Trojan.Win32.IEDummy_57afb57eb9
Trojan.Win32.IEDummy.FD, mzpefinder_pcap_file.YR (Lavasoft MAS)
Behaviour: Trojan
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: 57afb57eb9cd7bbf6129ba5458f33f0c
SHA1: 8b9cd7bd129beddbec21161db57c9f7353070b6f
SHA256: d348c4232c3c263691de65c71afeb78295a26cb40bc2e3f5f23691346604f9dd
SSDeep: 98304:U1BZdOT3gk62FJD7mGtpi4vtpydBDAjBirCp331WAO2aQg/lR:UDO8NKmr4vewUrCF1zOlQg/lR
Size: 4480928 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPXv0896v102v105v122Delphistub, UPolyXv05_v6
Company: no certificate found
Created at: 1992-06-20 01:22:17
Analyzed on: WindowsXP SP3 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
%original file name%.exe:188
The Trojan injects its code into the following process(es):
No processes have been created.
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process %original file name%.exe:188 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\desktop.ini (159 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2CE9S84I\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\NTER05EZ\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4LMR4XMF\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\68E7ZN4T\desktop.ini (67 bytes)
Registry activity
The process %original file name%.exe:188 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"Guid" = "8aefce96-4618-42ff-a057-3536aa78233e"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKCR\CLSID\{C379EAD1-CB34-4B09-AF6B-7E587F8BCD80}\ProgID]
"(Default)" = "57afb57eb9cd7bbf6129ba5458f33f0c.DynamicNS"
[HKCR\CLSID\{C379EAD1-CB34-4B09-AF6B-7E587F8BCD80}]
"(Default)" = "DynamicNS"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"TypesSupported" = "7"
"CategoryCount" = "16"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\ESENT\Process\57afb57eb9cd7bbf6129ba5458f33f0c\DEBUG]
"Trace Level" = ""
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"LogSessionName" = "stdout"
[HKCR\57afb57eb9cd7bbf6129ba5458f33f0c.DynamicNS]
"(Default)" = "DynamicNS"
[HKCR\CLSID\{C379EAD1-CB34-4B09-AF6B-7E587F8BCD80}\LocalServer32]
"(Default)" = "c:\%original file name%.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKCR\57afb57eb9cd7bbf6129ba5458f33f0c.DynamicNS\Clsid]
"(Default)" = "{C379EAD1-CB34-4B09-AF6B-7E587F8BCD80}"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"LogSessionName" = "stdout"
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "90 B4 BA F9 97 FD 91 46 58 65 EE 87 8C 91 40 63"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"CategoryMessageFile" = "%System%\ESENT.dll"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"LogSessionName" = "stdout"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"EventMessageFile" = "%System%\ESENT.dll"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"ControlFlags" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\ESENT\Process\57afb57eb9cd7bbf6129ba5458f33f0c\DEBUG]
"Trace Level"
Dropped PE files
There are no dropped PE files.
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name:
Product Name:
Product Version: 1.0.0.0
Legal Copyright:
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 1.0.0.0
File Description:
Comments:
Language: English (United States)
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| UPX0 | 4096 | 3072000 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| UPX1 | 3076096 | 3067904 | 3064832 | 5.47945 | bc5547e2e9a84385840e03c9434f4ef7 |
| .rsrc | 6144000 | 28672 | 26112 | 3.56985 | 99354acfc5ff0c1006e67d596d7e6ddd |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 49
1b1e4162b7ca77292a8fa08bb6313f5d
86016b47293c34508e6e38c6115b9429
cdf1d8f61c99d1694f56d325ff6b28e7
14c144c420fe39453f86c2f34a08814c
d8fd3c2de54637e95267b5e3d7eb6ae4
0edda393d56876fa62eff6579f2ec0d4
c78864a477d72bc077fb0306062f0bcb
