Trojan.Win32.IEDummy_3854f725af
Gen:Variant.Adware.Graftor.262074 (B) (Emsisoft), Trojan.Win32.IEDummy.FD, mzpefinder_pcap_file.YR (Lavasoft MAS)
Behaviour: Trojan, Adware
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: 3854f725af72ba90035d069b41510b47
SHA1: ba6f7d460f77f05e119c27cce2a3a4e75687d0e7
SHA256: 7b35e8a027dcbe49b881377231dbe4c99aa9319ae8899540fa31926722cc1059
SSDeep: 98304:F6Q8bq0dUcBxtAzC89QaRfGebrK/9WNSUeO5Mi3eFb3CnGKD:FmzdUQxcCeQKKbYPOFbNG
Size: 4790736 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 1992-06-20 01:22:17
Analyzed on: WindowsXP SP3 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
%original file name%.exe:1632
The Trojan injects its code into the following process(es):
No processes have been created.
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process %original file name%.exe:1632 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\desktop.ini (159 bytes)
Registry activity
The process %original file name%.exe:1632 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"Guid" = "8aefce96-4618-42ff-a057-3536aa78233e"
[HKLM\SOFTWARE\Microsoft\ESENT\Process\3854f725af72ba90035d069b41510b47\DEBUG]
"Trace Level" = ""
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKCR\CLSID\{C379EAD1-CB34-4B09-AF6B-7E587F8BCD80}\ProgID]
"(Default)" = "3854f725af72ba90035d069b41510b47.DynamicNS"
[HKCR\CLSID\{C379EAD1-CB34-4B09-AF6B-7E587F8BCD80}]
"(Default)" = "DynamicNS"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"TypesSupported" = "7"
"CategoryCount" = "16"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication]
"ID" = "708992537"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"Active" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"ControlFlags" = "1"
"LogSessionName" = "stdout"
[HKCR\3854f725af72ba90035d069b41510b47.DynamicNS\Clsid]
"(Default)" = "{C379EAD1-CB34-4B09-AF6B-7E587F8BCD80}"
[HKCR\CLSID\{C379EAD1-CB34-4B09-AF6B-7E587F8BCD80}\LocalServer32]
"(Default)" = "c:\%original file name%.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCR\3854f725af72ba90035d069b41510b47.DynamicNS]
"(Default)" = "DynamicNS"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"LogSessionName" = "stdout"
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "E7 F8 87 00 FD 0D 2A 07 65 2B B6 12 DE AF 71 54"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"CategoryMessageFile" = "%System%\ESENT.dll"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication]
"Name" = "%original file name%.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\Internet Explorer]
"iexplore.exe" = "Internet Explorer"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"EventMessageFile" = "%System%\ESENT.dll"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"LogSessionName" = "stdout"
"ControlFlags" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
"IntranetName" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\ESENT\Process\3854f725af72ba90035d069b41510b47\DEBUG]
"Trace Level"
Dropped PE files
There are no dropped PE files.
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name:
Product Name:
Product Version: 1.0.0.0
Legal Copyright:
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 1.0.0.0
File Description:
Comments:
Language: Language Neutral
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| UPX0 | 4096 | 13361152 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| UPX1 | 13365248 | 3653632 | 3652096 | 5.50012 | 3b7fd922a04c2f4174e5e1f7f5e53ec7 |
| .rsrc | 17018880 | 24576 | 24576 | 3.63792 | 1e750444d1d98009cad4f85c892c5264 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 4
