Trojan.NSIS.StartPage_9aa729cbc9

by malwarelabrobot on December 15th, 2015 in Malware Descriptions.

not-a-virus:HEUR:AdWare.Win32.OutBrowse.heur (Kaspersky), Trojan.NSIS.StartPage.FD, mzpefinder_pcap_file.YR (Lavasoft MAS)
Behaviour: Trojan, Adware


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: 9aa729cbc9bd3570b8c685cc9763559e
SHA1: 613525b0ea2d573fac6da86c910d993cc2adce28
SHA256: aa3e5de9fcd934c5069ffa2d3947debc7c1b0b6afba7f04169aa0b1ab205b319
SSDeep: 6144:YFJ0B2 RQ8E ERuyVvpwuyB3SGi3oOxI2rGL7:N2nHvVvSuyBCGIoONe7
Size: 347960 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: QGRBL
Created at: 2009-12-06 00:52:12
Analyzed on: WindowsXP SP3 32-bit


Summary:

Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).

Payload

No specific payload has been found.

Process activity

The Trojan creates the following process(es):

%original file name%.exe:1584
T09FME9PTw==10700.exe:356
wmic.exe:568
T09FME9PTw==29820.exe:1380

The Trojan injects its code into the following process(es):

beeiedfjah.exe:1388

Mutexes

The following mutexes were created/opened:
No objects were found.

File activity

The process %original file name%.exe:1584 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\beeiedfjah.exe (19208 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsv1.tmp (0 bytes)

The process T09FME9PTw==10700.exe:356 makes changes in the file system.
The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsg2.tmp (0 bytes)

The process wmic.exe:568 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\81450072976.txt (238 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\81450072976.txt (0 bytes)

The process T09FME9PTw==29820.exe:1380 makes changes in the file system.
The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp (0 bytes)

The process beeiedfjah.exe:1388 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\OperaChecker25-6[1].exe (3762 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\CAUFM3ED.htm (2083 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\XPLimitChecker[1].exe (6491 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bodyImg[1].png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\81450072976\T09FME9PTw==10700.exe (50 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\button[1].png (458 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\dc[1].js (469 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\81450072976\T09FME9PTw==29820.exe (1940 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\button_over[1].png (921 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\81450072976.txt (0 bytes)

Registry activity

The process %original file name%.exe:1584 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "88 0D 2B F5 DD B3 E7 71 2D 26 33 77 EF EF 86 5E"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

The process T09FME9PTw==10700.exe:356 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "41 2E 9F 61 65 DA 97 2D B5 53 76 47 63 86 FF 5D"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\OperaOB]
"Install" = "1"

The process wmic.exe:568 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A8 49 1D 42 C0 65 8D 1F F1 3C 5C 83 15 EA 6A 14"

The process T09FME9PTw==29820.exe:1380 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "23 9B 64 7A ED CB 62 EB C3 AC 02 07 37 E2 6F ED"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKCU\xplmtOB]
"Install" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

The process beeiedfjah.exe:1388 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1F 00 00 00 01 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "31 81 7D 22 79 46 E9 59 3E 1E 44 8C D5 B8 6B 25"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

Dropped PE files

MD5 File path
10ffabc748d68c40b68f883058c9b932 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\81450072976\T09FME9PTw==10700.exe
b6631cd12092841cac0763c854828c50 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\81450072976\T09FME9PTw==29820.exe
22b48d6dbee393a2b3e0123b2b86c56b c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\beeiedfjah.exe
b6631cd12092841cac0763c854828c50 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\XPLimitChecker[1].exe
10ffabc748d68c40b68f883058c9b932 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\OperaChecker25-6[1].exe

HOSTS file anomalies

No changes have been detected.

Rootkit activity

No anomalies have been detected.

Propagation

VersionInfo

Company Name: QGRBL
Product Name: QGRBL
Product Version: 1539.151125.1289.739
Legal Copyright: QGRBL
Legal Trademarks: QGRBL
Original Filename:
Internal Name:
File Version: 1539.151125.1289.739
File Description: QGRBL
Comments: QGRBL
Language: English (United States)

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 4096 23628 24064 4.46304 c52a72deb0170941d392ec38c6aeafd0
.rdata 28672 4764 5120 3.4982 dc77f8a1e6985a4361c55642680ddb4f
.data 36864 298072 1024 3.32453 723ad80df002dc5421798f4307abe5cf
.ndata 335872 311296 0 0 d41d8cd98f00b204e9800998ecf8427e
.rsrc 647168 54360 54784 2.83676 79b91469d53bc60eb16b4070e3b582e5

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

Total found: 117
03654a08e7f65aec190ee7e37246bb5f
a212f888d46a7e2d8802888390ff3c63
470ab50ccb81409a49b2abb4c05af91f
ee0edf52085544dd5ffae3892bd06855
07da75d17d57e9bbfa0916a2ad8b95b6
e74d8056cde545c3960d49ca018101bb
e5c5fddf9ff161c0d6de11988f8358c7
38623bf8200680f3967022fd39f52daf
fad9fe2f4d34a9a3943bbf54dfc38c01
1b45146c52aa1976ffcf47b50c6e4c7c
27967ee4c772b29835d5dba868867879
22dc967254eef4719b3c514ab7029cdb
18ed19164cd0f258338a661057321695
e9197129bf89c13fa74f5e0219c735ae
32d708fbb109abf91c1a372351481a8e
cae50b748f98679ee3004f13687fdc34
7d4b556f36f5170d24469ffd6280298b
c2297a50a1f58665aa97177a0357616e
9398d852900b4c351c5b8e38699dcd70
2f81cfbd26709f9f88985ed83777256d
562eb5ad8564d3591007404a367df858
02c83ab655f98711ad1fbb3123b78438
6daeb82e5bcd31515b4a926d6cba88b3
f9b90420cd1aef0263de7ca339f8947b
63745fe6fef243a667c80f8d31228f33
ad9ae311a36924f84d2f4d7c9571f8a2

