Sample details: dbd8d00ddc5e803b7b19bd139868fe90 --

Hashes
MD5: dbd8d00ddc5e803b7b19bd139868fe90
SHA1: 57fd025284d957e6127fdf105df7a79de0daac6f
SHA256: 1e37041e6d42a7c256c6efe06380fbbd581da62875e463372d4db4eaea60eb4b
SSDEEP: 1536:snkZ2rh/aqTTUQM+twzmLwMi1V7q3g5dely5On1TvQkzbkjql/A:tM9/pMMcvaGOnvyql/A
Details
File Type: PE32
Yara Hits
YRP/IsPE32 | YRP/IsWindowsGUI | YRP/maldoc_find_kernel32_base_method_1 | YRP/domain | YRP/IP | YRP/url | YRP/contentis_base64 | YRP/Browsers | YRP/network_tcp_socket | YRP/network_dns | YRP/escalate_priv | YRP/cred_local | YRP/cred_ff | YRP/win_registry | YRP/win_token | YRP/win_private_profile | YRP/win_files_operation | YRP/MD5_Constants | YRP/RIPEMD160_Constants | YRP/SHA1_Constants | YRP/DES_sbox | YRP/Str_Win32_Winsock2_Library | YRP/Str_Win32_Wininet_Library | YRP/with_sqlite | YRP/pony | BAMFDetect/pony |
Strings
		!This program cannot be run in DOS mode.
`.rdata
@.data
PSQRWV
^_ZY[X
VWPSQR
ZY[X_^
SVWhFXA
t>h2XA
t$hYaA
t%hGbA
t%hGbA
t%hGbA
t9hYdA
tBPh:dA
tchKgA
uFhAhA
tEhsiA
VWh=lA
t|hjmA
uehmoA
tQh~oA
tEh*rA
tEh@rA
9D$(ub
L$(9L$@
v89l$D|0
uM9l$D}G
D$0;D$(
9|$4r4
9|$4r4
+L$PRQW
+D$P][_^
aPLib v1.01  -  the smaller the better :)
Copyright (c) 1998-2009 by Joergen Ibsen, All Rights Reserved.
More information: http://www.ibsensoftware.com/
http://clue.darkbastard.com.de/panel/gate.php
YUIPWDFILE0YUIPKDFILE0YUICRYPTED0YUI1.0
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
UninstallString
DisplayName
Software\WinRAR
kernel32.dll
WTSGetActiveConsoleSessionId
ProcessIdToSessionId
netapi32.dll
NetApiBufferFree
NetUserEnum
ole32.dll
StgOpenStorage
advapi32.dll
AllocateAndInitializeSid
CheckTokenMembership
FreeSid
CredEnumerateA
CredFree
CryptGetUserKey
CryptExportKey
CryptDestroyKey
CryptReleaseContext
RevertToSelf
OpenProcessToken
ImpersonateLoggedOnUser
GetTokenInformation
ConvertSidToStringSidA
LogonUserA
LookupPrivilegeValueA
AdjustTokenPrivileges
CreateProcessAsUserA
crypt32.dll
CryptUnprotectData
CertOpenSystemStoreA
CertEnumCertificatesInStore
CertCloseStore
CryptAcquireCertificatePrivateKey
msi.dll
MsiGetComponentPathA
pstorec.dll
PStoreCreateInstance
userenv.dll
CreateEnvironmentBlock
DestroyEnvironmentBlock
shell32.dll
SHGetFolderPathA
My Documents
AppData
Local AppData
Cookies
History
My Documents
Common AppData
My Pictures
Common Documents
Common Administrative Tools
Administrative Tools
Personal
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
explorer.exe
S-1-5-18
SeImpersonatePrivilege
SeTcbPrivilege
SeChangeNotifyPrivilege
SeCreateTokenPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeIncreaseQuotaPrivilege
SeAssignPrimaryTokenPrivilege
Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/5.0)
POST %s HTTP/1.0
Host: %s
Accept: */*
Accept-Encoding: identity, *;q=0
Accept-Language: en-US
Content-Length: %lu
Content-Type: application/octet-stream
Connection: close
Content-Encoding: binary
User-Agent: %s
Content-Length:
Location:
{%08X-%04X-%04X-%02X%02X-%02X%02X%02X%02X%02X%02X}
GetNativeSystemInfo
kernel32.dll
IsWow64Process
Software\Far\Plugins\FTP\Hosts
Software\Far2\Plugins\FTP\Hosts
Software\Far Manager\Plugins\FTP\Hosts
Software\Far\SavedDialogHistory\FTPHost
Software\Far2\SavedDialogHistory\FTPHost
Software\Far Manager\SavedDialogHistory\FTPHost
Password
HostName
