Trojan.Win32.IEDummy_82f6f81110
not-a-virus:HEUR:AdWare.Win32.InstallMonster.gen (Kaspersky), Trojan.Win32.IEDummy.FD, mzpefinder_pcap_file.YR (Lavasoft MAS)
Behaviour: Trojan, Adware
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: 82f6f811108bdf6e3beeb15e6ecf7055
SHA1: 3fca19c2f88d14e0fda48eab1d7763472037d647
SHA256: 1e11901380d2d3637334c185dad437a8d31e466b7f86ef34801e6eb74a3888e6
SSDeep: 98304:SK W1If2ujC tjEG8n2tBTEYrbg8bQbTBcaSGdlQ4wx9bdybFwj9Qv:S1Wstlo2rEYrU3SaFQ4q9Z2FQ9q
Size: 5256264 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 1992-06-20 01:22:17
Analyzed on: WindowsXP SP3 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
%original file name%.exe:580
The Trojan injects its code into the following process(es):
No processes have been created.
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process %original file name%.exe:580 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
Registry activity
The process %original file name%.exe:580 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKCR\82f6f811108bdf6e3beeb15e6ecf7055.DynamicNS\Clsid]
"(Default)" = "{C379EAD1-CB34-4B09-AF6B-7E587F8BCD80}"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKCR\CLSID\{C379EAD1-CB34-4B09-AF6B-7E587F8BCD80}\ProgID]
"(Default)" = "82f6f811108bdf6e3beeb15e6ecf7055.DynamicNS"
[HKCR\CLSID\{C379EAD1-CB34-4B09-AF6B-7E587F8BCD80}]
"(Default)" = "DynamicNS"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"TypesSupported" = "7"
"CategoryCount" = "16"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"Guid" = "8aefce96-4618-42ff-a057-3536aa78233e"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"Active" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"ControlFlags" = "1"
"LogSessionName" = "stdout"
[HKCR\CLSID\{C379EAD1-CB34-4B09-AF6B-7E587F8BCD80}\LocalServer32]
"(Default)" = "c:\%original file name%.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"LogSessionName" = "stdout"
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\ESENT\Process\82f6f811108bdf6e3beeb15e6ecf7055\DEBUG]
"Trace Level" = ""
[HKCR\82f6f811108bdf6e3beeb15e6ecf7055.DynamicNS]
"(Default)" = "DynamicNS"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "3F 88 0E 2E 5B 76 F7 AB E3 38 B8 E1 56 59 27 6B"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"CategoryMessageFile" = "%System%\ESENT.dll"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"LogSessionName" = "stdout"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"EventMessageFile" = "%System%\ESENT.dll"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"ControlFlags" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\ESENT\Process\82f6f811108bdf6e3beeb15e6ecf7055\DEBUG]
"Trace Level"
Dropped PE files
There are no dropped PE files.
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name:
Product Name:
Product Version: 1.0.0.0
Legal Copyright:
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 1.0.0.0
File Description:
Comments:
Language: English (United States)
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| UPX0 | 4096 | 3112960 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| UPX1 | 3117056 | 1605632 | 1604096 | 5.46546 | e445d93d44de9062e7a511b05a1791e6 |
| .rsrc | 4722688 | 20480 | 18944 | 3.78601 | 87ecc6b79f84b4057e7b83a19a58f53e |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
| URL | IP |
|---|---|
| hxxp://fplr.biz/FFPsetup.exe | |
