdivide.net
Type: A
DNSmotherstream.net
Type: A
DNSsimplenothing.net
Type: A
DNSmothernothing.net
Type: A
DNSsimplebottle.net
Type: A
DNSmotherbottle.net
Type: A
DNSsimpledivide.net
Type: A
DNSmotherdivide.net
Type: A
DNSpossiblestream.net
Type: A
DNSmountainnothing.net
Type: A
DNSpossiblenothing.net
Type: A
DNSmountainbottle.net
Type: A
DNSpossiblebottle.net
Type: A
DNSmountaindivide.net
Type: A
DNSpossibledivide.net
Type: A
DNSperhapsstream.net
Type: A
DNSperhapsnothing.net
Type: A
DNSwindownothing.net
Type: A
DNSperhapsbottle.net
Type: A
DNSwindowbottle.net
Type: A
DNSperhapsdivide.net
Type: A
DNSwindowdivide.net
Type: A
DNSwinterstream.net
Type: A
DNSsubjectstream.net
Type: A
DNSwinternothing.net
Type: A
DNSsubjectnothing.net
Type: A
DNSwinterbottle.net
Type: A
DNSsubjectbottle.net
Type: A
DNSwinterdivide.net
Type: A
DNSsubjectdivide.net
Type: A
DNSfinishstream.net
Type: A
DNSleavestream.net
Type: A
DNSfinishnothing.net
Type: A
DNSleavenothing.net
Type: A
DNSfinishbottle.net
Type: A
DNSleavebottle.net
Type: A
DNSfinishdivide.net
Type: A
DNSleavedivide.net
Type: A
DNSsweetstream.net
Type: A
DNSprobablystream.net
Type: A
DNSprobablynothing.net
Type: A
DNSsweetbottle.net
Type: A
DNSprobablybottle.net
Type: A
DNSsweetdivide.net
Type: A
DNSprobablydivide.net
Type: A
DNSseveralstream.net
Type: A
DNSmaterialstream.net
Type: A
DNSseveralnothing.net
Type: A
DNSmaterialnothing.net
Type: A
DNSseveralbottle.net
Type: A
DNSmaterialbottle.net
Type: A
DNSseveraldivide.net
Type: A
DNSmaterialdivide.net
Type: A
DNSseveramanner.net
Type: A
DNSlaughmanner.net
Type: A
DNSseveraanother.net
Type: A
DNSlaughanother.net
Type: A
DNSseverabusiness.net
Type: A
DNSlaughbusiness.net
Type: A
DNSseveraappear.net
Type: A
DNSlaughappear.net
Type: A
DNSsimplemanner.net
Type: A
DNSmothermanner.net
Type: A
DNSsimpleanother.net
Type: A
DNSmotherbusiness.net
Type: A
DNSsimpleappear.net
Type: A
DNSmotherappear.net
Type: A
DNSpossiblemanner.net
Type: A
DNSmountainanother.net
Type: A
DNSpossibleanother.net
Type: A
DNSmountainbusiness.net
Type: A
DNSpossiblebusiness.net
Type: A
DNSmountainappear.net
Type: A
DNSpossibleappear.net
Type: A
DNSperhapsmanner.net
Type: A
DNSwindowmanner.net
Type: A
DNSperhapsanother.net
Type: A
DNSwindowanother.net
Type: A
DNSperhapsbusiness.net
Type: A
DNSwindowbusiness.net
Type: A
DNSperhapsappear.net
Type: A
DNSwindowappear.net
Type: A
DNSwintermanner.net
Type: A
DNSsubjectmanner.net
Type: A
DNSwinteranother.net
Type: A
DNSsubjectanother.net
Type: A
DNSwinterbusiness.net
Type: A
DNSsubjectbusiness.net
Type: A
DNSwinterappear.net
Type: A
DNSsubjectappear.net
Type: A
DNSfinishmanner.net
Type: A
DNSleavemanner.net
Type: A
DNSfinishanother.net
Type: A
DNSleaveanother.net
Type: A
DNSfinishbusiness.net
Type: A
DNSleavebusiness.net
Type: A
DNSfinishappear.net
Type: A
DNSleaveappear.net
Type: A
DNSsweetmanner.net
Type: A
DNSprobablymanner.net
Type: A
DNSsweetanother.net
Type: A
DNSprobablyanother.net
Type: A
DNSprobablybusiness.net
Type: A
DNSsweetappear.net
Type: A
DNSprobablyappear.net
Type: A
DNSseveralmanner.net
Type: A
DNSmaterialmanner.net
Type: A
DNSseveralanother.net
Type: A
DNSmaterialanother.net
Type: A
DNSseveralbusiness.net
Type: A
DNSmaterialbusiness.net
Type: A
DNSseveralappear.net
Type: A
DNSmaterialappear.net
Type: A
DNSseverainstead.net
Type: A
DNSlaughinstead.net
Type: A
DNSseveraexplain.net
Type: A
DNSlaughexplain.net
Type: A
DNSseverabright.net
Type: A
DNSlaughbright.net
Type: A
DNSseverainside.net
Type: A
DNSlaughinside.net
Type: A
DNSsimpleinstead.net
Type: A
DNSmotherinstead.net
Type: A
DNSsimpleexplain.net
Type: A
DNSmotherexplain.net
Type: A
DNSsimplebright.net
Type: A
DNSmotherbright.net
Type: A
DNSsimpleinside.net
Type: A
DNSmotherinside.net
Type: A
DNSmountaininstead.net
Type: A
DNSpossibleinstead.net
Type: A
DNSmountainexplain.net
Type: A
DNSpossibleexplain.net
Type: A
DNSmountainbright.net
Type: A
DNSpossiblebright.net
Type: A
DNSmountaininside.net
Type: A
HTTP GEThttp://sweetwomen.net/index.php
User-Agent:
HTTP GEThttp://materialpaint.net/index.php
User-Agent:
HTTP GEThttp://simplestream.net/index.php
User-Agent:
HTTP GEThttp://mountainstream.net/index.php
User-Agent:
HTTP GEThttp://windowstream.net/index.php
User-Agent:
HTTP GEThttp://sweetnothing.net/index.php
User-Agent:
HTTP GEThttp://motheranother.net/index.php
User-Agent:
HTTP GEThttp://simplebusiness.net/index.php
User-Agent:
HTTP GEThttp://mountainmanner.net/index.php
User-Agent:
HTTP GEThttp://sweetbusiness.net/index.php
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 184.168.221.104:80
Flows TCP192.168.1.1:1032 ➝ 208.100.26.234:80
Flows TCP192.168.1.1:1033 ➝ 141.8.225.124:80
Flows TCP192.168.1.1:1034 ➝ 207.148.248.143:80
Flows TCP192.168.1.1:1035 ➝ 216.21.239.197:80
Flows TCP192.168.1.1:1036 ➝ 72.52.4.119:80
Flows TCP192.168.1.1:1037 ➝ 50.63.202.39:80
Flows TCP192.168.1.1:1038 ➝ 72.52.4.119:80
Flows TCP192.168.1.1:1039 ➝ 208.100.26.234:80
Flows TCP192.168.1.1:1040 ➝ 50.240.78.247:80

