Sample details: cb79f95efa3d2d3f4c93e4bcf0eed942 --

Hashes
MD5: cb79f95efa3d2d3f4c93e4bcf0eed942
SHA1: 3bebfdb64debd13f7919c0641fc5cc64e6855d1d
SHA256: b573da0226d15127374a57f353acfb9b0370c10f2c102894bdb90940ddef6ee6
SSDEEP: 1536:g3Ul6zJXqTbSkvC2G58LqhHuJqH1O95d+GvvV4jT/X5cx:mU0FH5hOJqVO95d4/X
Details
File Type: PE32
Yara Hits
YRP/Microsoft_Visual_Cpp_v50v60_MFC | YRP/IsPE32 | YRP/IsDLL | YRP/IsWindowsGUI | YRP/maldoc_find_kernel32_base_method_1 | YRP/domain | YRP/url | YRP/contentis_base64 | YRP/Browsers | YRP/network_tcp_socket | YRP/network_dns | YRP/escalate_priv | YRP/cred_local | YRP/cred_ff | YRP/win_mutex | YRP/win_registry | YRP/win_token | YRP/win_private_profile | YRP/win_files_operation | YRP/MD5_Constants | YRP/RIPEMD160_Constants | YRP/SHA1_Constants | YRP/DES_sbox | YRP/Str_Win32_Winsock2_Library | YRP/Str_Win32_Wininet_Library | YRP/with_sqlite | YRP/pony | BAMFDetect/pony |
Strings
		!This program cannot be run in DOS mode.
`.rdata
@.data
.reloc
PSQRWV
^_ZY[X
VWPSQR
ZY[X_^
C:\1.bin
9D$(ub
L$(9L$@
v89l$D|0
uM9l$D}G
D$0;D$(
9|$4r4
9|$4r4
+L$PRQW
+D$P][_^
aPLib v1.01  -  the smaller the better :)
Copyright (c) 1998-2009 by Joergen Ibsen, All Rights Reserved.
More information: http://www.ibsensoftware.com/
1DA409EB2825851644CCDAB
3TerPWG34|rL:wFcFsn{iT92c\n4qiygu
http://facabeand.com/mlu/forum.php
http://hadcaldintheck.ru/mlu/forum.php
http://withersmebet.ru/mlu/forum.php
YUIPWDFILE0YUIPKDFILE0YUICRYPTED0YUI1.0
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
UninstallString
DisplayName
Software\WinRAR
vaultcli.dll
VaultOpenVault
VaultEnumerateItems
VaultGetItem
VaultCloseVault
VaultFree
kernel32.dll
WTSGetActiveConsoleSessionId
ProcessIdToSessionId
netapi32.dll
NetApiBufferFree
NetUserEnum
ole32.dll
StgOpenStorage
advapi32.dll
AllocateAndInitializeSid
CheckTokenMembership
FreeSid
CredEnumerateA
CredFree
CryptGetUserKey
CryptExportKey
CryptDestroyKey
CryptReleaseContext
RevertToSelf
OpenProcessToken
ImpersonateLoggedOnUser
GetTokenInformation
ConvertSidToStringSidA
LogonUserA
LookupPrivilegeValueA
AdjustTokenPrivileges
CreateProcessAsUserA
crypt32.dll
CryptUnprotectData
CertOpenSystemStoreA
CertEnumCertificatesInStore
CertCloseStore
CryptAcquireCertificatePrivateKey
msi.dll
MsiGetComponentPathA
pstorec.dll
PStoreCreateInstance
userenv.dll
CreateEnvironmentBlock
DestroyEnvironmentBlock
shell32.dll
SHGetFolderPathA
My Documents
AppData
Local AppData
Cookies
History
My Documents
Common AppData
My Pictures
Common Documents
Common Administrative Tools
Administrative Tools
Personal
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
explorer.exe
S-1-5-18
SeImpersonatePrivilege
SeTcbPrivilege
SeChangeNotifyPrivilege
SeCreateTokenPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeIncreaseQuotaPrivilege
SeAssignPrimaryTokenPrivilege
GetNativeSystemInfo
kernel32.dll