| hxxp://download.torrentex.ru/download.php | |
| hxxp://download1.torrentex.ru/download/torrentex0.1.4b.exe | |
| hxxp://tundra.site/pages/inmon/im-typ.html | |
| hxxp://tundra.site/pages/inmon/css/style.css | |
| hxxp://tundra.site/pages/inmon/images/icon2-green.png | |
| hxxp://tundra.site/pages/inmon/images/icon1-green.png | |
| hxxp://tundra.site/pages/inmon/images/icon3-green.png | |
| hxxp://cast-prod-dlv-pull.ironsrc.netdna-cdn.com/scripts/1/adnl.min.js | |
| hxxp://neu-dl-api.cloudapp.net/api/vv/1?callback=cb_1459914005975&ts=1459914005975&sessionId=ZTRJM&rfr=&siteId=9306&aus=5584,1,0 | |
| hxxp://cast-prod-dlv-pull.ironsrc.netdna-cdn.com/images/1eaeba30-fae9-4091-b89c-7f1ccf25c528.jpg | |
| hxxp://neu-dl-api.cloudapp.net/api/vp/1?clk=3aakKSwtxgnEr93D6JkBy54BzgTPvZmR2XHGtB_ljZs6rOiPhV5UlwvXQuA55bJlUtvLGcUsiWZXtDhiLnHHIckDhPa-5YSmSyhkVeoOOJbtzCXLx4daxwStZ1egCHSMavFBiwEx5TBz5fh7nh3wBBrOV5DMKf9FuY3bb3gU-Ag2WjepsFdajeHmVFhT6OUvEyZ-31j3oSTX8Fk71EOKox6TVD5wp29hucRX8JqN6QrYjKpIlp-rktjtYKKg7RI5POadtFph4CgYUfDR9FLNSB8wOZEfnNkEUYPRsHDx-3l-goNt1O8yOwaOLfzMPG6zVBAD6Csa0w3KrMNTncii5Ln2Ge6zq1FBIoUWCRdiCpZBnMebeiQulqZEu07vC5sKOobRd8YTJDdlYYboMxP0vG1DG9sSu7-TdmG6qMYYu_HGWiBCpOzz346YEynwNSPY4IrvubyuRBdLUuXeqPgK7w&rfr= | |
| hxxp://d.castplatform.com/api/vp/1?clk=3aakKSwtxgnEr93D6JkBy54BzgTPvZmR2XHGtB_ljZs6rOiPhV5UlwvXQuA55bJlUtvLGcUsiWZXtDhiLnHHIckDhPa-5YSmSyhkVeoOOJbtzCXLx4daxwStZ1egCHSMavFBiwEx5TBz5fh7nh3wBBrOV5DMKf9FuY3bb3gU-Ag2WjepsFdajeHmVFhT6OUvEyZ-31j3oSTX8Fk71EOKox6TVD5wp29hucRX8JqN6QrYjKpIlp-rktjtYKKg7RI5POadtFph4CgYUfDR9FLNSB8wOZEfnNkEUYPRsHDx-3l-goNt1O8yOwaOLfzMPG6zVBAD6Csa0w3KrMNTncii5Ln2Ge6zq1FBIoUWCRdiCpZBnMebeiQulqZEu07vC5sKOobRd8YTJDdlYYboMxP0vG1DG9sSu7-TdmG6qMYYu_HGWiBCpOzz346YEynwNSPY4IrvubyuRBdLUuXeqPgK7w&rfr= | |
| hxxp://cdn.castplatform.com/scripts/1/adnl.min.js | |
| hxxp://d.castplatform.com/api/vv/1?callback=cb_1459914005975&ts=1459914005975&sessionId=ZTRJM&rfr=&siteId=9306&aus=5584,1,0 | |
| hxxp://cdn.castplatform.com/images/1eaeba30-fae9-4091-b89c-7f1ccf25c528.jpg |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /FFPsetup.exe HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: fplr.biz
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.2.4
Date: Wed, 06 Apr 2016 03:39:58 GMT
Content-Type: application/octet-stream
Content-Length: 3378400
Last-Modified: Tue, 15 Dec 2015 16:17:36 GMT
Connection: keep-alive
Accept-Ranges: bytesMZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.......8...|O..|O..
|O..u7..nO..|O...O...8 .{O..u7..ZO..u7..$O..b...}O..u7..}O..Rich|O....
..............PE..L....v.U.....................<.......m...........
.@[email protected]................................
.....d...P.... ..|............n3......................................
[email protected]..........
..................... ..`.data............ [email protected]
...|.... ......................@..@...................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
...............................................`...p...|..............
......................... ...,[email protected]...^...n...~....................
.......................0...<...N...............v...d...R...B.......
........................0...L...j...~.................................
..........2...J...X...f...~...................................,...F...
`...r...................................................t.......Z...L.
..6... .......................................r.......................