URLs

URL IP
hxxp://smartinstaller.elasticbeanstalk.com/Installer/Flow?pubid=24718&distid=30497&productid=29729&subpubid=0&campaignid=0&networkid=0&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:0D:DD:4A&netv=&d1=4249078&d2=1561&d3=-1&d4=-1&d5=-1&ds1=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&cookieeula=&cookieprivacy=&hb=5&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=112.196.179.59&downloadtime=11/25/2015 12:50:27 PM&clickid=&version=6.12
hxxp://smartinstaller.elasticbeanstalk.com/Installer/Track?pubid=24718&distid=30497&productid=29729&subpubid=0&campaignid=0&networkid=0&reqid=379952702&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:0D:DD:4A&netv=&d1=4249078&d2=1561&d3=-1&d4=-1&d5=-1&ds1=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&cookieeula=&cookieprivacy=&hb=5&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=112.196.179.59&downloadtime=11/25/2015 12:50:27 PM&clickid=&status=2&installedid=10700&z=1&offerscreenid=234&offerorder=-1&downloadduration=-1&installduration=-1&issecond=0
hxxp://d2vubraihqcany.cloudfront.net/Installer/XP/XPLimitChecker.exe 54.239.192.13
hxxp://smartinstaller.elasticbeanstalk.com/Installer/Flow?pubid=24718&distid=30497&productid=29729&subpubid=0&campaignid=0&networkid=0&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:0D:DD:4A&netv=&d1=4249078&d2=1561&d3=-1&d4=-1&d5=-1&ds1=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&cookieeula=&cookieprivacy=&hb=5&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=112.196.179.59&downloadtime=11/25/2015 12:50:27 PM&clickid=&version=6.12&nipids=-29408-28693-28657-29219&secondcall=1&reqid=379952702
hxxp://smartinstaller.elasticbeanstalk.com/Installer/Track?pubid=24718&distid=30497&productid=29729&subpubid=0&campaignid=0&networkid=0&reqid=379952702&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:0D:DD:4A&netv=&d1=4249078&d2=1561&d3=-1&d4=-1&d5=-1&ds1=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&cookieeula=&cookieprivacy=&hb=5&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=112.196.179.59&downloadtime=11/25/2015 12:50:27 PM&clickid=&status=2&installedid=29820&z=1&offerscreenid=655&offerorder=-1&downloadduration=-1&installduration=-1&issecond=0
hxxp://smartinstaller.elasticbeanstalk.com//offers/DynamicOfferScreen?offerid=5&distid=30497&leadp=29729&countryid=262&sysbit=32&imgurl=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&dfb=0&hb=5&isagg=1&version=6.12&external=0&
hxxp://stats.l.doubleclick.net/dc.js
hxxp://staticrevenyou.outbrowse.netdna-cdn.com/offers/images/Theme12/topLine.jpg
hxxp://staticrevenyou.outbrowse.netdna-cdn.com/offers/images/Theme12/topComp.png
hxxp://staticrevenyou.outbrowse.netdna-cdn.com/offers/images/Theme12/bodyImg.png
hxxp://staticrevenyou.outbrowse.netdna-cdn.com/offers/images/Theme12/bgImg.jpg
hxxp://staticrevenyou.outbrowse.netdna-cdn.com/offers/images/Theme12/bottomLine.jpg
hxxp://staticrevenyou.outbrowse.netdna-cdn.com/offers/images/Theme12/nextCase.jpg
hxxp://staticrevenyou.outbrowse.netdna-cdn.com/offers/images/Theme12/button_over.png
hxxp://staticrevenyou.outbrowse.netdna-cdn.com/offers/images/Theme12/button.png
hxxp://srv.DESK-TOP-APP.INFO/Installer/Flow?pubid=24718&distid=30497&productid=29729&subpubid=0&campaignid=0&networkid=0&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:0D:DD:4A&netv=&d1=4249078&d2=1561&d3=-1&d4=-1&d5=-1&ds1=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&cookieeula=&cookieprivacy=&hb=5&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=112.196.179.59&downloadtime=11/25/2015 12:50:27 PM&clickid=&version=6.12
hxxp://static.revenyou.com/offers/images/Theme12/button.png 198.232.124.224
hxxp://static.revenyou.com/offers/images/Theme12/button_over.png 198.232.124.224
hxxp://static.revenyou.com/offers/images/Theme12/bgImg.jpg 198.232.124.224
hxxp://static.revenyou.com/offers/images/Theme12/bodyImg.png 198.232.124.224
hxxp://static.revenyou.com/offers/images/Theme12/nextCase.jpg 198.232.124.224
hxxp://static.revenyou.com/offers/images/Theme12/bottomLine.jpg 198.232.124.224
hxxp://srv.DESK-TOP-APP.INFO/Installer/Track?pubid=24718&distid=30497&productid=29729&subpubid=0&campaignid=0&networkid=0&reqid=379952702&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:0D:DD:4A&netv=&d1=4249078&d2=1561&d3=-1&d4=-1&d5=-1&ds1=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&cookieeula=&cookieprivacy=&hb=5&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=112.196.179.59&downloadtime=11/25/2015 12:50:27 PM&clickid=&status=2&installedid=10700&z=1&offerscreenid=234&offerorder=-1&downloadduration=-1&installduration=-1&issecond=0
hxxp://srv.DESK-TOP-APP.INFO/Installer/Flow?pubid=24718&distid=30497&productid=29729&subpubid=0&campaignid=0&networkid=0&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:0D:DD:4A&netv=&d1=4249078&d2=1561&d3=-1&d4=-1&d5=-1&ds1=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&cookieeula=&cookieprivacy=&hb=5&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=112.196.179.59&downloadtime=11/25/2015 12:50:27 PM&clickid=&version=6.12&nipids=-29408-28693-28657-29219&secondcall=1&reqid=379952702
hxxp://srv.serverdatasrv.com//offers/DynamicOfferScreen?offerid=5&distid=30497&leadp=29729&countryid=262&sysbit=32&imgurl=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&dfb=0&hb=5&isagg=1&version=6.12&external=0& 23.21.201.205
hxxp://stats.g.doubleclick.net/dc.js 64.233.164.156
hxxp://static.revenyou.com/offers/images/Theme12/topComp.png 198.232.124.224
hxxp://srv.DESK-TOP-APP.INFO/Installer/Track?pubid=24718&distid=30497&productid=29729&subpubid=0&campaignid=0&networkid=0&reqid=379952702&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:0D:DD:4A&netv=&d1=4249078&d2=1561&d3=-1&d4=-1&d5=-1&ds1=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&cookieeula=&cookieprivacy=&hb=5&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=112.196.179.59&downloadtime=11/25/2015 12:50:27 PM&clickid=&status=2&installedid=29820&z=1&offerscreenid=655&offerorder=-1&downloadduration=-1&installduration=-1&issecond=0
hxxp://static.revenyou.com/offers/images/Theme12/topLine.jpg 198.232.124.224
hxxp://cdn.download4desktop.com/Installer/OperaBrowser/OperaChecker25-6.exe 198.232.124.192
srv.desk-top-app.info 23.23.241.124


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

ET POLICY Executable served from Amazon S3

Traffic

GET /dc.js HTTP/1.1
Accept: */*
Referer: hXXp://srv.serverdatasrv.com//offers/DynamicOfferScreen?offerid=5&distid=30497&leadp=29729&countryid=262&sysbit=32&imgurl=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&dfb=0&hb=5&isagg=1&version=6.12&external=0&
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: stats.g.doubleclick.net
Connection: Keep-Alive