b1a12fe143f8495431a2d33a3c252fbe
1aa18274022b8f8b30412a3b2394dbcf
d96c41956306df5e81e3a5ef413dd4ef
89a0c27e8f701dceecc45efab078352e
b4996d4b4ee9d8246359588a46973576
e200fc2ad6f5610cea8ca6f8f71fde5a
9caf299f6670f46072a845d9266b0a52
19f279db0af179d91ed577e3c4f21be7
46a3c2d30674acc3963db1c18e982b93
5f97a8f7affaf610840dc739f5239462
a92b129672337cfbd8dc0a6728e35da0
7a0ee1fd6f1962380a5285e7a0543392
d7974d531caf5e8ac69ee80b35c14b97
45b5cc1a1a1e8ecb5d4328628191addf
45e9cb78d94272f767fd9883b51b229e
2fbe5c27758b1b27aa870025c31a80c8
e2e04529f943d0f32b0581ef8948071d
4713a4f5097cadb4a3a9aa720363d2a9
URLs
| URL | IP |
|---|---|
| hxxp://ychrome.ru/ChromeSetup.exe | |
| hxxp://download.torrentex.ru/download.php | |
| hxxp://download1.torrentex.ru/download/torrentex0.1.4b.exe | |
| hxxp://digimatic.biz/pages/displayCore2_russian/typ2-1.html | |
| hxxp://tundra.site/pages/displayCore2_russian/typ2-1.html | |
| hxxp://tundra.site/pages/displayCore2_russian/css/style.css | |
| hxxp://tundra.site/pages/displayCore2_russian/images/icon2-green.png | |
| hxxp://tundra.site/pages/displayCore2_russian/images/icon1-green.png | |
| hxxp://tundra.site/pages/displayCore2_russian/images/icon3-green.png | |
| hxxp://cast-prod-dlv-pull.ironsrc.netdna-cdn.com/scripts/1/adnl.min.js | |
| hxxp://neu-dl-api.cloudapp.net/api/vv/1?callback=cb_1456810791975&ts=1456810791975&sessionId=tojgT&rfr=&siteId=9306&aus=3958,1,0 | |
| hxxp://cast-prod-dlv-pull.ironsrc.netdna-cdn.com/layouts/graphic_300x250.js?v=4.4.27 | |
| hxxp://cast-prod-dlv-pull.ironsrc.netdna-cdn.com/images/d00f789b-95d8-4133-8eb1-0fd872f98e9b.gif | |
| hxxp://tundra.site/pages/displayCore2_russian/ | |
| hxxp://neu-dl-api.cloudapp.net/api/vp/1?clk=pAg7JYVWr-J2Omty0H00tHi51GfpOen2sqMreJuIY74r3HQ122cCaeo14YK1hwXtmaWluvgnPxOiW9khXedBJ-ZLBHvfB6Z27PayBtzREUcENrSv78i_z_M4x7vozutOWbIeFH7DmuJcvSzGdjdKvuO2vREj2UipylgOxo3PyGThcu5hA8Ns3pfawuA53cMpdWxtnuCiywB-hZgIunzeIB7kwn-GlICo1ST7agPQLSdS40TFmUbqpv4D9p_wRKIyjF1dXjU5pPLD6adTwWuZ92qVvACqOnkq4XWMyzkzJV7S_WpRndTx1JY5aeXd7y0gkQhCNnvcg4v9rh02LybEYkOLn6PPU_3lblzoDyq3lsV11JZ6KrLrel6zd2uByVkPDovlqltjr9ZQ1N6maV68_5Wvt0XTgoWd4fXwPNn74Cj8-iSFSs4oK9x2DuNUK4c6N5RWQvmqAlEHfn6hlrr8Xw&rfr= | |
| hxxp://cdn.castplatform.com/layouts/graphic_300x250.js?v=4.4.27 | |
| hxxp://cdn.castplatform.com/scripts/1/adnl.min.js | |
| hxxp://d.castplatform.com/api/vv/1?callback=cb_1456810791975&ts=1456810791975&sessionId=tojgT&rfr=&siteId=9306&aus=3958,1,0 | |
| hxxp://cdn.castplatform.com/images/d00f789b-95d8-4133-8eb1-0fd872f98e9b.gif | |
| hxxp://d.castplatform.com/api/vp/1?clk=pAg7JYVWr-J2Omty0H00tHi51GfpOen2sqMreJuIY74r3HQ122cCaeo14YK1hwXtmaWluvgnPxOiW9khXedBJ-ZLBHvfB6Z27PayBtzREUcENrSv78i_z_M4x7vozutOWbIeFH7DmuJcvSzGdjdKvuO2vREj2UipylgOxo3PyGThcu5hA8Ns3pfawuA53cMpdWxtnuCiywB-hZgIunzeIB7kwn-GlICo1ST7agPQLSdS40TFmUbqpv4D9p_wRKIyjF1dXjU5pPLD6adTwWuZ92qVvACqOnkq4XWMyzkzJV7S_WpRndTx1JY5aeXd7y0gkQhCNnvcg4v9rh02LybEYkOLn6PPU_3lblzoDyq3lsV11JZ6KrLrel6zd2uByVkPDovlqltjr9ZQ1N6maV68_5Wvt0XTgoWd4fXwPNn74Cj8-iSFSs4oK9x2DuNUK4c6N5RWQvmqAlEHfn6hlrr8Xw&rfr= |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
ET SHELLCODE Possible TCP x86 JMP to CALL Shellcode Detected
ET TROJAN VMProtect Packed Binary Inbound via HTTP - Likely Hostile
Traffic
GET /api/vv/1?callback=cb_1456810791975&ts=1456810791975&sessionId=tojgT&rfr=&siteId=9306&aus=3958,1,0 HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/displayCore2_russian/typ2-1.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: d.castplatform.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Length: 1209
Content-Type: text/javascript; charset=utf-8
Server: Microsoft-HTTPAPI/2.0
X-Country: UA
P3P: CP='NON UNI COM NAV STA OUR IND'
Set-Cookie: cuuid=e51004e0-f12a-45d1-9b51-535fdafb3baf; expires=Sun, 01 Mar 2026 05:41:40 GMT; domain=d.castplatform.com; path=/