IsWow64Process
Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/5.0)
POST %s HTTP/1.0
Host: %s
Accept: */*
Accept-Encoding: identity, *;q=0
Accept-Language: en-US
Content-Length: %lu
Content-Type: application/octet-stream
Connection: close
Content-Encoding: binary
User-Agent: %s
Content-Length:
Location:
Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyServer
{%08X-%04X-%04X-%02X%02X-%02X%02X%02X%02X%02X%02X}
_cx_ftp.ini
\GHISLER
InstallDir
FtpIniName
Software\_hisler\Windows Commander
Software\_hisler\Total Commander
\Ipswitch
Sites\
\Ipswitch\WS_FTP
\win.ini
WS_FTP
DEFDIR
CUTEFTP
QCHistory
Software\GlobalSCAPE\CuteFTP 6 Home\QCToolbar
Software\GlobalSCAPE\CuteFTP 6 Professional\QCToolbar
Software\GlobalSCAPE\CuteFTP 7 Home\QCToolbar
Software\GlobalSCAPE\CuteFTP 7 Professional\QCToolbar
Software\GlobalSCAPE\CuteFTP 8 Home\QCToolbar
Software\GlobalSCAPE\CuteFTP 8 Professional\QCToolbar
Software\GlobalSCAPE\CuteFTP 9\QCToolbar
\GlobalSCAPE\CuteFTP
\GlobalSCAPE\CuteFTP Pro
\GlobalSCAPE\CuteFTP Lite
\CuteFTP
\sm.dat
_oftware\FlashFXP\3
_oftware\FlashFXP
_oftware\FlashFXP\4
InstallerDathPath
Install Path
DataFolder
\Sites.dat
\Quick.dat
\_istory.dat
\FlashFXP\3
\FlashFXP\4
\FileZilla
\sitemanager.xml
\recentservers.xml
\filezilla.xml
Software\FileZilla
Software\FileZilla Client
Install_Dir
Remote Dir
Server Type
Server.Host
Server.User
Server.Pass
Server.Port
ServerType
Last Server Host
Last Server User
Last Server Pass
Last Server Port
Last Server Path
Last Server Type
\BulletProof Software
Software\BPFTP\Bullet Proof FTP\Main
Software\BulletProof Software\BulletProof FTP Client\Main
Software\BPFTP\Bullet Proof FTP\Options
Software\BulletProof Software\BulletProof FTP Client\Options
Software\BPFTP
LastSessionFile
SitesDir
InstallDir1
\SmartFTP
Favorites.dat
_istory.dat
Software\FTPWare\COREFTP\Sites
_VanDyke\Config\Sessions
\Sessions
Software\VanDyke\SecureFX
Config Path
Password
HostName
UserName
RemoteDirectory
PortNumber
FSProtocol
Software\Martin Prikryl
http://
https://
ftp://
wand.dat
_Software\Opera Software
Last Directory3
Last Install Path
Opera.HTML\shell\open\command
\Opera Software
nss3.dll
NSS_Init
NSS_Shutdown
NSSBase64_DecodeBuffer
SECITEM_FreeItem
PK11_GetInternalKeySlot
PK11_Authenticate
PK11SDR_Decrypt
PK11_FreeSlot
profiles.ini
Profile
IsRelative
PathToExe
prefs.js
logins.json
signons.sqlite
signons.txt
signons2.txt
signons3.txt
encryptedPassword":"
encryptedUsername":"
hostname":"
Firefox
\Mozilla\Firefox\
Software\Mozilla
ftp://
http://
https://
fireFTPsites.dat
Mozilla
\Mozilla\Profiles\
Internet Explorer
WininetCacheCredentials
MS IE FTP Passwords
DPAPI: 
Software\Microsoft\Internet Explorer\IntelliForms\Storage2
SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\IntelliForms\FormData
Microsoft_WinInet_*
ftp://
SspiPfc
;USQLite format 3
CONSTRAINT