HTTP/1.1 200 OK
Strict-Transport-Security: max-age=10886400
Date: Mon, 14 Dec 2015 05:39:53 GMT
Expires: Mon, 14 Dec 2015 07:39:53 GMT
Last-Modified: Thu, 05 Nov 2015 22:24:16 GMT
X-Content-Type-Options: nosniff
Content-Type: text/javascript
Vary: Accept-Encoding
Content-Encoding: gzip
Server: Golfe2
Content-Length: 15977
Cache-Control: public, max-age=7200
Age: 1399
...........}kW....w~........pk..f......Z.R..Y.C 8i.pi......b..}.>g.
.Kl...}4....d....O...-.....`~...E...]7..>..>....Pf.a.yU."HCC...i
...T*..b.....'..Olf[.Y.[c6P/.....'n.m'..m.... !_XXll..&..(..E..V=/.u.X
..%.w...i..rDoT.....?>z..1`.D...y...y7. \...5ZI...TA..........C...p
3..A..x.k.q4.2...?L.k=.v....4.:sB[...l.w.o {.....?Nc....|..........q..
.......[.n..2..X~.......S.f.]h~....7:.n...m.C#6...........#....y...7.|
..f.W.>..wS......)..Q....i......z......D.`...7N....y.C;....`1....x.
.p.tG.L..=..1r...M..2..)xa...{0!..5...^...7..."..........J8... ...5.O.
...l...r...|....R...P.0ok.8.Z.2....i|...S.y.od...~..k.>.....0vGr.mI
.....0.&&yg.sf2......m.....G=0..B.6..u....A.h.A.0.V.:.-...j..L.....5.E
.[...Q.{2imA......T........~. ...0*%.....>......hX...ga1./$......f.
#..d,.|www5/XX...c5..D-.....p.h..8D.@./.X,.....&gTV..5..,.x..?.....(.&
gt;?6Sy.].`.]...'-"....-...........(.n.@_"p"`.*...T.1.$..t.....o?.."..
/.kX.)[email protected].,HP........# ....d...-,.......-.j..B
S....9...%.~Sug,...`."[email protected]]..yn.i(5.....U.r..$j..0{|.i.5........
H}.......A=..&.Vq....4<..*7c.<b.....OQ8X...&..a/a.....aI.j.7.E.:
cuV=.P.q..d.....X....#[email protected][email protected].#....Q.....K.....
.A.y._....z|..9...9.zM......%m........m).?4.Q...c.....PTDB&..7.-G....E
.....E.7.t.V..G....._..!.....xt..}.......Ev..x..a.{...d.. .q./..OB|.
.6..{....a^.......@?.......o.....*T.;/Oa.......J..........I.)......J..
#..A....FS.....t.H..h...W..|B.~..t.6..........t"<..z..||.......8..B
9......x.a....m.V[.=...K!..\.....w."d...=>.B..(K...u.....~.".@b

<<< skipped >>>

GET /Installer/Flow?pubid=24718&distid=30497&productid=29729&subpubid=0&campaignid=0&networkid=0&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:0D:DD:4A&netv=&d1=4249078&d2=1561&d3=-1&d4=-1&d5=-1&ds1=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&cookieeula=&cookieprivacy=&hb=5&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=112.196.179.59&downloadtime=11/25/2015 12:50:27 PM&clickid=&version=6.12 HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.19 (KHTML, like Gecko) Chrome/18.0.1025.142 Safari/535.19
Host: srv.DESK-TOP-APP.INFO
Connection: Keep-Alive


HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Date: Mon, 14 Dec 2015 06:03:02 GMT
Server: Microsoft-IIS/8.0
X-AspNet-Version: 4.0.30319
X-AspNetMvc-Version: 4.0
X-Powered-By: ASP.NET
Content-Length: 16399
Connection: keep-alive
..Sv.NlmsAxc.2..*.JqaEv`.5. ).Bkmnjf`grQsoa"8,$.Fmkcsez_oajgRvjdo
"8.(.% O_fGew.2.AIBS^?UPM=IM]RMDN Qj^op_o_[XAkd_j.nsv.x FF=TXARLQ
ANRZMN>P.Mnbtu\j`UZJ[hh.PpTW:kfanEnqoYgeco.qbr '.M^eH_x24 5.CDC
VYBQRP@FOXSP?Q.SmalrZpbV[=mgbg.ity.{.HI@QZ<SOLDJT][email protected]_m]WUK^
ck*RsWT<fgdiHjsr\dg^p.len"*.J`imonM]mc.2.:kfan>rmrk`k ).Ono
bp[oBB.4154.3$.:jt[xoOda]m.8-&!EsU\ao?moCmot_gd.3/).DteSMD.3 ensl:
-*Yhbel\hj.a_fhZgi(qq/?habhBfmsni`)]s^ ).DteSMD-.8.bspp8*'\fgdiaen
,^\if_ff-nu-<ed`mAcrprg]&`qc.&!?okhYi]Jfhd.: ..<fgdiCesr
ma]'cu_.)-qdd`gr.',nfp8/32/43.)-s\Wm_p:=G=NL@DZ066 65 (e\dc*^
dbasgl8*.*'o]rri]mXlbq^qrj8`omn7).iebdYghed_q*rs*Ykb-p[uaPmnl]Zah9
skkci5hBA>mNLJ0ok!`sf^< _]BMD=$pcf9$]ZKD@$lpq9$]ZGQK$o_e9764)22$
`bh`=00*3.a^cc925/.ornb7`iiej..% L`earSMD.3 ensl:-*kmo,P?QREP?9O:QOP-_
ok*'j_dblr DwiYhbaL`earQ^j`^l<iebepd\8/12 onobp[obb:,8006!\dlrf
^</024/!ec^^o9272*4.alomprwd\8 4/ rus`dl8,0#]nkkg`hmhbr]sjak`5Hbaoi
rkfr.Ga_g`_.Lrma]nlglh`h Ngmn.#/2w24#-1..05r2.* *1.Cm_l.<[obt^nn
n%3=Mk]_q_c!5B.* *3.Dtje$_^]6.#ba95$dk\`e: %repnajg;3(0.&csl`kl^f&
lt;,"*.J\mc.4,-, <\_brfim]lB\l\.8.. .AloaqbprmdoRcbC`rq.4!W] &
#39;.KZwlos.: ,$.>dc_bpit`.5&/).OnokjldhlO[sa"8()'.Bfm
bnen\f^rP^nd.: ,$.Ljb_o=fr`jDgqq[kh"8 $.Ogont]lMa^`kAlgl]nbGai^ 7
hthl*.;\gPrh@oCf`[f[mu.9prs`$.KskCm=gem]nlgs_Hjsr\dg^p.4!-"*.JpgG
kLdcuj\jDgqq[khep.2.* ).OneCs]M^qrfsPeph.5...&!Lrc@p`KcpokpV_gm`.8
.*!("Njko>vbLdoujoL`kk.4!,"*.HjlrBrdNeqpdoO_iod.: .&

<<< skipped >>>

GET /Installer/Track?pubid=24718&distid=30497&productid=29729&subpubid=0&campaignid=0&networkid=0&reqid=379952702&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:0D:DD:4A&netv=&d1=4249078&d2=1561&d3=-1&d4=-1&d5=-1&ds1=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&cookieeula=&cookieprivacy=&hb=5&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=112.196.179.59&downloadtime=11/25/2015 12:50:27 PM&clickid=&status=2&installedid=10700&z=1&offerscreenid=234&offerorder=-1&downloadduration=-1&installduration=-1&issecond=0 HTTP/1.1

User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.19 (KHTML, like Gecko) Chrome/18.0.1025.142 Safari/535.19
Host: srv.DESK-TOP-APP.INFO
Connection: Keep-Alive


HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Date: Mon, 14 Dec 2015 06:03:08 GMT
Server: Microsoft-IIS/8.0
X-AspNet-Version: 4.0.30319
X-AspNetMvc-Version: 4.0
X-Powered-By: ASP.NET
Content-Length: 8
Connection: keep-alive
..OK..HTTP/1.1 200 OK..Cache-Control: private..Content-Type: text/html
; charset=utf-8..Date: Mon, 14 Dec 2015 06:03:08 GMT..Server: Microsof
t-IIS/8.0..X-AspNet-Version: 4.0.30319..X-AspNetMvc-Version: 4.0..X-Po
wered-By: ASP.NET..Content-Length: 8..Connection: keep-alive....OK..font>....