X-Elapsed: 178
X-Node: NEU3940D6
Date: Tue, 01 Mar 2016 05:41:39 GMTcb_1456810791975 && cb_1456810791975({"zones":[{"id":3958,"status":200
,"enabled":true,"template":"Graphic_300x250","data":[{"title":"Windows
PC Repair","description":"Scan your PC for Windows errors with 1 clic
k to diagnose and Repair damages!","button":"Download Now","company":"
Reimage","rating":3.5,"clk":"pAg7JYVWr-J2Omty0H00tHi51GfpOen2sqMreJuIY
74r3HQ122cCaeo14YK1hwXtmaWluvgnPxOiW9khXedBJ-ZLBHvfB6Z27PayBtzREUcENrS
v78i_z_M4x7vozutOWbIeFH7DmuJcvSzGdjdKvuO2vREj2UipylgOxo3PyGThcu5hA8Ns3
pfawuA53cMpdWxtnuCiywB-hZgIunzeIB7kwn-GlICo1ST7agPQLSdS40TFmUbqpv4D9p_
wRKIyjF1dXjU5pPLD6adTwWuZ92qVvACqOnkq4XWMyzkzJV7S_WpRndTx1JY5aeXd7y0gk
QhCNnvcg4v9rh02LybEYkOLn6PPU_3lblzoDyq3lsV11JZ6KrLrel6zd2uByVkPDovlqlt
jr9ZQ1N6maV68_5Wvt0XTgoWd4fXwPNn74Cj8-iSFSs4oK9x2DuNUK4c6N5RWQvmqAlEHf
n6hlrr8Xw","width":300,"height":250,"cUrl":"hXXp://d.castplatform.com/
api/c/1?clk=%clk%","trackers":[{"type":"Url","content":"hXXp://d.castp
latform.com/api/vp/1?clk=%clk%"}],"category":null,"assets":[{"assetDis
playType":2,"width":96,"height":96,"url":"//cdn.castplatform.com/image
s/d00f789b-95d8-4133-8eb1-0fd872f98e9b.gif","javascript":"","clickTagV
ar":""}]}],"styles":null,"settings":{"adUnitTitle":""},"displayType":"
Size"}],"ts":178});....<<< skipped >>>
GET /api/vp/1?clk=pAg7JYVWr-J2Omty0H00tHi51GfpOen2sqMreJuIY74r3HQ122cCaeo14YK1hwXtmaWluvgnPxOiW9khXedBJ-ZLBHvfB6Z27PayBtzREUcENrSv78i_z_M4x7vozutOWbIeFH7DmuJcvSzGdjdKvuO2vREj2UipylgOxo3PyGThcu5hA8Ns3pfawuA53cMpdWxtnuCiywB-hZgIunzeIB7kwn-GlICo1ST7agPQLSdS40TFmUbqpv4D9p_wRKIyjF1dXjU5pPLD6adTwWuZ92qVvACqOnkq4XWMyzkzJV7S_WpRndTx1JY5aeXd7y0gkQhCNnvcg4v9rh02LybEYkOLn6PPU_3lblzoDyq3lsV11JZ6KrLrel6zd2uByVkPDovlqltjr9ZQ1N6maV68_5Wvt0XTgoWd4fXwPNn74Cj8-iSFSs4oK9x2DuNUK4c6N5RWQvmqAlEHfn6hlrr8Xw&rfr= HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/displayCore2_russian/typ2-1.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: d.castplatform.com
Connection: Keep-Alive
Cookie: cuuid=e51004e0-f12a-45d1-9b51-535fdafb3baf
HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Length: 43
Content-Type: image/gif
Server: Microsoft-HTTPAPI/2.0
Set-Cookie: cuuid=2449d090-9930-4b1f-a071-28aaccd09926; expires=Sun, 01 Mar 2026 05:41:40 GMT; domain=d.castplatform.com; path=/
P3P: CP='NON UNI COM NAV STA OUR IND'
X-Elapsed: 0
Date: Tue, 01 Mar 2016 05:41:40 GMTGIF89a.............!.......,...........L..;HTTP/1.1 200 OK..Cache-Cont
rol: no-cache..Content-Length: 43..Content-Type: image/gif..Server: Mi
crosoft-HTTPAPI/2.0..Set-Cookie: cuuid=2449d090-9930-4b1f-a071-28aaccd
09926; expires=Sun, 01 Mar 2026 05:41:40 GMT; domain=d.castplatform.co
m; path=/..P3P: CP='NON UNI COM NAV STA OUR IND'..X-Elapsed: 0..Date:
Tue, 01 Mar 2016 05:41:40 GMT..GIF89a.............!.......,...........
L..;..
GET /pages/displayCore2_russian/images/icon1-green.png HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/displayCore2_russian/typ2-1.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: tundra.site
Connection: Keep-Alive
Cookie: X-Mapping-fjhppofk=3E8E1A8CCA3BD46AD95C5D4A4E8F490A
HTTP/1.1 200 OK
Server: nginx/1.8.0
Date: Tue, 01 Mar 2016 05:35:48 GMT
Content-Type: image/png
Content-Length: 3392
Last-Modified: Thu, 12 Jun 2014 09:04:00 GMT
Connection: keep-alive
ETag: "53996d00-d40"
Accept-Ranges: bytes.PNG........IHDR...>...E......$UF....tEXtSoftware.Adobe ImageReadyq
.e<....IDATx..[{l[W.?..g..fvR.]..2.4.z.N..?jOC......C....IS[....%Y.
...........i][email protected].@.?Hs%.:&.....&..c.............#YIS...;.w.....cB.O.
.....GE.l.3.n7.2Rv..FQ..JF. ...Lt.....?..m.cN...'yK...k..Y..l.........
.j...qO:.?.......n...8K........K7<9X.db.$.....b.............=-.....
...<uhB..2......-/VI.Hzy.$."..?y...<.....-.iF..x.. ...N..ke....)