2340f3f924417a2600b783713df881b6
520349754469222ea179806c41d581a8
c06d0986b978de24c8ada82504d618b7
7f8d705b3f73a960462fc84a72b35e4c
URLs
| URL | IP |
|---|---|
| hxxp://demodownload.image-line.com/flstudio/flstudio_12.0.2.exe | |
| hxxp://digimatic.biz/pages/displayCore2_russian/typ2-1.html | |
| hxxp://tundra.site/pages/displayCore2_russian/typ2-1.html | |
| hxxp://tundra.site/pages/displayCore2_russian/css/style.css | |
| hxxp://tundra.site/pages/displayCore2_russian/images/icon1-green.png | |
| hxxp://tundra.site/pages/displayCore2_russian/images/icon2-green.png | |
| hxxp://tundra.site/pages/displayCore2_russian/images/icon3-green.png | |
| hxxp://cast-prod-dlv-pull.ironsrc.netdna-cdn.com/scripts/1/adnl.min.js | |
| hxxp://neu-dl-api.cloudapp.net/api/vv/1?callback=cb_1459466574285&ts=1459466574285&sessionId=iIWgv&rfr=&siteId=9306&aus=3958,1,0 | |
| hxxp://cast-prod-dlv-pull.ironsrc.netdna-cdn.com/layouts/graphic_300x250.js?v=4.4.28 | |
| hxxp://cast-prod-dlv-pull.ironsrc.netdna-cdn.com/images/1ad74167-6977-4580-930a-bf7c3478533c.png | |
| hxxp://tundra.site/pages/displayCore2_russian/ | |
| hxxp://cdn.castplatform.com/images/1ad74167-6977-4580-930a-bf7c3478533c.png | |
| hxxp://d.castplatform.com/api/vv/1?callback=cb_1459466574285&ts=1459466574285&sessionId=iIWgv&rfr=&siteId=9306&aus=3958,1,0 | |
| hxxp://cdn.castplatform.com/scripts/1/adnl.min.js | |
| hxxp://cdn.castplatform.com/layouts/graphic_300x250.js?v=4.4.28 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /pages/displayCore2_russian/images/icon1-green.png HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/displayCore2_russian/typ2-1.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: tundra.site
Connection: Keep-Alive
Cookie: X-Mapping-fjhppofk=3E8E1A8CCA3BD46AD95C5D4A4E8F490A
HTTP/1.1 200 OK
Server: nginx/1.8.0
Date: Thu, 31 Mar 2016 23:15:27 GMT
Content-Type: image/png
Content-Length: 3392
Last-Modified: Thu, 12 Jun 2014 09:04:00 GMT
Connection: keep-alive
ETag: "53996d00-d40"
Accept-Ranges: bytes.PNG........IHDR...>...E......$UF....tEXtSoftware.Adobe ImageReadyq
.e<....IDATx..[{l[W.?..g..fvR.]..2.4.z.N..?jOC......C....IS[....%Y.
...........i][email protected].@.?Hs%.:&.....&..c.............#YIS...;.w.....cB.O.
.....GE.l.3.n7.2Rv..FQ..JF. ...Lt.....?..m.cN...'yK...k..Y..l.........
.j...qO:.?.......n...8K........K7<9X.db.$.....b.............=-.....
...<uhB..2......-/VI.Hzy.$."..?y...<.....-.iF..x.. ...N..ke....)
......!._.mJc..p,a.Z.Gd.x.(...p.......j....~3.. .I..a....~4...S...NN0f
.W..2.I.....t....i`..1d.6....E...^.oKGb$qm.}..;.f...g...h%x..t.K ..'..
.....(X...W.:...]#.p......>.._;.>j..{..V.(k.W...O\....oj..^.....
K.lq>.<.......eJ........?..Yp.`.Ic........F............OV.../...
n.....u.3...F..`... .....oj..b.......7"..;]i.B.. ...K.A{..W.^.g....9..
?}..p....R.M....i..N.D....;......QK..,".....9.....ub>...P.....g:9/.
..:?.y?..a8...L....L.b.s............W...O|.S...w*...3=..J.,...:...3ok.
.mz....W....E.S.F.N...99K.v.S.P.......].!ey:]#C..!.8 .W...D;dq.......&
gt;;...|Y.,3D.Gq.Mg.D..i.|..X.......[[email protected].*cYmj.=.3..2........W.
..vw...fy9^.....z......pEQ. ...Q....T....#.[/..t.0z.h!..>t.....%".B
l.{.<.{.JW.....?.3h.{w...(...DF..p...dV.}X....PJ...n.A.....o. p.(..
........H..3....H...N....F)p8....$.......Y....z:Tn.....W.q....6..D..G.
Ud.f.....C.X....D......N..{..T.j......../."..=...g..)..<(hwX.rf...0
...Z=J..=....1B..n.$U\.P.re.ku.u&8.nC.........W........so..../.O5...G.
....OB#%...x...~..`.;.....^.m."...........q..S]..T.....Fj)>...|.jZ.