_cx_ftp.ini
\GHISLER
InstallDir
FtpIniName
Software\_hisler\Windows Commander
Software\_hisler\Total Commander
\Ipswitch
Sites\
\Ipswitch\WS_FTP
\win.ini
WS_FTP
DEFDIR
CUTEFTP
QCHistory
Software\GlobalSCAPE\CuteFTP 6 Home\QCToolbar
Software\GlobalSCAPE\CuteFTP 6 Professional\QCToolbar
Software\GlobalSCAPE\CuteFTP 7 Home\QCToolbar
Software\GlobalSCAPE\CuteFTP 7 Professional\QCToolbar
Software\GlobalSCAPE\CuteFTP 8 Home\QCToolbar
Software\GlobalSCAPE\CuteFTP 8 Professional\QCToolbar
Software\GlobalSCAPE\CuteFTP 9\QCToolbar
\GlobalSCAPE\CuteFTP
\GlobalSCAPE\CuteFTP Pro
\GlobalSCAPE\CuteFTP Lite
\CuteFTP
\sm.dat
_oftware\FlashFXP\3
_oftware\FlashFXP
_oftware\FlashFXP\4
InstallerDathPath
Install Path
DataFolder
\Sites.dat
\Quick.dat
\_istory.dat
\FlashFXP\3
\FlashFXP\4
\FileZilla
\sitemanager.xml
\recentservers.xml
\filezilla.xml
Software\FileZilla
Software\FileZilla Client
Install_Dir
Remote Dir
Server Type
Server.Host
Server.User
Server.Pass
Server.Port
ServerType
Last Server Host
Last Server User
Last Server Pass
Last Server Port
Last Server Path
Last Server Type
FTP Navigator
FTP Commander
ftplist.txt
\BulletProof Software
Software\BPFTP\Bullet Proof FTP\Main
Software\BulletProof Software\BulletProof FTP Client\Main
Software\BPFTP\Bullet Proof FTP\Options
Software\BulletProof Software\BulletProof FTP Client\Options
Software\BPFTP
LastSessionFile
SitesDir
InstallDir1
\SmartFTP
Favorites.dat
_istory.dat
_ddrbk.dat
quick.dat
\TurboFTP
Software\TurboFTP
installpath
Software\Sota\FFFTP
CredentialSalt
CredentialCheck
Software\Sota\FFFTP\Options
Password
UserName
HostAdrs
RemoteDir
HostName
Username
Password
HostDirName
Software\CoffeeCup Software\Internet\Profiles
Software\FTPWare\COREFTP\Sites
profiles.xml
\FTP Explorer
Software\FTP Explorer\FTP Explorer\Workspace\MFCToolBar-224
Buttons
Software\FTP Explorer\Profiles
Password
PasswordType
InitialPath
FtpSite.xml
\Frigate3
_VanDyke\Config\Sessions
\Sessions
Software\VanDyke\SecureFX
Config Path
UltraFXP
\sites.xml
\FTPRush
RushSite.xml
Server
Username
Password
FtpPort
Software\Cryer\WebSitePublisher
\BitKinex
bitkinex.ds
Hostname
Username
Password
Software\ExpanDrive\Sessions
\ExpanDrive
\drives.js
"password" : "
Software\ExpanDrive
ExpanDrive_Home
Server
UserName
Password
_Password
Directory
Software\NCH Software\ClassicFTP\FTPAccounts
FtpServer
FtpUserName
FtpPassword
_FtpPassword
FtpDirectory
SOFTWARE\NCH Software\Fling\Accounts
Software\FTPClient\Sites
Software\SoftX.org\FTPClient\Sites
ftplast.osd
\GPSoftware\Directory Opus
\SharedSettings.ccs
\SharedSettings_1_0_5.ccs
\SharedSettings.sqlite
\SharedSettings_1_0_5.sqlite
\CoffeeCup Software
leapftp
unleap.exe
sites.dat
sites.ini
\LeapWare\LeapFTP
SOFTWARE\LeapWare
InstallPath
DataDir
Password
HostName
UserName
RemoteDirectory
PortNumber
FSProtocol
Software\Martin Prikryl
\32BitFtp.ini
NDSites.ini
\NetDrive
PassWord
UserName
RootDirectory
Software\South River Technologies\WebDrive\Connections
ServerType
FTP CONTROL
FTPCON
\Profiles
http://
https://
ftp://
wand.dat
_Software\Opera Software
Last Directory3
Last Install Path
Opera.HTML\shell\open\command
\Opera Software
wiseftpsrvs.bin
\AceBIT
Software\AceBIT
SOFTWARE\Classes\TypeLib\{CB1F2C0F-8094-4AAC-BCF5-41A64E27F777}
SOFTWARE\Classes\TypeLib\{9EA55529-E122-4757-BC79-E4825F80732C}