......!._.mJc..p,a.Z.Gd.x.(...p.......j....~3.. .I..a....~4...S...NN0f
.W..2.I.....t....i`..1d.6....E...^.oKGb$qm.}..;.f...g...h%x..t.K ..'..
.....(X...W.:...]#.p......>.._;.>j..{..V.(k.W...O\....oj..^.....
K.lq>.<.......eJ........?..Yp.`.Ic........F............OV.../...
n.....u.3...F..`... .....oj..b.......7"..;]i.B.. ...K.A{..W.^.g....9..
?}..p....R.M....i..N.D....;......QK..,".....9.....ub>...P.....g:9/.
..:?.y?..a8...L....L.b.s............W...O|.S...w*...3=..J.,...:...3ok.
.mz....W....E.S.F.N...99K.v.S.P.......].!ey:]#C..!.8 .W...D;dq.......&
gt;;...|Y.,3D.Gq.Mg.D..i.|..X.......[[email protected].*cYmj.=.3..2........W.
..vw...fy9^.....z......pEQ. ...Q....T....#.[/..t.0z.h!..>t.....%".B
l.{.<.{.JW.....?.3h.{w...(...DF..p...dV.}X....PJ...n.A.....o. p.(..
........H..3....H...N....F)p8....$.......Y....z:Tn.....W.q....6..D..G.
Ud.f.....C.X....D......N..{..T.j......../."..=...g..)..<(hwX.rf...0
...Z=J..=....1B..n.$U\.P.re.ku.u&8.nC.........W........so..../.O5...G.
....OB#%...x...~..`.;.....^.m."...........q..S]..T.....Fj)>...|.jZ.
..['.....:.s.x..O.m.....[....\$0..{..&.r...^.U...?.o..Y.......ZW].<<< skipped >>>
GET /pages/displayCore2_russian/ HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/displayCore2_russian/typ2-1.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: tundra.site
Connection: Keep-Alive
Cookie: X-Mapping-fjhppofk=3E8E1A8CCA3BD46AD95C5D4A4E8F490A
HTTP/1.1 200 OK
Server: nginx/1.8.0
Date: Tue, 01 Mar 2016 05:35:50 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Content-Encoding: gzip114...............n. .......{BpRi.(.....hC..M..uy.A.i..ia.,0..l0L....O
LI.r.t0...V........I..5b..N......#.|.32........r.M.v..t.x..k.c$S.3...@
.....%.<.FDR.r....d....U].....6.....1....S...'..l^..s........"{.\..
l"[email protected]/...^f.0..zg..........9s}}9.*2.....I.-.....~.....
......0..HTTP/1.1 200 OK..Server: nginx/1.8.0..Date: Tue, 01 Mar 2016
05:35:50 GMT..Content-Type: text/html..Transfer-Encoding: chunked..Con
nection: keep-alive..Vary: Accept-Encoding..Content-Encoding: gzip..11
4...............n. .......{BpRi.(.....hC..M..uy.A.i..ia.,0..l0L....OLI
.r.t0...V........I..5b..N......#.|.32........r.M.v..t.x..k.c$S.3...@..
...%.<.FDR.r....d....U].....6.....1....S...'..l^..s........"{.\..l"
[email protected]/...^f.0..zg..........9s}}9.*2.....I.-.....~.......
....0..
GET /download.php HTTP/1.0
Connection: keep-alive
Host: download.torrentex.ru
Accept: text/html,application/xhtml xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: identity
User-Agent: Mozilla/3.0 (compatible; Indy Library)
HTTP/1.1 302 Found
Server: nginx/1.4.6 (Ubuntu)
Date: Tue, 01 Mar 2016 05:32:07 GMT
Content-Type: text/html
Content-Length: 0
Connection: keep-alive
Location: hXXp://download1.torrentex.ru/download/torrentex0.1.4b.exe
GET /pages/displayCore2_russian/typ2-1.html HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: tundra.site
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.8.0
Vary: Accept-Encoding
Content-Type: text/html
Content-Encoding: gzip
Date: Tue, 01 Mar 2016 05:35:48 GMT
Transfer-Encoding: chunked
ETag: W/"558c0294-8c3"
Connection: keep-alive
Set-Cookie: X-Mapping-fjhppofk=3E8E1A8CCA3BD46AD95C5D4A4E8F490A; path=/
Last-Modified: Thu, 25 Jun 2015 13:31:00 GMT37d.............V.n.0......f..& [email protected].;..!.q....B.A...
....7.8i........9>?.w...................c..{.k&.Db..8.D:F"..k..2..q
...7...!7..rI8x.0.Rr.....<.....t.K....(..bV..f..L..T2R..1.......;..
r.........B...>!...I.1\!.Lk..(.m....C.7.K.........4.h..h..Z.a.:1!..
..,............`...%l.QS../.O......H}Q}..7....G.W?...d*....r.$..hH....
.u...{......m..v..9r.b;..Y.F......O...X`(Dul0.V.....W...H......j.M....
%h..C.:...52:I..7...P..`q..y..CY........D..h..XA^.i.A"v...p".E.J...5#.
1.f....D..8..B.y.....b..6.....X....3`.....D..O..4k....^.W..O....J.t..:
c.n.vb..........*.U..h...W......'.....Zur.di...\.G...6.5...-j.....u..O
.K.!..\;AP?]......r......V.Q"....Wy=.Bb...d4.....;..V}k......7../....h
.......z.t...............0....6.....h........W..f.p1.....L.yD....r.vV.