..['.....:.s.x..O.m.....[....\$0..{..&.r...^.U...?.o..Y.......ZW].<<< skipped >>>
GET /pages/displayCore2_russian/images/icon3-green.png HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/displayCore2_russian/typ2-1.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: tundra.site
Connection: Keep-Alive
Cookie: X-Mapping-fjhppofk=3E8E1A8CCA3BD46AD95C5D4A4E8F490A
HTTP/1.1 200 OK
Server: nginx/1.8.0
Date: Thu, 31 Mar 2016 23:15:27 GMT
Content-Type: image/png
Content-Length: 1519
Last-Modified: Thu, 12 Jun 2014 09:06:00 GMT
Connection: keep-alive
ETag: "53996d78-5ef"
Accept-Ranges: bytes.PNG........IHDR...>...E......$UF....tEXtSoftware.Adobe ImageReadyq
.e<....IDATx..[.O[u.........(.E....o..............U0...Q`.%...}0..$
..d....%&=<.H.|q.sNZ..R..=7.._/P...Z.....rN.....;..0`.......0`.....
S<q..x.6...8. .....4=A].....Y...L<y~&\".I.G..X.Y,......L\{......
./[email protected]:8.....!...............j..W.h..UvZ...bC.
B....1..j\YZ..9...9....r0..8......V...\..[.HO.y..`.{w..SQ.[.m..L.V.nli
.....L..`..n&...\[email protected].~.f......:.......x.i.g.......s
...>4...J...z .^r.z..3....RO<y.wI.).Z..v......^p.u.y"H....W*6Q..
tX."?..w...'...%. .......f.|o....3.s......:.Zz].2.............|.v..U..
..c..z.b....i........>....q.S .....'k3...6.......>D.qY.E........
....................1e1=.Ff)..o..|_..O...z...P6. ... ....?O.S...=.DtU.
.c.-C....SG.%.Y....*.......#.=y.K.quyM.......g.(....\9y.Y..s\v....!...
....>@..d............I..d{.m...!..zFR..........._#rr9.g....ut~....!
..;....-....*w...Hx.E.C]........}.....c.n"..>.".._.ZQ.C.."....q.j".
..... ......._I....S.g.....f...o3..Q...jpf......s.)...1B].SO..3..$N..]
.g(.z......D.......T...C/......u.a}....`. ":m.-m..W.....4..JJ.}...%.U.
T....-.N.....m."..?YE...q=....|P.....X.H,.......|..J.F.#M.......w.t...
Xrr&..e=;.a......R.e.RN...2....n-....g..8d../;....b......p..).&.0Xm.._
.Gs.T..V.y.mo..3....h...F.-.^HH......k....2i...v..&.......j..s,...~ok.
.....=......n.`.x..1.-.I...G..V...F...,U.K...Hb".;p...A/...s.V/.._....
7q.S.|....&.~81v-..../...!.G.Q.m............\./*.$h...>..*[email protected]~
h1yH..W.E...Wp].a.'{....8r.A,...r.....).hY...?.KE.u.........._...d<<< skipped >>>
GET /pages/displayCore2_russian/typ2-1.html HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: digimatic.biz
Connection: Keep-Alive
HTTP/1.1 301 Moved Permanently
Server: nginx/1.8.0
Date: Thu, 31 Mar 2016 23:15:26 GMT
Content-Type: text/html
Content-Length: 184
Connection: keep-alive
Location: hXXp://tundra.site/pages/displayCore2_russian/typ2-1.html<html>..<head><title>301 Moved Permanently</title
></head>..<body bgcolor="white">..<center><h1&
gt;301 Moved Permanently</h1></center>..<hr><cent
er>nginx/1.8.0</center>..</body>..</html>..HTTP/1
.1 301 Moved Permanently..Server: nginx/1.8.0..Date: Thu, 31 Mar 2016
23:15:26 GMT..Content-Type: text/html..Content-Length: 184..Connection
: keep-alive..Location: hXXp://tundra.site/pages/displayCore2_russian/
typ2-1.html..<html>..<head><title>301 Moved Permanen
tly</title></head>..<body bgcolor="white">..<cent
er><h1>301 Moved Permanently</h1></center>..<h
r><center>nginx/1.8.0</center>..</body>..</htm
l>....