GET /Installer/Flow?pubid=24718&distid=30497&productid=29729&subpubid=0&campaignid=0&networkid=0&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:0D:DD:4A&netv=&d1=4249078&d2=1561&d3=-1&d4=-1&d5=-1&ds1=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&cookieeula=&cookieprivacy=&hb=5&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=112.196.179.59&downloadtime=11/25/2015 12:50:27 PM&clickid=&version=6.12&nipids=-29408-28693-28657-29219&secondcall=1&reqid=379952702 HTTP/1.1

User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.19 (KHTML, like Gecko) Chrome/18.0.1025.142 Safari/535.19
Host: srv.DESK-TOP-APP.INFO
Connection: Keep-Alive


HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Date: Mon, 14 Dec 2015 06:03:09 GMT
Server: Microsoft-IIS/8.0
X-AspNet-Version: 4.0.30319
X-AspNetMvc-Version: 4.0
X-Powered-By: ASP.NET
Content-Length: 17554
Connection: keep-alive
..Sv.NlmsAxc.2..*.JqaEv`.5. ).Bkmnjf`grQsoa"83$.Fmkcsez_oajgRvjdo
"8.(( .*,3)25(*0.*.LdcKct.5. ).QagI`q1- 7.!("P`hjkrK[la"
;8.9QH ).Onobp[oBB.40("?go\rqL`ear 5('.GpQ`etDjjDgqq[kh"
8,$.>vbOQH"8..'.Cu_TNL0.2..*.=nim_i\Gblb.9."*.Ga_coOQ
H"8.`omn7).ort)K@KTBLC=T?NJQ'alg. oda]ml-Asm]mg^Ga_coMbneci7j
_dblh`=2.)!igam<.92 0( 6332)261-2&06,05&bdkobb:-/095!d`Zbm7
15704.^hsknquib8*1 $psr^ir8 -.alijeenmg_naqh`ie;Ha^kmpiep Ma^d\c.Jqkfc
nkdhl^f.Llsn. 6u03!27..-1v0,$.90 )..Gk]k.AaoaqZrll$1BSk\\mca.4@ 0 )0.
Hrhd"dd]5 .f_74"iq\_b6/#pdnsgjf8/,.,%axr`jiZj:*!("P\l`.
8* .Ab_aobmk[k@ar\.5.06./4-03.4, /2517 -1-*7.&!=nrdndksp_rNeeF]tl
7.!("N\qjnr.4,-, @^a^aqcua"8()'.NoilktgjfMZrb.9)1*.<
dlao_o]natJ\mc.4,-, Nd`^n>`sarGikoZji.9,, Qamms^fNbfcm;jfk^hcHil`.5
. ).B]nPpf<lAe_bgbms.5mpr_ .RsiAi:edldosgq]Dgqq[khep.2..*.LtjIlM]bn
j^lHjsr\dg^p.4!., Kj`>vbLdoujoL`kk.4!., Kj`>vbLdoujoN\esb.9.&quo
t;*.HjlrBrdNeqpdoMcog!6" '.Khqq?waRcnmgmT^fta"8..'.N
lmsNeeF]t,0.4!., KgnmPbaJay4/.5. z&[email protected]!., Kj`>vb.9.&quo
t;*.;jfnlhdjtRth`.8.&!Ioldlds_qcnjTwk]n.8.*!("P`_F^w.4!DKCTW&
gt;NPO?MP_SN=M.Ql`ssap`TW:kfan.ptw.w.FH?X[CSMJ@GR\ORAR.Ngamu^ldX\K\ag&
#39;PrV[=mgbgDgqq[khep.jak ).QagI`q1- 7.GGEWZ;PKPBHS[[email protected]]rcWT&l
t;fgdi.lvz.t.AIBS^?UPM=IM]RMDN Qj^op_o_[XM_dd)KsYV@iiejAilr^fkar.m^m.*
.LdlopoF\fc.4!=mgbg=kmtmdn"*.Hmhbr]sED 5*4-.5&!=lu\qnHdc_q.:.
'.DlU^csBopDfnm_if!61*.=s^SOF!6"folk3-,[legm]ai'aahl]

<<< skipped >>>

GET /Installer/Track?pubid=24718&distid=30497&productid=29729&subpubid=0&campaignid=0&networkid=0&reqid=379952702&dfb=0&os=5.1&ospv=-1&iev=6.0&ffv=&chromev=&macaddress=00:0C:29:0D:DD:4A&netv=&d1=4249078&d2=1561&d3=-1&d4=-1&d5=-1&ds1=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&cookieeula=&cookieprivacy=&hb=5&systembit=32&vm=1&machineguid=75ed9567-aa58-4c8e-a8ea-3cad7c47ab03&welcomeimgurl=&downloadip=112.196.179.59&downloadtime=11/25/2015 12:50:27 PM&clickid=&status=2&installedid=29820&z=1&offerscreenid=655&offerorder=-1&downloadduration=-1&installduration=-1&issecond=0 HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.19 (KHTML, like Gecko) Chrome/18.0.1025.142 Safari/535.19
Host: srv.DESK-TOP-APP.INFO
Connection: Keep-Alive


HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Date: Mon, 14 Dec 2015 06:03:09 GMT
Server: Microsoft-IIS/8.0
X-AspNet-Version: 4.0.30319
X-AspNetMvc-Version: 4.0
X-Powered-By: ASP.NET
Content-Length: 8
Connection: keep-alive
..OK..HTTP/1.1 200 OK..Cache-Control: private..Content-Type: text/html
; charset=utf-8..Date: Mon, 14 Dec 2015 06:03:09 GMT..Server: Microsof
t-IIS/8.0..X-AspNet-Version: 4.0.30319..X-AspNetMvc-Version: 4.0..X-Po
wered-By: ASP.NET..Content-Length: 8..Connection: keep-alive....OK....


GET /Installer/OperaBrowser/OperaChecker25-6.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cdn.download4desktop.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 14 Dec 2015 06:03:07 GMT
Content-Type: application/octet-stream
Content-Length: 50225
Connection: keep-alive
x-amz-id-2: s3PhcJrhxK/AixpFvo7sKAIr9Cd5pOB4AoWdhUKYVRQn2ZqM1ugC6kjV9DKLinYH
x-amz-request-id: 0E8DF1D0D13D047D
Last-Modified: Wed, 25 Jun 2014 14:41:23 GMT
ETag: "10ffabc748d68c40b68f883058c9b932"
Server: NetDNA-cache/2.2
Content-Disposition: attachment
X-Cache: HIT
Accept-Ranges: bytes
MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.......1..:u..iu..i
u..i...iw..iu..i...i...id..i!..i...i...it..iRichu..i..................
......PE..L......K.................^...........0.......p....@.........
.................................................................t....
......PC..............................................................
.............p...............................text...L\.......^........
.......... ..`.rdata.......p.......b..............@[email protected]\......
.....v..............@....ndata...................................rsrc.
..PC.......D...z..............@..@....................................
......................................................................
......................................................................
......................................................................
......................................................................
............................................U....\.}..t .}.F.E.u..H...
[email protected]@..e...E..E.P.u...Pr@
..}[email protected]... M.......M....3.....FQ.....NU..M.....
.....VT..U.....FP..E...............E.P.M...Hp@[email protected]
....E..9}[email protected].}[email protected]..
[email protected]@.W...E..E.h ...Pj.h`[email protected]...\r@._^3.
[.....L$....B...Si.....VW.T.....tO.q.3.;5..B.sB..i......D.......t.G...
..t...O..t .....u...3....3...F.....;5..B.r._^[...U..QQ.U.SV..i....