[email protected]@...@[email protected] log-file with an err<<< skipped >>>
GET /scripts/1/adnl.min.js HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/inmon/im-typ.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cdn.castplatform.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 06 Apr 2016 03:40:02 GMT
Content-Type: text/javascript; charset=utf-8
Content-Length: 59620
Connection: keep-alive
Vary: Accept-Encoding
Content-MD5: EWemSQBepDOLqdXHMBDo7g==
Last-Modified: Wed, 30 Mar 2016 12:54:04 GMT
ETag: 0x8D3589A5F8E2CCD
X-Node: cdn1
Server: NetDNA-cache/2.2
X-Cache: HIT// CAST Delivery Agent v4.4.28 #12:54.!function(global,undefined){Arra
y.prototype.indexOf||(Array.prototype.indexOf=function(e,t){if(this===
undefined||null===this)throw new TypeError('"this" is null or not defi
ned');var n=this.length>>>0;for(t= t||0,1/0===Math.abs(t)&&(t
=0),0>t&&(t =n,0>t&&(t=0));n>t;t )if(this[t]===e)return t;re
turn-1}),"object"!=typeof window.JSON&&(window.JSON={},window.JSON.str
ingify=function(e){if("[object Array]"===Object.prototype.toString.cal
l(e)){if(e.length>0){for(var t=e.length,n=[],a=0;t>a; a)n.push(
this.stringify(e[a]));return"[" n.join(", ") "]"}return"[]"}if("object
"==typeof e&&null!==e){var n=[];for(a in e)n.push('"' a '": ' this.str
ingify(e[a]));return"{" n.join(", ") "}"}return"string"==typeof e?'"'
e.replace(/"/g,'\\"') '"':e},window.JSON.parse=function(text,reviver){
function walk(e,t){var n,a,i=e[t];if(i&&"object"==typeof i)for(n in i)
Object.prototype.hasOwnProperty.call(i,n)&&(a=walk(i,n),a!==undefined?
i[n]=a:delete i[n]);return reviver.call(e,t,i)}var cx=/[\u0000\u00ad\u
0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u202f\u2060-\u206f\u
feff\ufff0-\uffff]/g,j;if(text=String(text),cx.lastIndex=0,cx.test(tex
t)&&(text=text.replace(cx,function(e){return"\\u" ("0000" e.charCodeAt
(0).toString(16)).slice(-4)})),/^[\],:{}\s]*$/.test(text.replace(/\\(?
:["\\\/bfnrt]|u[0-9a-fA-F]{4})/g,"@").replace(/"[^"\\\n\r]*"|true|fals
e|null|-?\d (?:\.\d*)?(?:[eE][ \-]?\d )?/g,"]").replace(/(?:^|:|,)(?:\
s*\[) /g,"")))return j=eval("(" text ")"),"function"==typeof reviv<<< skipped >>>
GET /images/1eaeba30-fae9-4091-b89c-7f1ccf25c528.jpg HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/inmon/im-typ.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cdn.castplatform.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 06 Apr 2016 03:40:02 GMT
Content-Type: image/jpeg; charset=utf-8
Content-Length: 99940
Connection: keep-alive
Vary: Accept-Encoding
Content-MD5: 84yOv9Fknx6WvATYJ8//sw==
Last-Modified: Sun, 13 Mar 2016 09:05:27 GMT
ETag: 0x8D34B1E9EAC9EFB
X-Node: cdn1
Server: NetDNA-cache/2.2
X-Cache: HIT......Exif..II*.................Ducky.......8......hXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c11
1 79.158325, 2015/09/10-01:10:20 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="
hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.a
dobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:9d3aa1bc-879e-f34
1-bb50-ccda3be4d297" xmpMM:DocumentID="xmp.did:C9F120E4E8F211E5B83DE63
5D0776361" xmpMM:InstanceID="xmp.iid:C9F120E3E8F211E5B83DE635D0776361"
xmp:CreatorTool="Adobe Photoshop CC 2015 (Windows)"> <xmpMM:Der
ivedFrom stRef:instanceID="xmp.iid:963c8fb8-b4bf-3f44-ba12-95c7f2efc8d
3" stRef:documentID="xmp.did:9d3aa1bc-879e-f341-bb50-ccda3be4d297"/>
; </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xp
acket end="r"?>....Adobe.d.........................................
.......................""""""""""................"""""""""""""""""""""
""""""""""""""""""""""""""""........ .................................
.......................................................!.1...AQ.aq"...
2B.....R#...b.r...3S..U...Cs$u6...c.4DTt%7....d..EeVv'8...5&..........