GET /scripts/1/adnl.min.js HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/displayCore2_russian/typ2-1.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cdn.castplatform.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 31 Mar 2016 23:22:45 GMT
Content-Type: text/javascript; charset=utf-8
Content-Length: 59620
Connection: keep-alive
Vary: Accept-Encoding
Content-MD5: EWemSQBepDOLqdXHMBDo7g==
Last-Modified: Wed, 30 Mar 2016 12:54:04 GMT
ETag: 0x8D3589A5F8E2CCD
X-Node: cdn2
Server: NetDNA-cache/2.2
X-Cache: HIT// CAST Delivery Agent v4.4.28 #12:54.!function(global,undefined){Arra
y.prototype.indexOf||(Array.prototype.indexOf=function(e,t){if(this===
undefined||null===this)throw new TypeError('"this" is null or not defi
ned');var n=this.length>>>0;for(t= t||0,1/0===Math.abs(t)&&(t
=0),0>t&&(t =n,0>t&&(t=0));n>t;t )if(this[t]===e)return t;re
turn-1}),"object"!=typeof window.JSON&&(window.JSON={},window.JSON.str
ingify=function(e){if("[object Array]"===Object.prototype.toString.cal
l(e)){if(e.length>0){for(var t=e.length,n=[],a=0;t>a; a)n.push(
this.stringify(e[a]));return"[" n.join(", ") "]"}return"[]"}if("object
"==typeof e&&null!==e){var n=[];for(a in e)n.push('"' a '": ' this.str
ingify(e[a]));return"{" n.join(", ") "}"}return"string"==typeof e?'"'
e.replace(/"/g,'\\"') '"':e},window.JSON.parse=function(text,reviver){
function walk(e,t){var n,a,i=e[t];if(i&&"object"==typeof i)for(n in i)
Object.prototype.hasOwnProperty.call(i,n)&&(a=walk(i,n),a!==undefined?
i[n]=a:delete i[n]);return reviver.call(e,t,i)}var cx=/[\u0000\u00ad\u
0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u202f\u2060-\u206f\u
feff\ufff0-\uffff]/g,j;if(text=String(text),cx.lastIndex=0,cx.test(tex
t)&&(text=text.replace(cx,function(e){return"\\u" ("0000" e.charCodeAt
(0).toString(16)).slice(-4)})),/^[\],:{}\s]*$/.test(text.replace(/\\(?
:["\\\/bfnrt]|u[0-9a-fA-F]{4})/g,"@").replace(/"[^"\\\n\r]*"|true|fals
e|null|-?\d (?:\.\d*)?(?:[eE][ \-]?\d )?/g,"]").replace(/(?:^|:|,)(?:\
s*\[) /g,"")))return j=eval("(" text ")"),"function"==typeof reviv<<< skipped >>>
GET /layouts/graphic_300x250.js?v=4.4.28 HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/displayCore2_russian/typ2-1.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cdn.castplatform.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 31 Mar 2016 23:22:46 GMT
Content-Type: text/javascript; charset=utf-8
Content-Length: 2972
Connection: keep-alive
Vary: Accept-Encoding
Content-MD5: KiIZm6dlzklWp1p98ApFMQ==
Last-Modified: Mon, 28 Mar 2016 09:00:09 GMT
ETag: 0x8D356E75DA2551A
X-Node: cdn1
Server: NetDNA-cache/2.2
X-Cache: HITcb_layout({transformer:{name:["Graphic_300x250"],mainLayout:"graphic_3
00_250_combo",subLayouts:["graphic_300_250_single_inner"]},addZoneType
s:function(e,a){a.graphic_layout={family:"layout_base",style:a.layout_
base.style ".namespace{overflow:hidden;background:#fff;border-top:soli
d 30px #39393a;border-bottom:solid 1px #f6f6f6}.namespace .slots{backg
round-color:#f9f9f9;overflow:hidden}.namespace .ca-sec-title{color:#ff
f;font-weight:400;line-height:30px;margin:0;font-size:12px;position:ab
solute;padding-left:10px;top:0}",template:'<div class="header ca-se
c-title cstm-title">{{adunit_title|default:we_recommend}}</div&g
t;<div class="slots cstm-bg"></div>'},a.graphic_inner=e.ex
tend({},a.inner_base,{style:a.inner_base.style ".namespace{display:blo
ck;overflow:hidden;position:relative;margin:0;border-bottom:solid 1px
#3d3c3d;border-right:solid 1px #3d3c3d;border-left:solid 1px #3d3c3d}.