<<< skipped >>>

GET /offers/images/Theme12/topComp.png HTTP/1.1
Accept: */*
Referer: hXXp://srv.serverdatasrv.com//offers/DynamicOfferScreen?offerid=5&distid=30497&leadp=29729&countryid=262&sysbit=32&imgurl=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&dfb=0&hb=5&isagg=1&version=6.12&external=0&
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static.revenyou.com
Connection: Keep-Alive


HTTP/1.1 404 Not Found
Date: Mon, 14 Dec 2015 06:03:12 GMT
Content-Type: text/html
Content-Length: 1245
Connection: keep-alive
X-Powered-By: ASP.NET
Server: NetDNA-cache/2.2
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "hXXp://ww
w.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">..<html xmlns="hXXp://
VVV.w3.org/1999/xhtml">..<head>..<meta http-equiv="Content
-Type" content="text/html; charset=iso-8859-1"/>..<title>404
- File or directory not found.</title>..<style type="text/css
">..<!--..body{margin:0;font-size:.7em;font-family:Verdana, Aria
l, Helvetica, sans-serif;background:#EEEEEE;}..fieldset{padding:0 15px
10px 15px;} ..h1{font-size:2.4em;margin:0;color:#FFF;}..h2{font-size:
1.7em;margin:0;color:#CC0000;} ..h3{font-size:1.2em;margin:10px 0 0 0;
color:#000000;} ..#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px
2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;..backgr
ound-color:#555555;}..#content{margin:0 0 0 2%;position:relative;}...c
ontent-container{background:#FFF;width:96%;margin-top:8px;padding:10px
;position:relative;}..-->..</style>..</head>..<body&
gt;..<div id="header"><h1>Server Error</h1></div&
gt;..<div id="content">.. <div class="content-container">&
lt;fieldset>.. <h2>404 - File or directory not found.</h2
>.. <h3>The resource you are looking for might have been rem
oved, had its name changed, or is temporarily unavailable.</h3>.
. </fieldset></div>..</div>..</body>..</htm
l>..
....

<<< skipped >>>

GET /offers/images/Theme12/bgImg.jpg HTTP/1.1

Accept: */*
Referer: hXXp://srv.serverdatasrv.com//offers/DynamicOfferScreen?offerid=5&distid=30497&leadp=29729&countryid=262&sysbit=32&imgurl=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&dfb=0&hb=5&isagg=1&version=6.12&external=0&
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static.revenyou.com
Connection: Keep-Alive


HTTP/1.1 404 Not Found
Date: Mon, 14 Dec 2015 06:03:12 GMT
Content-Type: text/html
Content-Length: 1245
Connection: keep-alive
X-Powered-By: ASP.NET
Server: NetDNA-cache/2.2
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "hXXp://ww
w.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">..<html xmlns="hXXp://
VVV.w3.org/1999/xhtml">..<head>..<meta http-equiv="Content
-Type" content="text/html; charset=iso-8859-1"/>..<title>404
- File or directory not found.</title>..<style type="text/css
">..<!--..body{margin:0;font-size:.7em;font-family:Verdana, Aria
l, Helvetica, sans-serif;background:#EEEEEE;}..fieldset{padding:0 15px
10px 15px;} ..h1{font-size:2.4em;margin:0;color:#FFF;}..h2{font-size:
1.7em;margin:0;color:#CC0000;} ..h3{font-size:1.2em;margin:10px 0 0 0;
color:#000000;} ..#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px
2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;..backgr
ound-color:#555555;}..#content{margin:0 0 0 2%;position:relative;}...c
ontent-container{background:#FFF;width:96%;margin-top:8px;padding:10px
;position:relative;}..-->..</style>..</head>..<body&
gt;..<div id="header"><h1>Server Error</h1></div&
gt;..<div id="content">.. <div class="content-container">&
lt;fieldset>.. <h2>404 - File or directory not found.</h2
>.. <h3>The resource you are looking for might have been rem
oved, had its name changed, or is temporarily unavailable.</h3>.
. </fieldset></div>..</div>..</body>..</htm
l>..
....

<<< skipped >>>

GET /offers/images/Theme12/nextCase.jpg HTTP/1.1

Accept: */*
Referer: hXXp://srv.serverdatasrv.com//offers/DynamicOfferScreen?offerid=5&distid=30497&leadp=29729&countryid=262&sysbit=32&imgurl=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&dfb=0&hb=5&isagg=1&version=6.12&external=0&
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static.revenyou.com
Connection: Keep-Alive


HTTP/1.1 404 Not Found
Date: Mon, 14 Dec 2015 06:03:12 GMT
Content-Type: text/html
Content-Length: 1245
Connection: keep-alive
X-Powered-By: ASP.NET
Server: NetDNA-cache/2.2
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "hXXp://ww
w.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">..<html xmlns="hXXp://
VVV.w3.org/1999/xhtml">..<head>..<meta http-equiv="Content
-Type" content="text/html; charset=iso-8859-1"/>..<title>404
- File or directory not found.</title>..<style type="text/css
">..<!--..body{margin:0;font-size:.7em;font-family:Verdana, Aria
l, Helvetica, sans-serif;background:#EEEEEE;}..fieldset{padding:0 15px
10px 15px;} ..h1{font-size:2.4em;margin:0;color:#FFF;}..h2{font-size:
1.7em;margin:0;color:#CC0000;} ..h3{font-size:1.2em;margin:10px 0 0 0;
color:#000000;} ..#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px
2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;..backgr
ound-color:#555555;}..#content{margin:0 0 0 2%;position:relative;}...c
ontent-container{background:#FFF;width:96%;margin-top:8px;padding:10px
;position:relative;}..-->..</style>..</head>..<body&
gt;..<div id="header"><h1>Server Error</h1..


GET /offers/images/Theme12/topLine.jpg HTTP/1.1
Accept: */*
Referer: hXXp://srv.serverdatasrv.com//offers/DynamicOfferScreen?offerid=5&distid=30497&leadp=29729&countryid=262&sysbit=32&imgurl=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&dfb=0&hb=5&isagg=1&version=6.12&external=0&
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static.revenyou.com
Connection: Keep-Alive


HTTP/1.1 404 Not Found
Date: Mon, 14 Dec 2015 06:03:12 GMT
Content-Type: text/html
Content-Length: 1245
Connection: keep-alive
X-Powered-By: ASP.NET
Server: NetDNA-cache/2.2
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "hXXp://ww
w.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">..<html xmlns="hXXp://
VVV.w3.org/1999/xhtml">..<head>..<meta http-equiv="Content
-Type" content="text/html; charset=iso-8859-1"/>..<title>404
- File or directory not found.</title>..<style type="text/css
">..<!--..body{margin:0;font-size:.7em;font-family:Verdana, Aria
l, Helvetica, sans-serif;background:#EEEEEE;}..fieldset{padding:0 15px
10px 15px;} ..h1{font-size:2.4em;margin:0;color:#FFF;}..h2{font-size:
1.7em;margin:0;color:#CC0000;} ..h3{font-size:1.2em;margin:10px 0 0 0;
color:#000000;} ..#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px
2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;..backgr
ound-color:#555555;}..#content{margin:0 0 0 2%;position:relative;}...c
ontent-container{background:#FFF;width:96%;margin-top:8px;padding:10px
;position:relative;}..-->..</style>..</head>..<body&
gt;..<div id="header"><h1>Server Error</h1></div&
gt;..<div id="content">.. <div class="content-container">&
lt;fieldset>.. <h2>404 - File or directory not found.</h2
>.. <h3>The resource you are looking for might have been rem
oved, had its name changed, or is temporarily unavailable.</h3>.
. </fieldset></div>..</div>..</body>..</htm
l>..
....