R;......-...|....{....K..H.....o...tH....:..V.AX.Ko..Pn>...x.....&g
t;s.}<...........L....4K...{&."...O.W.Sl.-...$....{$O8...8..Y....%.
........0......
GET /pages/displayCore2_russian/css/style.css HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/displayCore2_russian/typ2-1.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: tundra.site
Connection: Keep-Alive
Cookie: X-Mapping-fjhppofk=3E8E1A8CCA3BD46AD95C5D4A4E8F490A
HTTP/1.1 200 OK
Server: nginx/1.8.0
Vary: Accept-Encoding
Content-Type: text/css
Content-Encoding: gzip
Date: Tue, 01 Mar 2016 05:35:48 GMT
Transfer-Encoding: chunked
ETag: W/"539ed2a4-71e"
Connection: Keep-Alive
Last-Modified: Mon, 16 Jun 2014 11:19:00 GMT291.............U.n.0.}._a...R..$...mv.....X1...$...;6..K.u.)....3.D".
\.UAe....o...I......TvJ../!....... .).....em. Y.f....A...}AH.]u.%'`Y.B
R.YP.R.geS.2...T Q...dH.. ..N.... [email protected]:.6....S.l....e99..$
.=G]*D..... g.JT..mdv.={A.<h...%.%..8.TF\..i....JC......D....)&...N
...D...%.s.....I..HD.c&ES&.a........o`.....a?.l.........e...........)D
B...W.I-8K0.........@-uC h..is..:@.m&......T.eZl1......{[.6........1.I
S....Btd..q.m`...]c...z....N$. ..&|[email protected]
.........X.....M.=R...S&yp..7.-.w.m..j%......&...u....j4v~..~9.FgP.:..
....N...........p.q....%...gh.rA1....6.......2.....x!...v.|.FF...l.h..
...yP...B$x..%Y..Mu.....;..q.........0......
GET /pages/displayCore2_russian/images/icon2-green.png HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/displayCore2_russian/typ2-1.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: tundra.site
Connection: Keep-Alive
Cookie: X-Mapping-fjhppofk=3E8E1A8CCA3BD46AD95C5D4A4E8F490A
HTTP/1.1 200 OK
Server: nginx/1.8.0
Date: Tue, 01 Mar 2016 05:35:48 GMT
Content-Type: image/png
Content-Length: 3782
Last-Modified: Thu, 12 Jun 2014 09:05:00 GMT
Connection: keep-alive
ETag: "53996d3c-ec6"
Accept-Ranges: bytes.PNG........IHDR...>...E......$UF....tEXtSoftware.Adobe ImageReadyq
.e<...hIDATx..[kl#[email protected]. .}..}P@@.
[email protected]@.".Zg7.$..$q..f..\...c;....(W;.].x.~......;....?.
.....c.|X........B...;D...rv&.M..eE...eZ..1Ts5....E?..{O.x....B.. ..=B
...D...~.,,..p.493...XB.R...2&......1...., .5.....b[.B`ae...oF...p.FZ.
,."..zh......p...yH.l>!4:. .[aXi.3.... |.. ..t.....J...../4...(T.me
L..'9ceC.]R//...FkW.Z...vpb6d..?......=.x..M.RO....P..p[c-..K.p.,v....
....K.|.=......:!..2............<`....j....Mq...C<{*L2j.^05g.q=}
qy`..sy ]3.UK.j.....o.Z.......2&u5{.fw.}6.Oe8cuCO._..<.Jd.9.;......
.[4.2.i....y.K.Z.......q..J.A^..g......1..|.lN.)8............f.q]...4.
...........I..c...=.2..[..2LZ.1rIf....3.....M...2.M.f..R siU..i..0....
.9_.?.'...S.R#.sN.{.s.........@7...%..{........w>....A.V...{?..V9.*
G.....,.......lA.:7.........E.q.C..._W.Dd.k;&D..4..E}3.}..X.c.)`.!.$..
.R.........X.<....^.PH..NO.)...^KM-.......:.8...Q..S7.`. ...V...D.@
.'.<..x!..1.PU.ktr<[email protected]..'d..n.'|v*...R..=.uau0..u
C...S.......G....F............f...h.XN.h..-(..../....l.f..fI..`G.|....
.\...bf..Q*...p....Y..R......w........\[email protected].#.l!
)l(,V....6m.<...E..../.y....P.......y.........O.f....-.....Y....B.(
.s..r....z<jf....m...[Hc...%5.....$..x.Z...u2.....h.........94{....
.9...\.wE.?....!E.\l..S...).....A...2FV.y..Z..d.HEPsy....!.*X.......?s
|.qM..y..U.s.......m....Zi.T......C....m.nB.......4.....Q.........) ..