namespace h1,.namespace h2,.namespace h3,.namespace h4,.namespace h5,.
namespace p{margin:0}.namespace a{right:14px;bottom:12px;color:#2bb22f
;font-size:12px;font-weight:700}.namespace a.download_now_placeholder{
text-decoration:none}.namespace img{position:absolute;border:0}.namesp
ace .ca-title{font-weight:700;color:#4d4d4d;margin:0;height:auto}.name
space .ca-company{color:#768797;font-weight:400;font-size:14px;line-he
ight:24px}.namespace .ca-description{color:#5d5d5d;font-size:14px}.nam
espace .ca-stars-rating{margin-top:12px}.namespace .download_now{posit
ion:absolute;top:auto;right:auto;left:12px;bottom:9px}.namespace i<<< skipped >>>
GET /images/1ad74167-6977-4580-930a-bf7c3478533c.png HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/displayCore2_russian/typ2-1.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cdn.castplatform.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 31 Mar 2016 23:22:46 GMT
Content-Type: image/png; charset=utf-8
Content-Length: 1809
Connection: keep-alive
Vary: Accept-Encoding
Content-MD5: KZth6iAQTO7dVRd0ApjcRg==
Last-Modified: Thu, 10 Mar 2016 09:40:46 GMT
ETag: 0x8D348C80E8AB1A2
X-Node: cdn2
Server: NetDNA-cache/2.2
X-Cache: HIT.PNG........IHDR...d...d.....p..T....tEXtSoftware.Adobe ImageReadyq.e&
lt;...hiTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCe
hiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk=
"Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27 "> &
lt;rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#">
<rdf:Description rdf:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap
/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#"
xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xm
p.did:05801174072068118083CC1380C2A5EB" xmpMM:DocumentID="xmp.did:B9C1
07F2A61611E28BEABCE338DCB390" xmpMM:InstanceID="xmp.iid:B9C107F1A61611
E28BEABCE338DCB390" xmp:CreatorTool="Adobe Photoshop CS6 (Macintosh)"&
gt; <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:AC7ABFA9382068118C
1498AF981ABACE" stRef:documentID="xmp.did:05801174072068118083CC1380C2
A5EB"/> </rdf:Description> </rdf:RDF> </x:xmpmeta>
; <?xpacket end="r"?> ......?IDATx....OSQ.._...(.......VE.E. .@
...5.@.:1...F...?.A.'uW.7.&.$F.'[email protected].....{Z.'.-..i.>..=....
.|..$.T.T9.R...H%.....*.T..EG.....*..1.H=.D.u.?.tn..Vy.RH.lc..S.*-..J.
5.....#.3..N;......A.7......B...A. .!..\..7...4z....T..xdw.[.w.Kn.K.r]
..G%...o....rp].Wt.d...|[X...../.....B....#.......RX....lg<..]..`.m
[z.".o.(-...&i9\.).N..D.u....#.......:.2..*]'kh.&4........a..\.|.x....
..Z............c\..Bo.!)r.!....9r...V.9...m..O{ ...O...w.X!.;.d_..!...
-.O...lB.........hL^.}...S.ibN..C.Z. .*U.....:.Cn..._`.#$Y...-....<<< skipped >>>
GET /pages/displayCore2_russian/typ2-1.html HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: tundra.site
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.8.0
Vary: Accept-Encoding
Content-Type: text/html
Content-Encoding: gzip
Date: Thu, 31 Mar 2016 23:15:27 GMT
Transfer-Encoding: chunked
ETag: W/"558c0294-8c3"
Connection: keep-alive
Set-Cookie: X-Mapping-fjhppofk=3E8E1A8CCA3BD46AD95C5D4A4E8F490A; path=/
Last-Modified: Thu, 25 Jun 2015 13:31:00 GMT37d.............V.n.0......f..& [email protected].;..!.q....B.A...