<<< skipped >>>

GET /offers/images/Theme12/bodyImg.png HTTP/1.1

Accept: */*
Referer: hXXp://srv.serverdatasrv.com//offers/DynamicOfferScreen?offerid=5&distid=30497&leadp=29729&countryid=262&sysbit=32&imgurl=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&dfb=0&hb=5&isagg=1&version=6.12&external=0&
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static.revenyou.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 14 Dec 2015 06:03:12 GMT
Content-Type: image/png
Content-Length: 1914
Connection: keep-alive
Cache-Control: max-age=604800
Last-Modified: Mon, 05 Aug 2013 10:27:32 GMT
ETag: "36dd864c691ce1:0"
X-Powered-By: ASP.NET
Server: NetDNA-cache/2.2
Expires: Mon, 21 Dec 2015 06:03:12 GMT
X-Cache: HIT
Accept-Ranges: bytes
.PNG........IHDR.......:.....j.......sRGB.........gAMA......a.... cHRM
..z&..............u0...`..:....p..Q<...0PLTE.......................
.........................{.......IDATx......:..`..p..J.4.ty.:......)v.
.\....,.fwv..U...!.....b.f.....Cy(..OW......w......]R..l..2My}<..].
.8hn{*..X.).m..4w.U.J.....u..l.J...<...>uJ.....i.>o.%......I.
\..S......U.D.}OK..J`......sJ`.}..M.9%..A....u.T.%........K....OQ..._.
.d.>..L....]I. U.].c.Je...|.W.U?..E.}...*.vZ...K...M....).W...^V..&
gt;).e(.].Z.}dg%@....S.*/...........Y.W.]}...|.SgO........rrj...4UY../
..r.~.....Z.ep.wui.sP^..X.g%$(.......C........Ze....4yn}....U.({.V..{o
..}O...w.G.Q.^..r..p....0y............8......6.v....zz~....-...F*..f.F
]...R..*. -......e{mO.s.i.9.U....zz.6.f.T>.f.DQ%.. ...l.q\N."eA({_W
7..Q.....d........>...Y.."e.\....s,.. .Li)%....R.o.....C.9wQ....8..
......KNY..t..)...k...v)P*.....I...4&../.{)..qe..R.'...2..*..d.z&.T;y.
.)Q*....)R..2..)Tj.B..)V..b..)W......QB!rj.B.J)..N)b*...R)q..<S...z
%.LPr..%.LQ2.4e.....q&*c.De,..J.x& ig...g..b.(.g..p.)Qf..uf*1g..af .Y.
..... .;(.....s......r.v. ...s'...K.0wS.....sG%.......-.R..}......4S..
...W.....=.9eN(..OS..Jt(...<...P.(..DJ;_)..Y. ..7.>[email protected])e
M.qi;...........$.z%.[..P...SJzT*E]......2zT.t..L%6.TJ..Y.a...}.V..J..
.,.....H... ....;..2_._/[.^/[.\.W.\.!..%oT*y.Z....#Q.Bw.FI.7...H..2Jt.
*..../........2.F..X.....gqJ.q:.U.q.. V...B..s.(.J2.x..()#1@.'d4.Hh.h.
J.I.i.G.#.;.J....*Q$Z..?.........sR..D.<...| ......2.1b.A3...v.....
X.y{..R....{h..pzJ.I.).Y..Kn.z;%Jn..c.W...bL........t..!...A..(..*

<<< skipped >>>

GET /offers/images/Theme12/bottomLine.jpg HTTP/1.1

Accept: */*
Referer: hXXp://srv.serverdatasrv.com//offers/DynamicOfferScreen?offerid=5&distid=30497&leadp=29729&countryid=262&sysbit=32&imgurl=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&dfb=0&hb=5&isagg=1&version=6.12&external=0&
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static.revenyou.com
Connection: Keep-Alive


HTTP/1.1 404 Not Found
Date: Mon, 14 Dec 2015 06:03:12 GMT
Content-Type: text/html
Content-Length: 1245
Connection: keep-alive
X-Powered-By: ASP.NET
Server: NetDNA-cache/2.2
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "hXXp://ww
w.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">..<html xmlns="hXXp://
VVV.w3.org/1999/xhtml">..<head>..<meta http-equiv="Content
-Type" content="text/html; charset=iso-8859-1"/>..<title>404
- File or directory not found.</title>..<style type="text/css
">..<!--..body{margin:0;font-size:.7em;font-family:Verdana, Aria
l, Helvetica, sans-serif;background:#EEEEEE;}..fieldset{padding:0 15px
10px 15px;} ..h1{font-size:2.4em;margin:0;color:#FFF;}..h2{font-size:
1.7em;margin:0;color:#CC0000;} ..h3{font-size:1.2em;margin:10px 0 0 0;
color:#000000;} ..#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px
2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;..backgr
ound-color:#555555;}..#content{margin:0 0 0 2%;position:relative;}...c
ontent-container{background:#FFF;width:96%;margin-top:8px;padding:10px
;position:relative;}..-->..</style>..</head>..<body&
gt;..<div id="header"><h1>Server Error</h1></div&
gt;..<div id="content">.. <div class="content-container">&
lt;fieldset>.. <h2>404 - File or directory not found.</h2
>.. <h3>The resource you are looking for might have been rem
oved, had its name changed, or is temporarily unavailable.</h3>.
. </fieldset></div>..</div>..</body>..</htm
l>..
....

<<< skipped >>>

GET /offers/images/Theme12/button_over.png HTTP/1.1

Accept: */*
Referer: hXXp://srv.serverdatasrv.com//offers/DynamicOfferScreen?offerid=5&distid=30497&leadp=29729&countryid=262&sysbit=32&imgurl=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&dfb=0&hb=5&isagg=1&version=6.12&external=0&
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static.revenyou.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 14 Dec 2015 06:03:12 GMT
Content-Type: image/png
Content-Length: 921
Connection: keep-alive
Cache-Control: max-age=604800
Last-Modified: Mon, 05 Aug 2013 17:21:05 GMT
ETag: "f072da2a092ce1:0"
X-Powered-By: ASP.NET
Server: NetDNA-cache/2.2
Expires: Mon, 21 Dec 2015 06:03:12 GMT
X-Cache: HIT
Accept-Ranges: bytes
.PNG........IHDR...Y............m....tEXtSoftware.Adobe ImageReadyq.e&
lt;...;IDATx..Z;o.1..Y.D...W."$=D..*[email protected].
...........;..N.h..=.|..x6..f..pf...n...yX...>z......`87.3...t.e:.s
h..e..z.A....G.p..IZ.z...?Ra8........Y......O.......[[email protected].
...y..-.....Lc.0......O..|z.O/...k.....e...n..!......G.p...9....3. .'?
7 ..GD@..{.<....C$....N.........Q...<.,@...].;Q.'<.(.X.r.,.6.
......QrB..h..d&r....6....G..Shr.... .....4r..= ..f.....B.qP..l.K.....
...YB.Z....H....../:.l.(.S.D...nM7..P.%R........&_uR.H6A..(raP.H9...[\
D. .(....d...`.8.A......r5Q..........:v.e....u.....-&.1.....&.........
Z.|....).L...$....)K%a-....b..a*{<(W..P<..w7_Z.....h.%6.N.......
.*\FB...A...#..f.N...C..(.p...........K.|..5d..3u-........(.k. 7..6..t
svP!.U0.q.......9z.e [email protected]............. .>=...{WVim...
.f.c6.:...|.....0X.yk...../z..!.SHW.d......o.s........a..8..g.|zvg...o
[email protected].^......IEND.B`.
....



