Enter the MD5, SHA1 or SHA256 hash to search for:        

Summary

Sections


MD5:f42d530ca7d29dca8f5affb7af0cb4c8
SHA1:b99225f35649e9f9fd46fdffedcdb4955aeea7c4
SHA256:6bdd6175a40281e844b28a27e7644fb7081063dc490e707167b5f00067ba88e6
Date Submitted:2/26/2012 9:57:21 PM
Malicious:True
Executable:True
Minotaur Sample ID
128839

FileType Statistics

FileType:
 68.0% (.EXE) Win32 Executable Generic (8527/13/3)
 15.9% (.EXE) Generic Win/DOS Executable (2002/3)
 15.9% (.EXE) DOS Executable Generic (2000/1)
  0.0% (.CEL) Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3)


Identity Statistics

Vendors Declaring Malicious:
TotalVendors:
VirusTotal Report:
http://www.virustotal.com/file/6bdd6175a40281e844b28a27e7644fb7081063dc490e707167b5f00067ba88e6/analysis/

Malware Family Detections:Dropped:Worm.Generic.365388
Suspect.Trojan.Generic.FD-4
TrojWare.Win32.Downloader.Fraudload.AB
W32/FakeAlert.FY.gen!Eldorado
Trojan:Win32/Fifesock.gen!A
W32/Obfuscated.A2!genr
Suspicious file
Riskware
Trojan.Win32.Generic.pak!cobra

Static Analysis Data

CRC Data
ClaimedActual
75037765679


Claimed Compile Date:
Thu Feb 23 03:36:26 2012 UTC

CountLanguage Reference Counts
3LANG_ENGLISH SUBLANG_ENGLISH_US
2LANG_RUSSIAN SUBLANG_RUSSIAN

Screenshots


Click here to start video playback

Origin Statistics

URL IDDate AddedURLIPSource
1311042/26/2012 9:57:21 PMhttp://photo-album-mcshs.osa.pl/album.exe91.217.153.155Clean-MX

Primary Domain Information

Level 3 (control)91.217.153.155Control
Google91.217.153.155ALLOWED
OpenDNS91.217.153.155ALLOWED
Norton91.217.153.155ALLOWED
Comodo91.217.153.155ALLOWED

Network Traffic Analysis



HTTP Request Data

HostPortHTTP URIMethod
62.143.199.2480/LfpGLZFyF3AOwgCVtsF.htmGET
46.249.143.380/86PCa8uA.htmGET
46.249.143.380/MJLfWpHFyDKBsqE.htmGET
46.49.52.2980/6Suc.htmGET
62.221.134.3980/H/2UKGb.htmGET
62.231.125.3480/fPcyADRYQnxsDdw0p.htmGET
67.172.102.5980/hmSZVjkx15M.htmGET
69.142.117.1680/6Ynqm9wIB.htmGET
69.142.117.1680/gbSy5rqKhQqodklZ.htmGET
77.120.133.5580/SShG.htmGET
77.91.4.1880/rehC12OFBWGWL35.htmGET
78.142.39.3080/ISJF9AuF.htmGET
78.88.37.3080/P6V4Efa.htmGET
78.92.186.480/cSgT.htmGET
78.92.186.480/QbZ1NULy4X7sG.htmGET
wyylsic.eu80/jucheck.exeGET
stn0001.com80/1/setup.php?act=grabber&id=uOr4IHTwxtisdYE4akxpOO3e&log=STARTEDGET
stn0001.com80/1/setup.php?act=grabber&id=uOr4IHTwxtisdYE4akxpOO3e&log=OTHER_5_1_SP_3_0_GET
stn0001.com80/1/setup.php?act=grabber&id=uOr4IHTwxtisdYE4akxpOO3e&log=ANTIEMULGET
stn0001.com80/1/setup.php?act=grabber&id=uOr4IHTwxtisdYE4akxpOO3e&log=20GET
ryflyed.eu80/rnn0001.exeGET
95.77.237.580/9pJ5VbuUOpbq71I.htmGET
95.77.237.580/AjEt2kCCV/1m88taLY.htmGET
99.40.31.5880/RjboocrgCubEgIzmKd.htmGET
92.47.86.4580/aAgm.htmGET
91.189.34.1480/mUmmyfT0OZdOvzzz.htmGET
91.220.90.3380/NOkJSY/.htmGET
91.189.34.1480/cjGl.htmGET
89.46.237.1280/stesTnHdCP.htmGET
89.69.4.4880/1p7vW59yW.htmGET
89.228.29.4080/IHnawT5pV.htmGET
89.46.237.1280/BfWX.htmGET
89.148.84.4580/MqNLGkZoFCg.htmGET
89.133.241.280/FSWI16f/iUUt.htmGET
89.133.241.280/tzFMyLVAYs8wH.htmGET
88.132.4.5680/vHfB89FAdI6.htmGET
85.121.218.3980/oxXpVU2wPF.htmGET
87.248.90.3680/GEfqo/cfEs05.htmGET
84.38.80.980/ZCJK.htmGET
84.205.164.4680/8iPZ5wFKkOvIi/lmOHb.htmGET
84.38.80.980/103PMNPCOnPnBzrlK8.htmGET
82.237.8.5280/TbwBXyh9mJjU.htmGET
81.15.207.4380/8I6JhjdL8FhGK.htmGET
79.124.88.1480/XDldNnJIq5ZfittSHa.htmGET
79.124.88.1480/OANFjjB9N9.htmGET
31.6.149.1380/kHM8.htmGET
31.6.149.1380/WSYuO/qEndDrOYe.htmGET
31.133.32.5080/HvbQy4.htmGET
31.41.12.3280/Wkka.htmGET
24.178.227.880/wKCNf3Ib.htmGET
24.241.206.3580/cFpvqSSZ.htmGET
196.202.56.1080/szuTuNhgsi4I32.htmGET
212.52.46.2480/8Hwr6KXcGswKG.htmGET
190.160.160.1680/KbGO.htmGET
196.202.56.1080/aYkpTghnswEVQXw.htmGET
188.124.101.1780/xmj7dCIm4z6.htmGET
188.2.220.4680/0BZt5.htmGET
186.22.136.5380/oly0o2CWwBznI.htmGET
178.90.10.5480/W5MQaLDhX65up50Nz.htmGET
178.235.51.2980/uT8qlVy9Ih2ed.htmGET
178.48.73.2480/Ya50i.htmGET
178.168.91.280/CA0oGEk7.htmGET
178.168.91.280/U67D1T.htmGET
178.165.69.1280/zZk0pubhEyiDwUgf7U.htmGET
176.73.170.680/41x166tjyF417mawY.htmGET
176.73.170.680/dV9VHjt.htmGET
178.165.69.1280/HxoBTXGmspTaG5.htmGET

DNS Request Data


DNS Requests
Query
ryflyed.eu
wyylsic.eu
stn0001.com
ryflyed.eu
ryflyed.eu

DNS Responses
QueryResponse
wyylsic.eu211.203.38.199
stn0001.com91.217.153.155
ryflyed.eu178.149.146.124
ryflyed.eu109.173.31.53

Discussion

blog comments powered by Disqus