....7.8i........9>?.w...................c..{.k&.Db..8.D:F"..k..2..q
...7...!7..rI8x.0.Rr.....<.....t.K....(..bV..f..L..T2R..1.......;..
r.........B...>!...I.1\!.Lk..(.m....C.7.K.........4.h..h..Z.a.:1!..
..,............`...%l.QS../.O......H}Q}..7....G.W?...d*....r.$..hH....
.u...{......m..v..9r.b;..Y.F......O...X`(Dul0.V.....W...H......j.M....
%h..C.:...52:I..7...P..`q..y..CY........D..h..XA^.i.A"v...p".E.J...5#.
1.f....D..8..B.y.....b..6.....X....3`.....D..O..4k....^.W..O....J.t..:
c.n.vb..........*.U..h...W......'.....Zur.di...\.G...6.5...-j.....u..O
.K.!..\;AP?]......r......V.Q"....Wy=.Bb...d4.....;..V}k......7../....h
.......z.t...............0....6.....h........W..f.p1.....L.yD....r.vV.
R;......-...|....{....K..H.....o...tH....:..V.AX.Ko..Pn>...x.....&g
t;s.}<...........L....4K...{&."...O.W.Sl.-...$....{$O8...8..Y....%.
........0......
GET /pages/displayCore2_russian/css/style.css HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/displayCore2_russian/typ2-1.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: tundra.site
Connection: Keep-Alive
Cookie: X-Mapping-fjhppofk=3E8E1A8CCA3BD46AD95C5D4A4E8F490A
HTTP/1.1 200 OK
Server: nginx/1.8.0
Date: Thu, 31 Mar 2016 23:15:27 GMT
Content-Type: text/css
Last-Modified: Mon, 16 Jun 2014 11:19:00 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
ETag: W/"539ed2a4-71e"
Content-Encoding: gzip291.............U.n.0.}._a...R..$...mv.....X1...$...;6..K.u.)....3.D".
\.UAe....o...I......TvJ../!....... .).....em. Y.f....A...}AH.]u.%'`Y.B
R.YP.R.geS.2...T Q...dH.. ..N.... [email protected]:.6....S.l....e99..$
.=G]*D..... g.JT..mdv.={A.<h...%.%..8.TF\..i....JC......D....)&...N
...D...%.s.....I..HD.c&ES&.a........o`.....a?.l.........e...........)D
B...W.I-8K0.........@-uC h..is..:@.m&......T.eZl1......{[.6........1.I
S....Btd..q.m`...]c...z....N$. ..&|[email protected]
.........X.....M.=R...S&yp..7.-.w.m..j%......&...u....j4v~..~9.FgP.:..
....N...........p.q....%...gh.rA1....6.......2.....x!...v.|.FF...l.h..
...yP...B$x..%Y..Mu.....;..q.........0......
GET /pages/displayCore2_russian/images/icon2-green.png HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/displayCore2_russian/typ2-1.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: tundra.site
Connection: Keep-Alive
Cookie: X-Mapping-fjhppofk=3E8E1A8CCA3BD46AD95C5D4A4E8F490A
HTTP/1.1 200 OK
Server: nginx/1.8.0
Date: Thu, 31 Mar 2016 23:15:27 GMT
Content-Type: image/png
Content-Length: 3782
Last-Modified: Thu, 12 Jun 2014 09:05:00 GMT
Connection: keep-alive
ETag: "53996d3c-ec6"
Accept-Ranges: bytes.PNG........IHDR...>...E......$UF....tEXtSoftware.Adobe ImageReadyq
.e<...hIDATx..[kl#[email protected]. .}..}P@@.
[email protected]@.".Zg7.$..$q..f..\...c;....(W;.].x.~......;....?.
.....c.|X........B...;D...rv&.M..eE...eZ..1Ts5....E?..{O.x....B.. ..=B
...D...~.,,..p.493...XB.R...2&......1...., .5.....b[.B`ae...oF...p.FZ.
,."..zh......p...yH.l>!4:. .[aXi.3.... |.. ..t.....J...../4...(T.me
L..'9ceC.]R//...FkW.Z...vpb6d..?......=.x..M.RO....P..p[c-..K.p.,v....
....K.|.=......:!..2............<`....j....Mq...C<{*L2j.^05g.q=}
qy`..sy ]3.UK.j.....o.Z.......2&u5{.fw.}6.Oe8cuCO._..<.Jd.9.;......