wiseftpsrvs.ini
wiseftp.ini
FTPVoyager.ftp
FTPVoyager.ftp.backup
FTPVoyager.ftp.old.backup
FTPVoyager.qc
\RhinoSoft.com
nss3.dll
NSS_Init
NSS_Shutdown
NSSBase64_DecodeBuffer
SECITEM_FreeItem
PK11_GetInternalKeySlot
PK11_Authenticate
PK11SDR_Decrypt
PK11_FreeSlot
profiles.ini
Profile
IsRelative
PathToExe
prefs.js
signons.sqlite
signons.txt
signons2.txt
signons3.txt
Firefox
\Mozilla\Firefox\
Software\Mozilla
ftp://
http://
https://
fireFTPsites.dat
SeaMonkey
\Mozilla\SeaMonkey\
\Flock\Browser\
Mozilla
\Mozilla\Profiles\
Software\LeechFTP
AppDir
LocalDir
bookmark.dat
SiteInfo.QFP
Favorites.dat
WinFTP
sites.db
CLSID\{11C1D741-A95B-11d2-8A80-0080ADB32FF4}\InProcServer32
servers.xml
\FTPGetter
ESTdb2.dat
QData.dat
\Estsoft\ALFTP
Internet Explorer
WininetCacheCredentials
MS IE FTP Passwords
DPAPI: 
Software\Microsoft\Internet Explorer\IntelliForms\Storage2
Microsoft_WinInet_*
ftp://
Software\Adobe\Common
SiteServers
SiteServer %d\Host
SiteServer %d\WebUrl
SiteServer %d\Remote Directory
SiteServer %d-User
SiteServer %d-User PW
%s\Keychain
SiteServer %d\SFTP
DeluxeFTP
sites.xml
SQLite format 3
CONSTRAINT
PRIMARY
UNIQUE
FOREIGN
Web Data
Login Data
logins
origin_url
password_value
username_value
ftp://
http://
https://
moz_logins
hostname
encryptedPassword
encryptedUsername
\Google\Chrome
\Chromium
\ChromePlus
Software\ChromePlus
Install_Dir
\Bromium
\Nichrome
\Comodo
\RockMelt
K-Meleon
\K-Meleon
\Profiles
\Epic\Epic
Staff-FTP
sites.ini
\Sites
\Visicom Media
\Global Downloader
SM.arch
FreshFTP
BlazeFtp
site.dat
LastPassword
LastAddress
LastUser
LastPort
Software\FlashPeak\BlazeFtp\Settings
\BlazeFtp
FTP++.Link\shell\open\command
Connections.txt
3D-FTP
sites.ini
\3D-FTP
\SiteDesigner
SOFTWARE\Classes\TypeLib\{F9043C88-F6F2-101A-A3C9-08002B2F49FB}\1.2\0\win32
EasyFTP
\NetSarang
TERMSRV/*
password 51:b:
username:s:
full address:s:
TERMSRV/
FTP Now
FTPNow
sites.xml
SOFTWARE\Robo-FTP 3.7\Scripts
SOFTWARE\Robo-FTP 3.7\FTPServers
FTP Count
FTP File%d
Password
ServerName
UserID
InitialDirectory
PortNumber
ServerType
2.5.29.37
Software\LinasFTP\Site Manager
Remote Dir
\Cyberduck
user.config
<setting name="
value="
Software\SimonTatham\PuTTY\Sessions
HostName
UserName
Password
PortNumber
TerminalType
NppFTP.xml
\Notepad++
Software\CoffeeCup Software
FTP destination server
FTP destination user
FTP destination password
FTP destination port
FTP destination catalog
FTP profiles
FTPShell
ftpshell.fsi
Software\MAS-Soft\FTPInfo\Setup
DataDir
\FTPInfo
ServerList.xml
NexusFile
ftpsite.ini
FastStone Browser
FTPList.db
\MapleStudio\ChromePlus
Software\Nico Mak Computing\WinZip\FTP
Software\Nico Mak Computing\WinZip\mru\jobs
UserID
xflags
Folder
winex="
\Yandex
My FTP
project.ini
{74FF1730-B1F2-4D88-926B-1568FAE61DB7}
NovaFTP.db
\INSoftware\NovaFTP
.oeaccount
<_OP3_Password2
<_MTP_Password2
<IMAP_Password2
<HTTPMail_Password2
\Microsoft\Windows Live Mail
Software\Microsoft\Windows Live Mail
\Microsoft\Windows Mail
Software\Microsoft\Windows Mail
Software\RimArts\B2\Settings
DataDir
DataDirBak
Mailbox.ini
Software\Poco Systems Inc
\PocoSystem.ini
Program
DataPath
accounts.ini
\Pocomail
Software\IncrediMail
EmailAddress
Technology
PopServer
PopPort
PopAccount
PopPassword
_mtpServer
_mtpPort
_mtpAccount
_mtpPassword
account.cfg
account.cfn
\BatMail
\The Bat!