PRIMARY
UNIQUE
FOREIGN
Web Data
Login Data
logins
origin_url
password_value
username_value
ftp://
http://
https://
moz_logins
hostname
encryptedPassword
encryptedUsername
\Google\Chrome
\ChromePlus
Software\ChromePlus
Install_Dir
TeamViewer
TERMSRV/*
password 51:b:
username:s:
full address:s:
TERMSRV/
.oeaccount
<_OP3_Password2
<_MTP_Password2
<IMAP_Password2
<HTTPMail_Password2
\Microsoft\Windows Live Mail
Software\Microsoft\Windows Live Mail
\Microsoft\Windows Mail
Software\Microsoft\Windows Mail
Software\IncrediMail
EmailAddress
Technology
PopServer
PopPort
PopAccount
PopPassword
_mtpServer
_mtpPort
_mtpAccount
_mtpPassword
SMTP Email Address
SMTP Server
POP3 Server
POP3 User Name
SMTP User Name
NNTP Email Address
NNTP User Name
NNTP Server
IMAP Server
IMAP User Name
HTTP User
HTTP Server URL
POP3 User
IMAP User
HTTPMail User Name
HTTPMail Server
SMTP User
POP3 Port
SMTP Port
IMAP Port
POP3 Password2
IMAP Password2
NNTP Password2
HTTPMail Password2
SMTP Password2
POP3 Password
IMAP Password
NNTP Password
HTTP Password
SMTP Password
Software\Microsoft\Internet Account Manager\Accounts
Identities
Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts
Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Microsoft Outlook Internet Settings
Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook
Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook
Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook
Software\Microsoft\Internet Account Manager
Outlook
\Accounts
identification
identitymgr
inetcomm server passwords
outlook account manager passwords
identities
{%08X-%04X-%04X-%02X%02X-%02X%02X%02X%02X%02X%02X}
Thunderbird
\Thunderbird
r`l`oui`
lhbidmmd
dlhodl
rbnnuds
`reg`reg
eh`lnoe
l`yvdmm
ktruho
bihbjdo
e`ohdmmd
hmnwdxnt3
gtbjngg
qshobd
ktohns
s`hocnv
003322
gtbjxnt0
ohoudoen
qd`otu
bitsbi
ctccmdr
sncdsu
333333
edruhox
mnwhof
fgikjl
lxmnwd
k`rqds
032230
bnb`bnm`
idmqld
ohbnmd
fthu`s
chmmf`udr
mnnjhof
rbnncx
knrdqi
fdodrhr
dll`otdm
b`rrhd
whbunsx
q`rrv1se
gnnc`s
hmnwdfne
o`ui`o
cm`cm`
ehfhu`m
qd`bidr
gnnuc`mm0
00000000
uitoeds
f`udv`x
hmnwdxnt 
gnnuc`mm
uhffds
bnswduud
jhmmds
bsd`uhwd
032547698
fnnfmd
{ybwcol
ru`susdj
`rimdx
biddrd
rtorihod
bishru
111111
rnbbds
pvdsux0
gshdoe
rtllds
0325476
ldsmho
03254769
knse`o
edyuds
vhoods
rq`sjx
vhoenvr
032`cb
`ouinox
ficeuo
inuenf
c`rdc`mm
q`rrvnse0
es`fno
ustruon0
houdsodu
ltruehd
mduldho
johfiu
knse`o32
`cb032
sde032
qs`hrd
gsddenl
kdrtr0
mnoeno
bnlqtuds
lhbsnrngu
ltggho
lnuids
l`ruds
000000
p`{vry
r`ltdm
b`o`e`
rm`xds
s`bidm
nodmnwd
pvdsux
qs`xds
hmnwdxnt0
vi`udwds
q`rrvnse
cmdrrhof
ronnqx
0p3v2d5s
bnnjhd
bidmrd`
qnjdlno
i`i`i`
``````
i`sebnsd
ri`env
vdmbnld
ltru`of
745230
c`hmdx
cm`icm`i
l`ushy
kdrrhb`
rudmm`
cdok`lho
udruhof
rdbsdu
ushohux
shbi`se
ri`mnl
lnojdx
hmnwdxnt
uinl`r
cmhoj093
k`rlhod
qtsqmd
`ofdmr
cmdrrde
0325476981