.[4.2.i....y.K.Z.......q..J.A^..g......1..|.lN.)8............f.q]...4.
...........I..c...=.2..[..2LZ.1rIf....3.....M...2.M.f..R siU..i..0....
.9_.?.'...S.R#.sN.{.s.........@7...%..{........w>....A.V...{?..V9.*
G.....,.......lA.:7.........E.q.C..._W.Dd.k;&D..4..E}3.}..X.c.)`.!.$..
.R.........X.<....^.PH..NO.)...^KM-.......:.8...Q..S7.`. ...V...D.@
.'.<..x!..1.PU.ktr<[email protected]..'d..n.'|v*...R..=.uau0..u
C...S.......G....F............f...h.XN.h..-(..../....l.f..fI..`G.|....
.\...bf..Q*...p....Y..R......w........\[email protected].#.l!
)l(,V....6m.<...E..../.y....P.......y.........O.f....-.....Y....B.(
.s..r....z<jf....m...[Hc...%5.....$..x.Z...u2.....h.........94{....
.9...\.wE.?....!E.\l..S...).....A...2FV.y..Z..d.HEPsy....!.*X.......?s
|.qM..y..U.s.......m....Zi.T......C....m.nB.......4.....Q.........) ..
.Ph..'.~|..nZ'.Fpk..:....3...)_|.~....H..gnM.J?k....$y......-.....<<< skipped >>>
GET /pages/displayCore2_russian/ HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/displayCore2_russian/typ2-1.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: tundra.site
Connection: Keep-Alive
Cookie: X-Mapping-fjhppofk=3E8E1A8CCA3BD46AD95C5D4A4E8F490A
HTTP/1.1 200 OK
Server: nginx/1.8.0
Date: Thu, 31 Mar 2016 23:15:29 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Content-Encoding: gzip114...............n. .......{BpRi.(.....hC..M..uy.A.i..ia.,0..l0L....O
LI.r.t0...V........I..5b..N......#.|.32........r.M.v..t.x..k.c$S.3...@
.....%.<.FDR.r....d....U].....6.....1....S...'..l^..s........"{.\..
l"[email protected]/...^f.0..zg..........9s}}9.*2.....I.-.....~.....
......0..HTTP/1.1 200 OK..Server: nginx/1.8.0..Date: Thu, 31 Mar 2016
23:15:29 GMT..Content-Type: text/html..Transfer-Encoding: chunked..Con
nection: keep-alive..Vary: Accept-Encoding..Content-Encoding: gzip..11
4...............n. .......{BpRi.(.....hC..M..uy.A.i..ia.,0..l0L....OLI
.r.t0...V........I..5b..N......#.|.32........r.M.v..t.x..k.c$S.3...@..
...%.<.FDR.r....d....U].....6.....1....S...'..l^..s........"{.\..l"
[email protected]/...^f.0..zg..........9s}}9.*2.....I.-.....~.......
....0..
GET /api/vv/1?callback=cb_1459466574285&ts=1459466574285&sessionId=iIWgv&rfr=&siteId=9306&aus=3958,1,0 HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/displayCore2_russian/typ2-1.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: d.castplatform.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Length: 1262
Content-Type: text/javascript; charset=utf-8
Server: Microsoft-HTTPAPI/2.0
X-Country: UA
P3P: CP='NON UNI COM NAV STA OUR IND'
Set-Cookie: cuuid=82e9bc9b-44d5-4f0c-a3b6-4f7de78bc34e; expires=Tue, 31 Mar 2026 23:22:46 GMT; domain=d.castplatform.com; path=/
X-Elapsed: 197
X-Node: NEU3940D0
Date: Thu, 31 Mar 2016 23:22:46 GMTcb_1459466574285 && cb_1459466574285({"zones":[{"id":3958,"status":200
,"enabled":true,"template":"Graphic_300x250","data":[{"title":"Faceboo
k","description":"................ .............. Facebook\n..........
........................ .................. .. .......................