.Ph..'.~|..nZ'.Fpk..:....3...)_|.~....H..gnM.J?k....$y......-.....<<< skipped >>>
GET /pages/displayCore2_russian/images/icon3-green.png HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/displayCore2_russian/typ2-1.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: tundra.site
Connection: Keep-Alive
Cookie: X-Mapping-fjhppofk=3E8E1A8CCA3BD46AD95C5D4A4E8F490A
HTTP/1.1 200 OK
Server: nginx/1.8.0
Date: Tue, 01 Mar 2016 05:35:49 GMT
Content-Type: image/png
Content-Length: 1519
Last-Modified: Thu, 12 Jun 2014 09:06:00 GMT
Connection: keep-alive
ETag: "53996d78-5ef"
Accept-Ranges: bytes.PNG........IHDR...>...E......$UF....tEXtSoftware.Adobe ImageReadyq
.e<....IDATx..[.O[u.........(.E....o..............U0...Q`.%...}0..$
..d....%&=<.H.|q.sNZ..R..=7.._/P...Z.....rN.....;..0`.......0`.....
S<q..x.6...8. .....4=A].....Y...L<y~&\".I.G..X.Y,......L\{......
./[email protected]:8.....!...............j..W.h..UvZ...bC.
B....1..j\YZ..9...9....r0..8......V...\..[.HO.y..`.{w..SQ.[.m..L.V.nli
.....L..`..n&...\[email protected].~.f......:.......x.i.g.......s
...>4...J...z .^r.z..3....RO<y.wI.).Z..v......^p.u.y"H....W*6Q..
tX."?..w...'...%. .......f.|o....3.s......:.Zz].2.............|.v..U..
..c..z.b....i........>....q.S .....'k3...6.......>D.qY.E........
....................1e1=.Ff)..o..|_..O...z...P6. ... ....?O.S...=.DtU.
.c.-C....SG.%.Y....*.......#.=y.K.quyM.......g.(....\9y.Y..s\v....!...
....>@..d............I..d{.m...!..zFR..........._#rr9.g....ut~....!
..;....-....*w...Hx.E.C]........}.....c.n"..>.".._.ZQ.C.."....q.j".
..... ......._I....S.g.....f...o3..Q...jpf......s.)...1B].SO..3..$N..]
.g(.z......D.......T...C/......u.a}....`. ":m.-m..W.....4..JJ.}...%.U.
T....-.N.....m."..?YE...q=....|P.....X.H,.......|..J.F.#M.......w.t...
Xrr&..e=;.a......R.e.RN...2....n-....g..8d../;....b......p..).&.0Xm.._
.Gs.T..V.y.mo..3....h...F.-.^HH......k....2i...v..&.......j..s,...~ok.
.....=......n.`.x..1.-.I...G..V...F...,U.K...Hb".;p...A/...s.V/.._....
7q.S.|....&.~81v-..../...!.G.Q.m............\./*.$h...>..*[email protected]~
h1yH..W.E...Wp].a.'{....8r.A,...r.....).hY...?.KE.u.........._...d<<< skipped >>>
GET /ChromeSetup.exe HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: ychrome.ru
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 01 Mar 2016 05:41:36 GMT
Content-Type: application/octet-stream
Content-Length: 880784
Connection: keep-alive
Last-Modified: Fri, 04 Dec 2015 22:55:46 GMT
ETag: "14248c8-d7090-5261a6867cdd3"
Accept-Ranges: bytesMZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.......{..5?.|f?.|f
?.|f$..f0.|f$..fa.|f$..f..|f$..f9.|f6..f4.|f?.}fO.|f$..f>.|f?..f..|
f$..f>.|fRich?.|f........PE..L.....[T.....................^......)S
............@.................................]K....@.................
................D...x....`..$............8...8...p....................
......................@............................................tex
t............................... ..`.rdata...1.......2................
..@[email protected]....,[email protected]...$....`..........
............@[email protected]......."[email protected]..............
......................................................................
......................................................................
......................................................................
......................................................................
..................................................U..3..}.....j....j.j
[email protected],...t ...t..."[email protected]....
..][email protected]..([email protected]%[email protected].;.s.N....|O
.u.;.r.3..........#._^][email protected][email protected].].P.u..E..{...YY]
.U..QSVW3...JA.S........E......<..u>[email protected][email protected]
.V.1.....YY..u..u....J....E.....u.3._^[.......H........J........P.R..U
[email protected][email protected][email protected][email protected].......
....;u.r.hW...........P. b..Y;E.s.......P.u.S.0b..P.<....M.....<<< skipped >>>
GET /pages/displayCore2_russian/typ2-1.html HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: digimatic.biz
Connection: Keep-Alive
HTTP/1.1 301 Moved Permanently
Server: nginx/1.8.0
Date: Tue, 01 Mar 2016 05:35:48 GMT
Content-Type: text/html
Content-Length: 184
Connection: keep-alive
Location: hXXp://tundra.site/pages/displayCore2_russian/typ2-1.html<html>..<head><title>301 Moved Permanently</title
></head>..<body bgcolor="white">..<center><h1&
gt;301 Moved Permanently</h1></center>..<hr><cent
er>nginx/1.8.0</center>..</body>..</html>..HTTP/1
.1 301 Moved Permanently..Server: nginx/1.8.0..Date: Tue, 01 Mar 2016
05:35:48 GMT..Content-Type: text/html..Content-Length: 184..Connection
: keep-alive..Location: hXXp://tundra.site/pages/displayCore2_russian/
typ2-1.html..<html>..<head><title>301 Moved Permanen
tly</title></head>..<body bgcolor="white">..<cent
er><h1>301 Moved Permanently</h1></center>..<h
r><center>nginx/1.8.0</center>..</body>..</htm
l>....