id`wdo
itouds
qdqqds
knio207
ctruds
`oesdv
fhofds
6666666
inbjdx
idmmn0
`ofdm0
rtqdsl`o
e`ohdm
032032
gnsdwds
onuihof
e`jnu`
jhuudo
c`o`o`
gmnvds
u`xmns
mnwdmx
i`oo`i
qshobdrr
bnlq`p
kdoohgds
lxrq`bd0
rlnjdx
l`uuidv
i`smdx
snuhlh
gtbjxnt
rnbbds0
032547
rhofmd
knrit`
032pvd
ru`sv`sr
rhmwds
`truho
lhbi`dm
`l`oe`
bi`smhd
c`oehu
l`ffhd
l`wdshbj
nomhod
rqhshu
fdnsfd
gshdoer
e`mm`r
`ehe`r
0p3v2d
ns`ofd
udruudru
`rrinmd
chudld
777777
vhmmh`l
lhbjdx
`regfi
vhrenl
c`ul`o
Client Hash
STATUS-IMPORT-OK
LMIIgnition.exe
Local\mtxLogMeInIgnition.IgnitionMutex
cmd /K
;3+#>6.&
'2, /+0&7!4-)1#
inet_addr
gethostbyname
socket
connect
closesocket
select
setsockopt
WSAStartup
wsock32.dll
CreateFileA
ReadFile
CloseHandle
WriteFile
lstrlenA
GlobalLock
GlobalUnlock
LocalFree
LocalAlloc
GetTickCount
lstrcpyA
lstrcatA
GetFileAttributesA
ExpandEnvironmentStringsA
GetFileSize
CreateFileMappingA
MapViewOfFile
UnmapViewOfFile
LoadLibraryA
GetProcAddress
GetTempPathA
CreateDirectoryA
DeleteFileA
GetCurrentProcess
WideCharToMultiByte
GetLastError
lstrcmpA
CreateToolhelp32Snapshot
Process32First
OpenProcess
Process32Next
GetModuleHandleA
FindFirstFileA
lstrcmpiA
FindNextFileA
FindClose
GetVersionExA
GetLocaleInfoA
GetSystemInfo
GetWindowsDirectoryA
GetPrivateProfileStringA
SetCurrentDirectoryA
GetPrivateProfileSectionNamesA
GetPrivateProfileIntA
GetCurrentDirectoryA
lstrlenW
TerminateProcess
CreateMutexA
CreateProcessA
LCMapStringA
ExitProcess
SetUnhandledExceptionFilter
kernel32.dll
ObtainUserAgentString
urlmon.dll
LoadUserProfileA
UnloadUserProfile
userenv.dll
CreateStreamOnHGlobal
GetHGlobalFromStream
CoCreateGuid
CoTaskMemFree
CoCreateInstance
OleInitialize
ole32.dll
wsprintfA
FindWindowExA
SendMessageA
GetClassNameA
SendMessageW
user32.dll
RegOpenKeyExA
RegQueryValueExA
RegCloseKey
RegOpenKeyA
RegEnumKeyExA
RegCreateKeyA
RegSetValueExA
IsTextUnicode
RegOpenCurrentUser
GetUserNameA
advapi32.dll
InternetCrackUrlA
InternetCreateUrlA
wininet.dll
StrStrIA
StrRChrIA
StrToIntA
StrCmpNIA
StrStrIW
StrStrA
shlwapi.dll
5'8p:8=v=
0/141j1
5(5-575<5F5K5U5Z5d5i5s5x5
788J9S9\9~9
E6O6Y6c6m6
7%7+70767?7E7O7m7t7
<(<]<q<l>~>
172T2s2
647F7K7Q7
7&8d8k8r8
9!9&9,9A9F9L9r9w9}9
=<=X=g=v=
>E?S?f?t?
0Y0f0s0
1"2)20272=2B2H2U2Z2`2m2r2x2
3+303B3G3Y3^3p3u3
6 6%6*6/646I6N6S6X6]6b6z6
7*7/757T7Y7_7~7
8;8p8u8{8
9"9'9-9
;&;h;t;
>$>0>r>
8D9^9}9
9T:Y:_:n:
;E;J;\;i;n;t;};
>c><?D?O?`?k?|?
^0v0:1_1
4.4\4m4~4
7C8T8h8
9&9+909d=
?-?3?|?
1*1N1T1
2#202=2J2W2j2p2
303:3Y3r3
151O1i1
2.292J2U2r2
4@4c4x4
5&5\5q5v5
7>8H8R8[8p8y8
8/9>9C9I9Z9d9t9~9
;V<_<h<
>8?B?q?
080A0G0
1=2b2y2
4:4Z4u4
= =4=:=G=L=Z=`=t=y=
>G>a>f>k>q>~>
3D4i4w4
5%5:5^5y5
5:6U6p6
7*878[8r8{8
9"9(9.949:9@9F9L9R9X9^9d9j9p9v9|9
:$:*:0:6:<:B:H:N:T:Z:`:f:l:r:x:~:
#7.797D7
1'2P2^2l2z2N3^3l3|3
305A5R5c5{5
636D6U6#777\7j7x7
:&:5:<:K:
;5?5C5G5K5O5S5W5[5_5c5g5k5
"6&6*6.62666:6>6B6F6J6N6R6V6Z6^6b6f6j6n6r6v6z6~6