...........!1..AQ..aq......."2....BRb.r.#..3.....CS............?..V.&.
....u.{f..,6.T.....)*4..#....:.S..g....v.b.u.......u.&. eR....T .1}-..
..r.....Upe7,ztr....1.H....]..D..A..G....W...........Nd.DN\.L=...M<<< skipped >>>
GET /pages/inmon/images/icon1-green.png HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/inmon/im-typ.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: tundra.site
Connection: Keep-Alive
Cookie: X-Mapping-fjhppofk=3E8E1A8CCA3BD46AD95C5D4A4E8F490A
HTTP/1.1 200 OK
Server: nginx/1.8.0
Date: Wed, 06 Apr 2016 03:32:30 GMT
Content-Type: image/png
Content-Length: 3392
Last-Modified: Wed, 12 Aug 2015 13:59:00 GMT
Connection: keep-alive
ETag: "55cb5124-d40"
Accept-Ranges: bytes.PNG........IHDR...>...E......$UF....tEXtSoftware.Adobe ImageReadyq
.e<....IDATx..[{l[W.?..g..fvR.]..2.4.z.N..?jOC......C....IS[....%Y.
...........i][email protected].@.?Hs%.:&.....&..c.............#YIS...;.w.....cB.O.
.....GE.l.3.n7.2Rv..FQ..JF. ...Lt.....?..m.cN...'yK...k..Y..l.........
.j...qO:.?.......n...8K........K7<9X.db.$.....b.............=-.....
...<uhB..2......-/VI.Hzy.$."..?y...<.....-.iF..x.. ...N..ke....)
......!._.mJc..p,a.Z.Gd.x.(...p.......j....~3.. .I..a....~4...S...NN0f
.W..2.I.....t....i`..1d.6....E...^.oKGb$qm.}..;.f...g...h%x..t.K ..'..
.....(X...W.:...]#.p......>.._;.>j..{..V.(k.W...O\....oj..^.....
K.lq>.<.......eJ........?..Yp.`.Ic........F............OV.../...
n.....u.3...F..`... .....oj..b.......7"..;]i.B.. ...K.A{..W.^.g....9..
?}..p....R.M....i..N.D....;......QK..,".....9.....ub>...P.....g:9/.
..:?.y?..a8...L....L.b.s............W...O|.S...w*...3=..J.,...:...3ok.
.mz....W....E.S.F.N...99K.v.S.P.......].!ey:]#C..!.8 .W...D;dq.......&
gt;;...|Y.,3D.Gq.Mg.D..i.|..X.......[[email protected].*cYmj.=.3..2........W.
..vw...fy9^.....z......pEQ. ...Q....T....#.[/..t.0z.h!..>t.....%".B
l.{.<.{.JW.....?.3h.{w...(...DF..p...dV.}X....PJ...n.A.....o. p.(..
........H..3....H...N....F)p8....$.......Y....z:Tn.....W.q....6..D..G.
Ud.f.....C.X....D......N..{..T.j......../."..=...g..)..<(hwX.rf...0
...Z=J..=....1B..n.$U\.P.re.ku.u&8.nC.........W........so..../.O5...G.
....OB#%...x...~..`.;.....^.m."...........q..S]..T.....Fj)>...|.jZ.