. .. ........","button":"......................","company":"","rating"
:0.0,"clk":"w-dh5isXlIs-RD0VRYRP7M2Eg0aQr2g0TPvrPtScS91GlGNqEVYGk5Q4LB
tGVMBvMgKKmqC12MVG6JXLHNwTUYVxekzcsG592pshMC62OFV2bNEumQWcyzpKKgnOOEwB
un536LluYm0SpKKryx-RKosTyANrUjm0ev9VzHlXtdbrhctgM-ddMQmtq5oKEp5gG8ys1u
UOq1iNDcCwEPV0dEKIisjHmPThALNG07pW4j8IHCNtKUhjmqqpLPXpjBzVOc2VqkWVqDyO
SrXTbgDzyusuMKZvnqijvhTR5Ay-w5Jj7aovvjuGIwqdKLmMfWi9BnQ7U426SKkRWFNyka
713u-398VER8GkP6rPkicmWjAxjtxpDqk2-MfVtASAmiE4QA4YJ9ZqTm7bi_Jbtkmhdmwd
9oXb9xlQyWOJk-IMRhqa60bnewxg4kX3lhnIJfwEBKK8uVoUGv_1me7SnoWm9g","width
":300,"height":250,"cUrl":"hXXp://d.castplatform.com/api/c/1?clk=%clk%
","trackers":[{"type":"Url","content":"hXXp://d.castplatform.com/api/v
p/1?clk=%clk%"}],"category":null,"assets":[{"assetDisplayType":2,"widt
h":96,"height":96,"url":"//cdn.castplatform.com/images/1ad74167-6977-4
580-930a-bf7c3478533c.png","javascript":"","clickTagVar":""}]}],"style
s":null,"settings":{"adUnitTitle":""},"displayType":"Size"}],"ts":197}
);..<<< skipped >>>
GET /flstudio/flstudio_12.0.2.exe HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: demodownload.image-line.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: application/x-msdos-program
Accept-Ranges: bytes
ETag: "4106556841"
Last-Modified: Tue, 12 May 2015 15:58:10 GMT
Content-Length: 455819504
Date: Thu, 31 Mar 2016 23:22:43 GMT
Server: lighttpd/1.4.28MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.......1..:u..iu..i
u..i...iw..iu..i...i...id..i!..i...i...it..iRichu..i..................
......PE..L......K.................\..........<2.......p....@......
[email protected] ......................................s.
..........z...........3 .8............................................
................p...............................text...ZZ.......\.....
............. ..`.rdata.......p.......`..............@[email protected]........
[email protected][email protected]
rc....z.......|...v..............@..@.................................
......................................................................
......................................................................
......................................................................
......................................................................
...............................................U....\.}..t .}.F.E.u..H
.....>[email protected].>[email protected].
P.u...Pr@..}[email protected]... M.......M....3.....FQ.....N
U..M..........VT..U.....FP..E...............E.P.M...Hp@..E...E.P.E.P.u
[email protected]}[email protected].}.j.W.E......E.......P
[email protected]@[email protected] [email protected]..
.\r@._^3.[.....L$...>B...Si.....VW.T.....tO.q.3.;5.>B.sB..i.....
.D.......t.G.....t...O..t .....u...3....3...F.....;5.>B.r._^[..<<< skipped >>>
The Trojan connects to the servers at the folowing location(s):
%?9-*09,*19}*09
.text
`.data
.rsrc
msvcrt.dll
KERNEL32.dll
NTDLL.DLL
USER32.dll
SHLWAPI.dll
SHDOCVW.dll
Software\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess
IE-X-X
rsabase.dll
System\CurrentControlSet\Control\Windows
dw15 -x -s %u
watson.microsoft.com
IEWatsonURL
%s -h %u
iedw.exe
Iexplore.XPExceptionFilter
jscript.DLL
mshtml.dll
mlang.dll
urlmon.dll
wininet.dll
shdocvw.DLL
browseui.DLL
comctl32.DLL
IEXPLORE.EXE
iexplore.pdb
ADVAPI32.dll
MsgWaitForMultipleObjects
IExplorer.EXE
IIIIIB(II<.Fg
7?_____ZZSSH%
)z.UUUUUUUU
,....Qym
````2```
{.QLQIIIKGKGKGKGKGKG;33;33;0
8888880
8887080
browseui.dll
shdocvw.dll
6.00.2900.5512 (xpsp.080413-2105)
Windows
Operating System
6.00.2900.5512
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
%original file name%.exe:1632
- Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\desktop.ini (159 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.