GET /offers/images/Theme12/button.png HTTP/1.1

Accept: */*
Referer: hXXp://srv.serverdatasrv.com//offers/DynamicOfferScreen?offerid=5&distid=30497&leadp=29729&countryid=262&sysbit=32&imgurl=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&dfb=0&hb=5&isagg=1&version=6.12&external=0&
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: static.revenyou.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Mon, 14 Dec 2015 06:03:12 GMT
Content-Type: image/png
Content-Length: 458
Connection: keep-alive
Cache-Control: max-age=604800
Last-Modified: Mon, 05 Aug 2013 17:21:12 GMT
ETag: "1b5642f092ce1:0"
X-Powered-By: ASP.NET
Server: NetDNA-cache/2.2
Expires: Mon, 21 Dec 2015 06:03:12 GMT
X-Cache: HIT
Accept-Ranges: bytes
.PNG........IHDR...Y............m....tEXtSoftware.Adobe ImageReadyq.e&
lt;...lIDATx...1..p....at.`...[_)...&.........~...C..V$z.J.w.Wi.......
.../..<........R.H)s..i....t.....}2M...9i.&..(..c.....l.&.0`.&a..f.
..p...R.Jr....bA....$.....cr....u....sq..x....?..> ..pu`.h..C......
.$w$..gY. .....%9MS...V.....IF'..0].;..HF..]b..Hr..pW...k..{..EQD.....
-L.....#..H.u.. ..lF....j".,<........<. ......18....\.....oI...^
.....:..._......rU.<Z`..d..E.|.0.......B.....IEND.B`...


GET /Installer/XP/XPLimitChecker.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: d2vubraihqcany.cloudfront.net
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: application/octet-stream
Content-Length: 50053
Connection: keep-alive
Date: Tue, 08 Dec 2015 02:54:36 GMT
Last-Modified: Mon, 04 May 2015 10:45:00 GMT
ETag: "b6631cd12092841cac0763c854828c50"
Accept-Ranges: bytes
Server: AmazonS3
Age: 73713
X-Cache: Hit from cloudfront
Via: 1.1 7b8a7488445561e0573f89a1f8dc5d44.cloudfront.net (CloudFront)
X-Amz-Cf-Id: b52kvpmtoOo_k9LDxvAPxV-A0dXu-dMLzffW7EMlc-lb2V3ZJp4kcQ==
MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.......1..:u..iu..i
u..i...iw..iu..i...i...id..i!..i...i...it..iRichu..i..................
......PE..L......K.................^....... ...0.......p....@.........
.................0...............................................t....
......(C..............................................................
.............p...............................text...L\.......^........
.......... ..`.rdata.......p.......b..............@[email protected].......
[email protected]....... ...........................rsrc.
..(C.......D...z..............@..@....................................
......................................................................
......................................................................
......................................................................
......................................................................
............................................U....\.}..t .}.F.E.u..H...
[email protected]@..e...E..E.P.u...Pr@
..}[email protected]... M.......M....3.....FQ.....NU..M.....
.....VT..U.....FP..E...............E.P.M...Hp@[email protected]
....E..9}[email protected].}[email protected]..
[email protected]@.W...E..E.h ...Pj.h`[email protected]...\r@._^3.
[.....L$....E...Si.. ..VW.T.....tO.q.3.;5..E.sB..i.. ...D.......t.G...
..t...O..t .....u...3....3...F.. ..;5..E.r._^[...U..QQ.U.SV..i.. .

<<< skipped >>>

GET //offers/DynamicOfferScreen?offerid=5&distid=30497&leadp=29729&countryid=262&sysbit=32&imgurl=&cookieproductname=77-105-99-114-111-115-111-102-116-32-79-102-102-105-99-101-32-80-114-111-102-101-115-115-105-111-110-97-108-32-80-108-117-115-32-37-50-56-120-54-52-37-50-57-32-37-50-56-120-51-50-37-50-57-50-48-49-51-32-73-110-99-108-32-65-99-116-105-118-97-116-111-114-37-53-66-85-112-100-97-116-101-100-37-53-68-32-50-48-49-53-32-74-117-110-101&dfb=0&hb=5&isagg=1&version=6.12&external=0& HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: srv.serverdatasrv.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Date: Mon, 14 Dec 2015 06:03:11 GMT
Server: Microsoft-IIS/8.0
X-AspNet-Version: 4.0.30319
X-AspNetMvc-Version: 4.0
X-Powered-By: ASP.NET
Content-Length: 12914
Connection: keep-alive
<html>.    <head>.      <title>5 - NonProduct (WakeN
et Pixel Manager)</title><script type='text/javascript'>va
r _gaq = _gaq || [];_gaq.push(['_setAccount', 'UA-37348037-1']);_gaq.p
ush(['_setDomainName', 'ppdownload.com']);_gaq.push(['_setAllowLinker'
, true]);.. _gaq.push(['_tr
ackPageview']);.. (function
() {.. var ga = document.
createElement('script'); ga.type = 'text/javascript'; ga.async = true;
.. ga.src = ('https:' ==
document.location.protocol ? 'hXXps://' : 'hXXp://') 'stats.g.double
click.net/dc.js';.. var s
= document.getElementsByTagName('script')[0]; s.parentNode.insertBefo
re(ga, s);.. })();</scri
pt><style type='text/css'>body { width:100%; he
ight:100%; margin:0px; padding:0px; font-size:font-family:helvetica; f
ont-size:12px;} .divLeadpName { border-bottom-style:gro
ove;border-bottom-width: thin; padding-left:61px; padding-top:9px; fon
t-size:font-family:helvetica; font-style:italic; font-size:25px;
font-weight:bold; color:black; position:absolute; width:
100%; background-color: #fff; ba} #divTop {display: none} #
divMiddle {background-color: #efecec; height: 100%;} #middle {
background-color: #fff;} .divOnNext { position:absol

<<< skipped >>>

The Trojan connects to the servers at the folowing location(s):

%original file name%.exe_1584:

.text
`.rdata
@.data
.ndata
.rsrc
uDSSh
.DEFAULT\Control Panel\International
Software\Microsoft\Windows\CurrentVersion
GetWindowsDirectoryA
KERNEL32.dll
ExitWindowsEx
USER32.dll
GDI32.dll
SHFileOperationA
ShellExecuteA
SHELL32.dll
RegEnumKeyA
RegCreateKeyExA
RegCloseKey
RegDeleteKeyA
RegOpenKeyExA
ADVAPI32.dll
COMCTL32.dll
ole32.dll
VERSION.dll
verifying installer: %d%%
hXXp://nsis.sf.net/NSIS_Error
... %d%%
~nsu.tmp
%u.%u%s%s
RegDeleteKeyExA
%s=%s
*?|<>/":
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\beeiedfjah.exe 9)1)0)1)7)9)8)4)5)8)7 Jk9JQzYpLDMsMBkmUlVBSUA8OSsYKEVEVFZISUNFPzUpFy5ESExLQUA4KykrODcfKDpBQDgoGSZPUk49TDtQWkE9NDE5NiswGCtOPUtNRFJeTklEOWNsbWc5Ly5saW4qPz1MQixUTkkkOUxLJkJFRU8fKDpERT5DQjs8IC49KDUwLSwyJzY4Hyg7KjksLS8oHy9DLDQlLRsnPSs8LTAZJjwxOCUqFy5QUUg7TT9PV0lJSFZAPFA1HCpIS0ZDVUJNVj1RRzk2Fy5QUUg7TT9PV0c4TEU8RmBbbmpraF1zJTEpRl5iZFteHDEwT2tmXmFua2JmbWFrHikoTGdtbBwxMCQrL3AyLx0rMCQyLx4pMHQuKh4pODIvKiodLitBZ1prJTEpOFtwZG5aa25yJC45TWxfWW1cYyU0PRwqLC0oKiwkMi9DbGZhGyc T0RfVEtDNWRvbGkxLi9jKi1nXywtX2lpdDYvaSZfZ2duW2VybmdrJmpgbChqZHR0aVZqcSldcVwfL0RRPFc/SDxFQE1FPBkmQEtOTFg5UU9WTDxKOTAYKEtHQU1EUEdRWk1LQzwgLk9ENS4bJz1KMD0fKElNSk9BRjxeV0RFOkdJQEFGOEZFVEtDNRwqQUxWUVVNTUBFQThsa2xkIC5LPExRTUZCRUZfVEw8Sls/OVJKPDIfKD9BQEBQNigfL0hMVjxVSTlGQEJfREc6SlVLTD47PGZgZWpdHCo8SE5NTE46O1dFSzUqKDEuMDItJi0yMScsOCAuSThKPUdEPkNeSU1MSzlIRzVtaXRlHyhLQUlANSorMzgzLiwwLjIYKDtOV01FRjlAWkxCREQ9MComKjEqKikoNCowKzEtLDUqMCFPTQ==
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp
beeiedfjah.exe
393C3
11f1
353X3
3%3x3
?%?*?/?4?=?
3 3$30383
7 7$7(7,70747
Certification Services Division1806
hXXp://t2.symcb.com0
!hXXp://t1.symcb.com/ThawtePCA.crl0
hXXp://tl.symcb.com/tl.crl0
hXXps://VVV.thawte.com/cps0/
!hXXps://VVV.thawte.com/repository0
hXXp://tl.symcd.com0&
hXXp://tl.symcb.com/tl.crt0
.?AV?$CAtlExeModuleT@VCSmartInstallerModule@@@ATL@@
.?AVCWebPage@@
<requestedExecutionLevel level='requireAdministrator' uiAccess='false' />
%F<~H
:*.cx(
zcÁ
.aJcy
c:\%original file name%.exe
%original file name%.exe
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsv1.tmp
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="Nullsoft.NSIS.exehead" type="win32"/><description>Nullsoft Install System v2.46</description><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"/></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/></application></compatibility></assembly>
{8856F961-340A-11D0-A96B-00C04FD705A2}
00000000
1539.151125.1289.739

beeiedfjah.exe_1388:

.text
`.rdata
@.data
.rsrc
@.reloc
tCPjB
<1%uMj
r%f;M
j.Yf;
_tcPVj@
.PjRW
X:X:X:X:X:X
%d/%d/%d %d:%d:%d
Error %u in WinHttpQueryDataAvailable.
Error %u in WinHttpReadData.
Error %d has occurred.
F%D,3
operator
GetProcessWindowStation
function not supported
operation canceled
address_family_not_supported
operation_in_progress
operation_not_supported
protocol_not_supported
operation_would_block
address family not supported
broken pipe
inappropriate io control operation
not supported
operation in progress
operation not permitted
operation not supported
operation would block
protocol not supported
WinHttpCrackUrl
WinHttpOpen
WinHttpCloseHandle
WinHttpConnect
WinHttpReadData
WinHttpWriteData
WinHttpQueryDataAvailable
WinHttpSetOption
WinHttpSetTimeouts
WinHttpOpenRequest
WinHttpAddRequestHeaders
WinHttpSendRequest
WinHttpReceiveResponse
WinHttpQueryHeaders
WinHttpGetProxyForUrl
WinHttpGetIEProxyConfigForCurrentUser
WINHTTP.dll
GetProcessHeap
KERNEL32.dll
CreateDialogIndirectParamW
USER32.dll
GDI32.dll
RegCloseKey
RegCreateKeyExW
RegEnumKeyExW
RegOpenKeyExW
RegQueryInfoKeyW
ADVAPI32.dll
ShellExecuteW
SHELL32.dll
ole32.dll
OLEAUT32.dll
URLDownloadToFileW
urlmon.dll
IPHLPAPI.DLL
GetCPInfo
zcÁ
.?AV?$CAtlExeModuleT@VCSmartInstallerModule@@@ATL@@
.?AVCWebPage@@
<requestedExecutionLevel level='requireAdministrator' uiAccess='false' />
393C3
11f1
353X3
3%3x3
?%?*?/?4?=?
3 3$30383
7 7$7(7,70747
QG9lH3VqchdtdWtkHXlucRt0WGh0GXNsIHJwam0XbmheH2ZucnBcaWNbdGJuaz8fJElMSxpSPkJMTUxBSUE8Pik=
UUJUVE5JRkVBX05SQlJeQDxWSg==
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.19 (KHTML, like Gecko) Chrome/18.0.1025.142 Safari/535.19
\default.html
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
Q0JGQFFHUTlMT1BSQlI=
JWFpcmduYmljYWU8
firefox
chrome
opera
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice
ChromeHTML
FirefoxHTML
IE.AssocFile.HTM
Opera.HTML
http\shell\open\command
Opera.exe
Safari.exe
SOFTWARE\Mozilla\Mozilla FireFox
Software\Mozilla\Mozilla FireFox
SOFTWARE\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}
@@exeurl
1-3-0-1-4-5-3-9-6-0-7
ExeURL2
RegKey
ReportName
PreExe
PostExe
RegKey64
AntivirusesRegKeys
PreExeResultTerm
PreExeResultValue
PostExeResultTerm
PostExeResultValue
PostRegKey32
PostRegKey64
RegKey32
WinHttpClient
n2d.exe
downoad.exe
Hmscoree.dll
- floating point support not loaded
- CRT not initialized
- Attempt to initialize the CRT more than once.
kernel32.dll
USER32.DLL
portuguese-brazilian
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\beeiedfjah.exe
{8856F961-340A-11D0-A96B-00C04FD705A2}


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    %original file name%.exe:1584
    T09FME9PTw==10700.exe:356
    wmic.exe:568
    T09FME9PTw==29820.exe:1380

  2. Delete the original Trojan file.
  3. Delete or disinfect the following files created/modified by the Trojan:

    %Documents and Settings%\%current user%\Local Settings\Temp\beeiedfjah.exe (19208 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\81450072976.txt (238 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\OperaChecker25-6[1].exe (3762 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\CAUFM3ED.htm (2083 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\XPLimitChecker[1].exe (6491 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bodyImg[1].png (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\81450072976\T09FME9PTw==10700.exe (50 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\button[1].png (458 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\dc[1].js (469 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\81450072976\T09FME9PTw==29820.exe (1940 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\button_over[1].png (921 bytes)

  4. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  5. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

No votes yet

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now