..['.....:.s.x..O.m.....[....\$0..{..&.r...^.U...?.o..Y.......ZW].<<< skipped >>>
GET /api/vv/1?callback=cb_1459914005975&ts=1459914005975&sessionId=ZTRJM&rfr=&siteId=9306&aus=5584,1,0 HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/inmon/im-typ.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: d.castplatform.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Length: 1055
Content-Type: text/javascript; charset=utf-8
Server: Microsoft-HTTPAPI/2.0
X-Country: UA
P3P: CP='NON UNI COM NAV STA OUR IND'
Set-Cookie: cuuid=fabe1eac-1742-4c64-ae76-05e489014c1e; expires=Mon, 06 Apr 2026 03:40:02 GMT; domain=d.castplatform.com; path=/
X-Elapsed: 178
X-Node: NEU3940D1
Date: Wed, 06 Apr 2016 03:40:02 GMTcb_1459914005975 && cb_1459914005975({"zones":[{"id":5584,"status":200
,"enabled":true,"template":"Free_Creative_800x440","data":[{"clickTag"
:null,"clk":"3aakKSwtxgnEr93D6JkBy54BzgTPvZmR2XHGtB_ljZs6rOiPhV5UlwvXQ
uA55bJlUtvLGcUsiWZXtDhiLnHHIckDhPa-5YSmSyhkVeoOOJbtzCXLx4daxwStZ1egCHS
MavFBiwEx5TBz5fh7nh3wBBrOV5DMKf9FuY3bb3gU-Ag2WjepsFdajeHmVFhT6OUvEyZ-3
1j3oSTX8Fk71EOKox6TVD5wp29hucRX8JqN6QrYjKpIlp-rktjtYKKg7RI5POadtFph4Cg
YUfDR9FLNSB8wOZEfnNkEUYPRsHDx-3l-goNt1O8yOwaOLfzMPG6zVBAD6Csa0w3KrMNTn
cii5Ln2Ge6zq1FBIoUWCRdiCpZBnMebeiQulqZEu07vC5sKOobRd8YTJDdlYYboMxP0vG1
DG9sSu7-TdmG6qMYYu_HGWiBCpOzz346YEynwNSPY4IrvubyuRBdLUuXeqPgK7w","widt
h":800,"height":440,"cUrl":"hXXp://d.castplatform.com/api/c/1?clk=%clk
%","trackers":[{"type":"Url","content":"hXXp://d.castplatform.com/api/
vp/1?clk=%clk%"}],"category":null,"assets":[{"assetDisplayType":1,"wid
th":800,"height":440,"url":"//cdn.castplatform.com/images/1eaeba30-fae
9-4091-b89c-7f1ccf25c528.jpg","javascript":"","clickTagVar":""}]}],"st
yles":null,"settings":{"adUnitTitle":""},"displayType":"Size"}],"ts":1
78});....
GET /api/vp/1?clk=3aakKSwtxgnEr93D6JkBy54BzgTPvZmR2XHGtB_ljZs6rOiPhV5UlwvXQuA55bJlUtvLGcUsiWZXtDhiLnHHIckDhPa-5YSmSyhkVeoOOJbtzCXLx4daxwStZ1egCHSMavFBiwEx5TBz5fh7nh3wBBrOV5DMKf9FuY3bb3gU-Ag2WjepsFdajeHmVFhT6OUvEyZ-31j3oSTX8Fk71EOKox6TVD5wp29hucRX8JqN6QrYjKpIlp-rktjtYKKg7RI5POadtFph4CgYUfDR9FLNSB8wOZEfnNkEUYPRsHDx-3l-goNt1O8yOwaOLfzMPG6zVBAD6Csa0w3KrMNTncii5Ln2Ge6zq1FBIoUWCRdiCpZBnMebeiQulqZEu07vC5sKOobRd8YTJDdlYYboMxP0vG1DG9sSu7-TdmG6qMYYu_HGWiBCpOzz346YEynwNSPY4IrvubyuRBdLUuXeqPgK7w&rfr= HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/inmon/im-typ.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: d.castplatform.com
Connection: Keep-Alive
Cookie: cuuid=fabe1eac-1742-4c64-ae76-05e489014c1e
HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Length: 43
Content-Type: image/gif
Server: Microsoft-HTTPAPI/2.0
Set-Cookie: cuuid=47b51822-d569-49bb-b2cb-0f54c7c8bb3f; expires=Mon, 06 Apr 2026 03:40:03 GMT; domain=d.castplatform.com; path=/
P3P: CP='NON UNI COM NAV STA OUR IND'
X-Elapsed: 0
Date: Wed, 06 Apr 2016 03:40:02 GMTGIF89a.............!.......,...........L..;HTTP/1.1 200 OK..Cache-Cont
rol: no-cache..Content-Length: 43..Content-Type: image/gif..Server: Mi
crosoft-HTTPAPI/2.0..Set-Cookie: cuuid=47b51822-d569-49bb-b2cb-0f54c7c
8bb3f; expires=Mon, 06 Apr 2026 03:40:03 GMT; domain=d.castplatform.co
m; path=/..P3P: CP='NON UNI COM NAV STA OUR IND'..X-Elapsed: 0..Date:
Wed, 06 Apr 2016 03:40:02 GMT..GIF89a.............!.......,...........
L..;..