GET /scripts/1/adnl.min.js HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/displayCore2_russian/typ2-1.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cdn.castplatform.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Tue, 01 Mar 2016 05:41:40 GMT
Content-Type: text/javascript; charset=utf-8
Content-Length: 59414
Connection: keep-alive
Vary: Accept-Encoding
Content-MD5: tlGRjZdEAb8gg079PUsx5Q==
Last-Modified: Mon, 01 Feb 2016 13:19:45 GMT
ETag: 0x8D32B0A5A54EF35
X-Node: cdn1
Server: NetDNA-cache/2.2
X-Cache: HIT// CAST Delivery Agent v4.4.27 #13:19.!function(global,undefined){Arra
y.prototype.indexOf||(Array.prototype.indexOf=function(e,t){if(this===
undefined||null===this)throw new TypeError('"this" is null or not defi
ned');var n=this.length>>>0;for(t= t||0,1/0===Math.abs(t)&&(t
=0),0>t&&(t =n,0>t&&(t=0));n>t;t )if(this[t]===e)return t;re
turn-1}),"object"!=typeof window.JSON&&(window.JSON={},window.JSON.str
ingify=function(e){if("[object Array]"===Object.prototype.toString.cal
l(e)){if(e.length>0){for(var t=e.length,n=[],a=0;t>a; a)n.push(
this.stringify(e[a]));return"[" n.join(", ") "]"}return"[]"}if("object
"==typeof e&&null!==e){var n=[];for(a in e)n.push('"' a '": ' this.str
ingify(e[a]));return"{" n.join(", ") "}"}return"string"==typeof e?'"'
e.replace(/"/g,'\\"') '"':e},window.JSON.parse=function(text,reviver){
function walk(e,t){var n,a,i=e[t];if(i&&"object"==typeof i)for(n in i)
Object.prototype.hasOwnProperty.call(i,n)&&(a=walk(i,n),a!==undefined?
i[n]=a:delete i[n]);return reviver.call(e,t,i)}var cx=/[\u0000\u00ad\u
0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u202f\u2060-\u206f\u
feff\ufff0-\uffff]/g,j;if(text=String(text),cx.lastIndex=0,cx.test(tex
t)&&(text=text.replace(cx,function(e){return"\\u" ("0000" e.charCodeAt
(0).toString(16)).slice(-4)})),/^[\],:{}\s]*$/.test(text.replace(/\\(?
:["\\\/bfnrt]|u[0-9a-fA-F]{4})/g,"@").replace(/"[^"\\\n\r]*"|true|fals
e|null|-?\d (?:\.\d*)?(?:[eE][ \-]?\d )?/g,"]").replace(/(?:^|:|,)(?:\
s*\[) /g,"")))return j=eval("(" text ")"),"function"==typeof reviv<<< skipped >>>
GET /layouts/graphic_300x250.js?v=4.4.27 HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/displayCore2_russian/typ2-1.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cdn.castplatform.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Tue, 01 Mar 2016 05:41:41 GMT
Content-Type: text/javascript; charset=utf-8
Content-Length: 2972
Connection: keep-alive
Vary: Accept-Encoding
Content-MD5: KiIZm6dlzklWp1p98ApFMQ==
Last-Modified: Mon, 01 Feb 2016 13:17:03 GMT
ETag: 0x8D32B09FA13D1F0
X-Node: cdn1
Server: NetDNA-cache/2.2
X-Cache: HITcb_layout({transformer:{name:["Graphic_300x250"],mainLayout:"graphic_3
00_250_combo",subLayouts:["graphic_300_250_single_inner"]},addZoneType
s:function(e,a){a.graphic_layout={family:"layout_base",style:a.layout_
base.style ".namespace{overflow:hidden;background:#fff;border-top:soli
d 30px #39393a;border-bottom:solid 1px #f6f6f6}.namespace .slots{backg
round-color:#f9f9f9;overflow:hidden}.namespace .ca-sec-title{color:#ff
f;font-weight:400;line-height:30px;margin:0;font-size:12px;position:ab
solute;padding-left:10px;top:0}",template:'<div class="header ca-se
c-title cstm-title">{{adunit_title|default:we_recommend}}</div&g
t;<div class="slots cstm-bg"></div>'},a.graphic_inner=e.ex
tend({},a.inner_base,{style:a.inner_base.style ".namespace{display:blo
ck;overflow:hidden;position:relative;margin:0;border-bottom:solid 1px
#3d3c3d;border-right:solid 1px #3d3c3d;border-left:solid 1px #3d3c3d}.
namespace h1,.namespace h2,.namespace h3,.namespace h4,.namespace h5,.
namespace p{margin:0}.namespace a{right:14px;bottom:12px;color:#2bb22f
;font-size:12px;font-weight:700}.namespace a.download_now_placeholder{
text-decoration:none}.namespace img{position:absolute;border:0}.namesp
ace .ca-title{font-weight:700;color:#4d4d4d;margin:0;height:auto}.name
space .ca-company{color:#768797;font-weight:400;font-size:14px;line-he
ight:24px}.namespace .ca-description{color:#5d5d5d;font-size:14px}.nam
espace .ca-stars-rating{margin-top:12px}.namespace .download_now{posit
ion:absolute;top:auto;right:auto;left:12px;bottom:9px}.namespace i<<< skipped >>>
GET /images/d00f789b-95d8-4133-8eb1-0fd872f98e9b.gif HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/displayCore2_russian/typ2-1.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cdn.castplatform.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Tue, 01 Mar 2016 05:41:41 GMT
Content-Type: image/gif; charset=utf-8
Content-Length: 5997
Connection: keep-alive
Vary: Accept-Encoding
Content-MD5: M7d1PaTMMt6h052RjEVrbw==
Last-Modified: Thu, 24 Dec 2015 14:45:03 GMT
ETag: 0x8D30C70CEB7CAB4
X-Node: cdn1
Server: NetDNA-cache/2.2
X-Cache: HITGIF89ad.d....@........[........]..:v{............J..I..h.....2{....8..