Raw Pcap
0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2073   : close..Host: s
0x00000040 (00064)   77656574 776f6d65 6e2e6e65 740d0a0d   weetwomen.net...
0x00000050 (00080)   0a                                    .

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a206d   : close..Host: m
0x00000040 (00064)   61746572 69616c70 61696e74 2e6e6574   aterialpaint.net
0x00000050 (00080)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2073   : close..Host: s
0x00000040 (00064)   696d706c 65737472 65616d2e 6e65740d   implestream.net.
0x00000050 (00080)   0a0d0a0a                              ....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a206d   : close..Host: m
0x00000040 (00064)   6f756e74 61696e73 74726561 6d2e6e65   ountainstream.ne
0x00000050 (00080)   740d0a0d 0a                           t....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2077   : close..Host: w
0x00000040 (00064)   696e646f 77737472 65616d2e 6e65740d   indowstream.net.
0x00000050 (00080)   0a0d0a0d 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2073   : close..Host: s
0x00000040 (00064)   77656574 6e6f7468 696e672e 6e65740d   weetnothing.net.
0x00000050 (00080)   0a0d0a0d 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a206d   : close..Host: m
0x00000040 (00064)   6f746865 72616e6f 74686572 2e6e6574   otheranother.net
0x00000050 (00080)   0d0a0d0a 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2073   : close..Host: s
0x00000040 (00064)   696d706c 65627573 696e6573 732e6e65   implebusiness.ne
0x00000050 (00080)   740d0a0d 0a                           t....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a206d   : close..Host: m
0x00000040 (00064)   6f756e74 61696e6d 616e6e65 722e6e65   ountainmanner.ne
0x00000050 (00080)   740d0a0d 0a                           t....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2073   : close..Host: s
0x00000040 (00064)   77656574 62757369 6e657373 2e6e6574   weetbusiness.net
0x00000050 (00080)   0d0a0d0a 0a                           .....


Strings