GET /download.php HTTP/1.0
Connection: keep-alive
Host: download.torrentex.ru
Accept: text/html,application/xhtml xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: identity
User-Agent: Mozilla/3.0 (compatible; Indy Library)
HTTP/1.1 302 Found
Server: nginx/1.4.6 (Ubuntu)
Date: Wed, 06 Apr 2016 03:27:59 GMT
Content-Type: text/html
Content-Length: 0
Connection: keep-alive
Location: hXXp://download1.torrentex.ru/download/torrentex0.1.4b.exe
GET /download/torrentex0.1.4b.exe HTTP/1.0
Connection: keep-alive
Host: download1.torrentex.ru
Accept: text/html,application/xhtml xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: identity
User-Agent: Mozilla/3.0 (compatible; Indy Library)
HTTP/1.1 200 OK
Server: nginx/1.4.2
Date: Wed, 06 Apr 2016 03:39:58 GMT
Content-Type: application/octet-stream
Content-Length: 18698056
Last-Modified: Fri, 13 Nov 2015 04:59:52 GMT
Connection: keep-alive
ETag: "56456e48-11d4f48"
Accept-Ranges: bytesMZP.....................@.............................................
..!..L.!..This program must be run under Win32..$7....................
......................................................................
..............................................PE..L......U............
......................... ....@................................../....
[email protected]..........
......................................................................
...............text...4........................... ..`.itext..D.......
.................... ..`.data........ [email protected]..
...V...0...........................idata..............................
@....tls.....................................rdata....................
..........@[email protected]................ ..............@..@................
....................@..@..............................................
......................................................................
[email protected]............
@...string([email protected]......@...............................@.....
.... 9@.([email protected]@[email protected]@[email protected]@..9@.,[email protected]@[email protected].%..A....%..A.
...%..A....%..A....%..A....%..A....%(.A....%..A....%$.A....%..A....%..
A....%..A....%..A....%..A....%|.A....%x.A....%t.A....%p.A....%l.A....%
h.A....% .A....%d.A....%`.A....%\.A....%..A....%..A....%..A....%X.A...
.%T.A....%..A....%..A....%..A....%P.A....%L.A....%H.A....%D.A....%@.A.
..S..........$D...T.J....D$,.t...\$0....D[..@..%<.A....%8.A....<<< skipped >>>
GET /pages/inmon/im-typ.html HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: tundra.site
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.8.0
Vary: Accept-Encoding
Content-Type: text/html
Content-Encoding: gzip
Date: Wed, 06 Apr 2016 03:32:29 GMT
Transfer-Encoding: chunked
ETag: W/"5628d116-7b9"
Connection: keep-alive
Set-Cookie: X-Mapping-fjhppofk=3E8E1A8CCA3BD46AD95C5D4A4E8F490A; path=/
Last-Modified: Thu, 22 Oct 2015 12:05:42 GMT364.............U.n.0......f..& .4 .4.]L..........18N.;....]..^.!.....
_y...8N.... ..:.s..../.....5l.`....?; .#... .1......a......nL#ICn 7..p
....O..(....>...x.O]R...D9....p1#Nmz3I%#....{.v....Gl .....pL.c.9`D
..@M?&].p..2...bk. ..S.Z..#.a!.#..X,.....U.F......mAx>. .2.t.`z....
M.r....F.P...:Vo...Oj.....#..SC....l..MW,3.hVv..)Q/.....FN....q.y.r...
..k...7kv.P..WX.4..E..LyYc..>......C._.......Y...d...WPz...z....R?.
.q.,}..|.R}..G5.e....K5.6.)$.D.......`...D.:... ..B [email protected].%".'e
.......T..i[..P........z..C..8..:..Y.f.p.;........'.f%#:.{.1t3.{1...`^
.W........[.T...0?0c..~...7.:>s.t.H...k...6.v.wd...T.#...$..u..q..6
.8F...m......ziF.. {...f...\. .h7.[.;7Z....z..]'..._....huvom..e..7],d
....q`.a.7.t..........*...........`]...gqf.......... ....EB.oy...z...3
..`I6.....,...A........j.Ha.,...Pn......I'.~..P.FkQK\...^.^.....K.{..&
."...O.W....r...D'@.vQ.......g.f.~.....i.......0......