...Y.....C..r.....C..M.....;|.y.....F..............5}....e..H.....B..i
..O.....L.....6~.<..........................L|....b..............u.
.......W........E.....Bx|...>.....Y..T.....c........4|.b...........
...[.....:..?.....s..L..{..[..R..x..=...........V..R..T..t..X..C..W...
..U..Y.....U..i..6}.8..z..P.....Q........n........V.....I.....S.....4p
tI..Q..^..}.....N.....|..=..m...........^........P..N.....7........"RX
;..Z........I..............^.....T.....B..?.....O..R..............U...
...rxV.....7|.,ekT..L..W..>..K..V..9..C..E..Y..W..N..[..[../pv...^.
._..1z.0y.5~.3|.\..[..Z..C.....B....................M..Q.....S..;..=..
N........=..[..$]aD..`..S.....6y._..B..............O..L...........2z.V
..Q..O........Q..W..!..XMP DataXMP<?xpacket begin="..." id="W5M0MpC
ehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk
="Adobe XMP Core 5.6-c111 79.158325, 2015/09/10-01:10:20 ">
<rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#">
; <rdf:Description rdf:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xa
p/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#
" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmpMM:OriginalDocumentID="x
mp.did:54521e55-5d95-f641-bd02-1debd9140b99" xmpMM:DocumentID="xmp.did
:5E315AD2AA4B11E593128CCF1E300019" xmpMM:InstanceID="xmp.iid:5E315AD1A
A4B11E593128CCF1E300019" xmp:CreatorTool="Adobe Photoshop CC 2014 (Win
dows)"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:DB3131D<<< skipped >>>
GET /download/torrentex0.1.4b.exe HTTP/1.0
Connection: keep-alive
Host: download1.torrentex.ru
Accept: text/html,application/xhtml xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: identity
User-Agent: Mozilla/3.0 (compatible; Indy Library)
HTTP/1.1 200 OK
Server: nginx/1.4.2
Date: Tue, 01 Mar 2016 05:41:36 GMT
Content-Type: application/octet-stream
Content-Length: 18698056
Last-Modified: Fri, 13 Nov 2015 04:59:52 GMT
Connection: keep-alive
ETag: "56456e48-11d4f48"
Accept-Ranges: bytesMZP.....................@.............................................
..!..L.!..This program must be run under Win32..$7....................
......................................................................
..............................................PE..L......U............
......................... ....@................................../....
[email protected]..........
......................................................................
...............text...4........................... ..`.itext..D.......
.................... ..`.data........ [email protected]..
...V...0...........................idata..............................
@....tls.....................................rdata....................
..........@[email protected]................ ..............@..@................
....................@..@..............................................
......................................................................
[email protected]............
@...string([email protected]......@...............................@.....
.... 9@.([email protected]@[email protected]@[email protected]@..9@.,[email protected]@[email protected].%..A....%..A.
...%..A....%..A....%..A....%..A....%(.A....%..A....%$.A....%..A....%..
A....%..A....%..A....%..A....%|.A....%x.A....%t.A....%p.A....%l.A....%
h.A....% .A....%d.A....%`.A....%\.A....%..A....%..A....%..A....%X.A...
.%T.A....%..A....%..A....%..A....%P.A....%L.A....%H.A....%D.A....%@.A.
..S..........$D...T.J....D$,.t...\$0....D[..@..%<.A....%8.A....<<< skipped >>>
The Trojan connects to the servers at the folowing location(s):
%?9-*09,*19}*09
.text
`.data
.rsrc
msvcrt.dll
KERNEL32.dll
NTDLL.DLL
USER32.dll
SHLWAPI.dll
SHDOCVW.dll
Software\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess
IE-X-X
rsabase.dll
System\CurrentControlSet\Control\Windows
dw15 -x -s %u
watson.microsoft.com
IEWatsonURL
%s -h %u
iedw.exe
Iexplore.XPExceptionFilter
jscript.DLL
mshtml.dll
mlang.dll
urlmon.dll
wininet.dll
shdocvw.DLL
browseui.DLL
comctl32.DLL
IEXPLORE.EXE
iexplore.pdb
ADVAPI32.dll
MsgWaitForMultipleObjects
IExplorer.EXE
IIIIIB(II<.Fg
7?_____ZZSSH%
)z.UUUUUUUU
,....Qym
````2```
{.QLQIIIKGKGKGKGKGKG;33;33;0
8888880
8887080
browseui.dll
shdocvw.dll
6.00.2900.5512 (xpsp.080413-2105)
Windows
Operating System
6.00.2900.5512
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
%original file name%.exe:188
- Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\desktop.ini (159 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\2CE9S84I\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\NTER05EZ\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4LMR4XMF\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\68E7ZN4T\desktop.ini (67 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.