Software\RIT\The Bat!
Software\RIT\The Bat!\Users depot
Working Directory
ProgramDir
Default
Dir #%d
RLUQ!Dl`hm!@eesdrr
RLUQ!Rdswds
QNQ2!Rdswds
QNQ2!Trds!O`ld
RLUQ!Trds!O`ld
OOUQ!Dl`hm!@eesdrr
OOUQ!Trds!O`ld
OOUQ!Rdswds
HL@Q!Rdswds
HL@Q!Trds!O`ld
IUUQ!Trds
IUUQ!Rdswds!TSM
QNQ2!Trds
HL@Q!Trds
IUUQL`hm!Trds!O`ld
IUUQL`hm!Rdswds
RLUQ!Trds
QNQ2!Qnsu
RLUQ!Qnsu
HL@Q!Qnsu
QNQ2!Q`rrvnse3
HL@Q!Q`rrvnse3
OOUQ!Q`rrvnse3
IUUQL`hm!Q`rrvnse3
RLUQ!Q`rrvnse3
QNQ2!Q`rrvnse
HL@Q!Q`rrvnse
OOUQ!Q`rrvnse
IUUQ!Q`rrvnse
RLUQ!Q`rrvnse
Software\Microsoft\Internet Account Manager\Accounts
Identities
Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts
Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Microsoft Outlook Internet Settings
Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook
Software\Microsoft\Internet Account Manager
Outlook
\Accounts
identification
identitymgr
inetcomm server passwords
outlook account manager passwords
identities
{%08X-%04X-%04X-%02X%02X-%02X%02X%02X%02X%02X%02X}
Thunderbird
\Thunderbird
FastTrack
ftplist.txt
wallet.dat
\Bitcoin
electrum.dat
\Electrum
.wallet
\MultiBit
Accounts.ini
\Maxprog\FTP Disk
wallet.dat
\Litecoin
wallet.dat
\Namecoin
wallet.dat
\Terracoin
.wallet
\Armory
wallet.dat
\PPCoin
wallet.dat
\Primecoin
wallet.dat
\Feathercoin
wallet.dat
\NovaCoin
wallet.dat
\Freicoin
wallet.dat
\Devcoin
wallet.dat
\Franko
wallet.dat
\ProtoShares
wallet.dat
\Megacoin
wallet.dat
\Quarkcoin
wallet.dat
\Worldcoin
wallet.dat
\Infinitecoin
wallet.dat
\Ixcoin
wallet.dat
\Anoncoin
wallet.dat
\BBQcoin
wallet.dat
\Digitalcoin
wallet.dat
\Mincoin
wallet.dat
\GoldCoin (GLD)
wallet.dat
\Yacoin
wallet.dat
\Zetacoin
wallet.dat
\Fastcoin
wallet.dat
\I0coin
wallet.dat
\Tagcoin
wallet.dat
\Bytecoin
wallet.dat
\Florincoin
wallet.dat
\Phoenixcoin
wallet.dat
\Luckycoin
wallet.dat
\Craftcoin
wallet.dat
\Junkcoin
r`l`oui`
lhbidmmd
dlhodl
rbnnuds
`reg`reg
eh`lnoe
l`yvdmm
ktruho
bihbjdo
e`ohdmmd
hmnwdxnt3
gtbjngg
qshobd
ktohns
s`hocnv
003322
gtbjxnt0
ohoudoen
qd`otu
bitsbi
ctccmdr
sncdsu
333333
edruhox
mnwhof
fgikjl
lxmnwd
k`rqds
032230
bnb`bnm`
idmqld
ohbnmd
fthu`s
chmmf`udr
mnnjhof
rbnncx
knrdqi
fdodrhr
dll`otdm
b`rrhd
whbunsx
q`rrv1se
gnnc`s
hmnwdfne
o`ui`o
cm`cm`
ehfhu`m
qd`bidr
gnnuc`mm0
00000000
uitoeds
f`udv`x
hmnwdxnt 
gnnuc`mm
uhffds
bnswduud
jhmmds
bsd`uhwd
032547698
fnnfmd
{ybwcol
ru`susdj
`rimdx
biddrd
rtorihod
bishru
111111
rnbbds
pvdsux0
gshdoe
rtllds
0325476
ldsmho
03254769
knse`o
edyuds
vhoods