GET /pages/inmon/css/style.css HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/inmon/im-typ.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: tundra.site
Connection: Keep-Alive
Cookie: X-Mapping-fjhppofk=3E8E1A8CCA3BD46AD95C5D4A4E8F490A
HTTP/1.1 200 OK
Server: nginx/1.8.0
Date: Wed, 06 Apr 2016 03:32:29 GMT
Content-Type: text/css
Last-Modified: Thu, 22 Oct 2015 12:08:45 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
ETag: W/"5628d1cd-70e"
Content-Encoding: gzip28e.............U.n.@.}N.b...KA\.lB.....7.00...ah.F.....pYR-U.b..c...E
z.,.%.9."..-.5MSV..%..r2Z2~......XB_.O.(.%.........uY..(.../.H..O7..X^
..TB...U.I9.......H4&.....0.5..`(e..a.B[%...RUDd..L....C.y..Q...z]...h
......5.s...........:..L>..E.=HS...R...b c....C.j...^..%.J.R'..SL`.
[email protected][... x_....1oa...6.~7...4.y..7..3.l.9.....#.
.b!....O..... .v ...e........k..........fB(3S............wX.......y...
,p......I.n..^..tJ.......B..2!aT...B.t=v!.nv[..4L...t ..w..z.q;#...o}N
;U}...|.....C3X....v.../c=.............cl...#..5..^..0.}an.h. .S7.7.~K
Z.6......Y.d.......Y.`.L8...............y...O.l FY. ..#5..A.k.Wm......
..h2.'.....$...Qg...P....9........0......
GET /pages/inmon/images/icon2-green.png HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/inmon/im-typ.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: tundra.site
Connection: Keep-Alive
Cookie: X-Mapping-fjhppofk=3E8E1A8CCA3BD46AD95C5D4A4E8F490A
HTTP/1.1 200 OK
Server: nginx/1.8.0
Date: Wed, 06 Apr 2016 03:32:30 GMT
Content-Type: image/png
Content-Length: 3782
Last-Modified: Wed, 12 Aug 2015 13:59:00 GMT
Connection: keep-alive
ETag: "55cb5124-ec6"
Accept-Ranges: bytes.PNG........IHDR...>...E......$UF....tEXtSoftware.Adobe ImageReadyq
.e<...hIDATx..[kl#[email protected]. .}..}P@@.
[email protected]@.".Zg7.$..$q..f..\...c;....(W;.].x.~......;....?.
.....c.|X........B...;D...rv&.M..eE...eZ..1Ts5....E?..{O.x....B.. ..=B
...D...~.,,..p.493...XB.R...2&......1...., .5.....b[.B`ae...oF...p.FZ.
,."..zh......p...yH.l>!4:. .[aXi.3.... |.. ..t.....J...../4...(T.me
L..'9ceC.]R//...FkW.Z...vpb6d..?......=.x..M.RO....P..p[c-..K.p.,v....
....K.|.=......:!..2............<`....j....Mq...C<{*L2j.^05g.q=}
qy`..sy ]3.UK.j.....o.Z.......2&u5{.fw.}6.Oe8cuCO._..<.Jd.9.;......
.[4.2.i....y.K.Z.......q..J.A^..g......1..|.lN.)8............f.q]...4.
...........I..c...=.2..[..2LZ.1rIf....3.....M...2.M.f..R siU..i..0....
.9_.?.'...S.R#.sN.{.s.........@7...%..{........w>....A.V...{?..V9.*
G.....,.......lA.:7.........E.q.C..._W.Dd.k;&D..4..E}3.}..X.c.)`.!.$..
.R.........X.<....^.PH..NO.)...^KM-.......:.8...Q..S7.`. ...V...D.@
.'.<..x!..1.PU.ktr<[email protected]..'d..n.'|v*...R..=.uau0..u
C...S.......G....F............f...h.XN.h..-(..../....l.f..fI..`G.|....
.\...bf..Q*...p....Y..R......w........\[email protected].#.l!
)l(,V....6m.<...E..../.y....P.......y.........O.f....-.....Y....B.(
.s..r....z<jf....m...[Hc...%5.....$..x.Z...u2.....h.........94{....
.9...\.wE.?....!E.\l..S...).....A...2FV.y..Z..d.HEPsy....!.*X.......?s
|.qM..y..U.s.......m....Zi.T......C....m.nB.......4.....Q.........) ..
.Ph..'.~|..nZ'.Fpk..:....3...)_|.~....H..gnM.J?k....$y......-.....<<< skipped >>>
GET /pages/inmon/images/icon3-green.png HTTP/1.1
Accept: */*
Referer: hXXp://tundra.site/pages/inmon/im-typ.html
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: tundra.site
Connection: Keep-Alive
Cookie: X-Mapping-fjhppofk=3E8E1A8CCA3BD46AD95C5D4A4E8F490A
HTTP/1.1 200 OK
Server: nginx/1.8.0
Date: Wed, 06 Apr 2016 03:32:30 GMT
Content-Type: image/png
Content-Length: 1519
Last-Modified: Wed, 12 Aug 2015 13:59:00 GMT
Connection: keep-alive
ETag: "55cb5124-5ef"
Accept-Ranges: bytes.PNG........IHDR...>...E......$UF....tEXtSoftware.Adobe ImageReadyq
.e<....IDATx..[.O[u.........(.E....o..............U0...Q`.%...}0..$
..d....%&=<.H.|q.sNZ..R..=7.._/P...Z.....rN.....;..0`.......0`.....
S<q..x.6...8. .....4=A].....Y...L<y~&\".I.G..X.Y,......L\{......
./[email protected]:8.....!...............j..W.h..UvZ...bC.
B....1..j\YZ..9...9....r0..8......V...\..[.HO.y..`.{w..SQ.[.m..L.V.nli
.....L..`..n&...\[email protected].~.f......:.......x.i.g.......s
...>4...J...z .^r.z..3....RO<y.wI.).Z..v......^p.u.y"H....W*6Q..
tX."?..w...'...%. .......f.|o....3.s......:.Zz].2.............|.v..U..
..c..z.b....i........>....q.S .....'k3...6.......>D.qY.E........
....................1e1=.Ff)..o..|_..O...z...P6. ... ....?O.S...=.DtU.
.c.-C....SG.%.Y....*.......#.=y.K.quyM.......g.(....\9y.Y..s\v....!...
....>@..d............I..d{.m...!..zFR..........._#rr9.g....ut~....!
..;....-....*w...Hx.E.C]........}.....c.n"..>.".._.ZQ.C.."....q.j".
..... ......._I....S.g.....f...o3..Q...jpf......s.)...1B].SO..3..$N..]
.g(.z......D.......T...C/......u.a}....`. ":m.-m..W.....4..JJ.}...%.U.
T....-.N.....m."..?YE...q=....|P.....X.H,.......|..J.F.#M.......w.t...
Xrr&..e=;.a......R.e.RN...2....n-....g..8d../;....b......p..).&.0Xm.._
.Gs.T..V.y.mo..3....h...F.-.^HH......k....2i...v..&.......j..s,...~ok.
.....=......n.`.x..1.-.I...G..V...F...,U.K...Hb".;p...A/...s.V/.._....
7q.S.|....&.~81v-..../...!.G.Q.m............\./*.$h...>..*[email protected]~
h1yH..W.E...Wp].a.'{....8r.A,...r.....).hY...?.KE.u.........._...d<<< skipped >>>
The Trojan connects to the servers at the folowing location(s):
%?9-*09,*19}*09
.text
`.data
.rsrc
msvcrt.dll
KERNEL32.dll
NTDLL.DLL
USER32.dll
SHLWAPI.dll
SHDOCVW.dll
Software\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess
IE-X-X
rsabase.dll
System\CurrentControlSet\Control\Windows
dw15 -x -s %u
watson.microsoft.com
IEWatsonURL
%s -h %u
iedw.exe
Iexplore.XPExceptionFilter
jscript.DLL
mshtml.dll
mlang.dll
urlmon.dll
wininet.dll
shdocvw.DLL
browseui.DLL
comctl32.DLL
IEXPLORE.EXE
iexplore.pdb
ADVAPI32.dll
MsgWaitForMultipleObjects
IExplorer.EXE
IIIIIB(II<.Fg
7?_____ZZSSH%
)z.UUUUUUUU
,....Qym
````2```
{.QLQIIIKGKGKGKGKGKG;33;33;0
8888880
8887080
browseui.dll
shdocvw.dll
6.00.2900.5512 (xpsp.080413-2105)
Windows
Operating System
6.00.2900.5512
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
%original file name%.exe:580
- Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
- Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.