rq`sjx
vhoenvr
032`cb
`ouinox
ficeuo
inuenf
c`rdc`mm
q`rrvnse0
es`fno
ustruon0
houdsodu
ltruehd
mduldho
johfiu
knse`o32
`cb032
sde032
qs`hrd
gsddenl
kdrtr0
mnoeno
bnlqtuds
lhbsnrngu
ltggho
lnuids
l`ruds
000000
p`{vry
r`ltdm
b`o`e`
rm`xds
s`bidm
nodmnwd
pvdsux
qs`xds
hmnwdxnt0
vi`udwds
q`rrvnse
cmdrrhof
ronnqx
0p3v2d5s
bnnjhd
bidmrd`
qnjdlno
i`i`i`
``````
i`sebnsd
ri`env
vdmbnld
ltru`of
745230
c`hmdx
cm`icm`i
l`ushy
kdrrhb`
rudmm`
cdok`lho
udruhof
rdbsdu
ushohux
shbi`se
ri`mnl
lnojdx
hmnwdxnt
uinl`r
cmhoj093
k`rlhod
qtsqmd
`ofdmr
cmdrrde
0325476981
id`wdo
itouds
qdqqds
knio207
ctruds
`oesdv
fhofds
6666666
inbjdx
idmmn0
`ofdm0
rtqdsl`o
e`ohdm
032032
gnsdwds
onuihof
e`jnu`
jhuudo
c`o`o`
gmnvds
u`xmns
mnwdmx
i`oo`i
qshobdrr
bnlq`p
kdoohgds
lxrq`bd0
rlnjdx
l`uuidv
i`smdx
snuhlh
gtbjxnt
rnbbds0
032547
rhofmd
knrit`
032pvd
ru`sv`sr
rhmwds
`truho
lhbi`dm
`l`oe`
bi`smhd
c`oehu
l`ffhd
l`wdshbj
nomhod
rqhshu
fdnsfd
gshdoer
e`mm`r
`ehe`r
0p3v2d
ns`ofd
udruudru
`rrinmd
chudld
777777
vhmmh`l
lhbjdx
`regfi
vhrenl
c`ul`o
Client Hash
STATUS-IMPORT-OK
;3+#>6.&
'2, /+0&7!4-)1#
CreateFileA
ReadFile
CloseHandle
WriteFile
lstrlenA
GlobalLock
GlobalUnlock
LocalFree
LocalAlloc
GetTickCount
lstrcpyA
lstrcatA
GetFileAttributesA
ExpandEnvironmentStringsA
GetFileSize
CreateFileMappingA
MapViewOfFile
UnmapViewOfFile
LoadLibraryA
GetProcAddress
GetTempPathA
CreateDirectoryA
DeleteFileA
GetCurrentProcess
WideCharToMultiByte
GetLastError
lstrcmpA
CreateToolhelp32Snapshot
Process32First
OpenProcess
Process32Next
FindFirstFileA
lstrcmpiA
FindNextFileA
FindClose
GetModuleHandleA
GetVersionExA
GetLocaleInfoA
GetSystemInfo
GetWindowsDirectoryA
GetPrivateProfileStringA
SetCurrentDirectoryA
GetPrivateProfileSectionNamesA
GetPrivateProfileIntA
GetCurrentDirectoryA
lstrlenW
MultiByteToWideChar
LCMapStringA
ExitProcess
SetUnhandledExceptionFilter
kernel32.dll
CreateStreamOnHGlobal
GetHGlobalFromStream
CoCreateGuid
CoTaskMemFree
CoCreateInstance
OleInitialize
ole32.dll
wsprintfA
user32.dll
RegOpenKeyExA
RegQueryValueExA
RegCloseKey
RegOpenKeyA
RegEnumKeyExA
RegCreateKeyA
RegSetValueExA
IsTextUnicode
RegOpenCurrentUser
RegEnumValueA
GetUserNameA
advapi32.dll
InternetCrackUrlA
InternetCreateUrlA
wininet.dll
StrStrIA
StrRChrIA
StrToIntA
StrStrA
StrCmpNIA
StrStrIW
shlwapi.dll
ObtainUserAgentString
urlmon.dll
inet_addr
gethostbyname
socket
connect
closesocket
select
setsockopt
WSAStartup
wsock32.dll
LoadUserProfileA
UnloadUserProfile
userenv.dll