75.102.21.13(Parabola’s botnet hosted with United States Chicago Hostforweb Inc)

Remote Host Port Number
184.73.209.168 80
204.0.5.41 80
204.0.5.42 80
204.0.5.48 80
204.0.5.56 80
216.178.38.103 80
216.178.38.168 80
63.135.86.21 80
64.208.138.220 80
64.208.241.27 80
75.102.21.13 1234 PASS xxx

MODE NEW-[USA|00|P|67055] -ix
JOIN #!nn! test
PONG 22 MOTD
NICK NEW-[USA|00|P|67055]
USER XP-7278 * 0 :COMPUTERNAME

* The data identified by the following URLs was then requested from the remote web server:
o http://adx.bidsystem.com/showAd.aspx?pid=50000021&plid=24013&adsize=160×600&fncback=C1Mk0Bi8Ej7V.b1Mk0Bi8Ej7V&fnlocid=270&fan=1
o http://c2.ac-images.myspacecdn.com/images02/148/s_da284a441c5f4464b1d6fcf740709065.jpg
o http://c2.ac-images.myspacecdn.com/images02/126/s_4d7ed2676ac74675a5552f7b24732f69.jpg
o http://c2.ac-images.myspacecdn.com/images02/93/s_2cea4d23bd8d4e08b405e9afb8427cc9.jpg
o http://c2.ac-images.myspacecdn.com/images02/137/s_2032c06594304ebabb3577bc7314148d.jpg
o http://c2.ac-images.myspacecdn.com/images02/122/s_ecb2945068064858b04a94815ed95475.jpg
o http://c2.ac-images.myspacecdn.com/images02/128/s_36b81e97299349e5a66f930e4bf2fc65.jpg
o http://c2.ac-images.myspacecdn.com/images02/66/s_f3d83cef7b3346348d256a5b85670921.jpg
o http://c2.ac-images.myspacecdn.com/images02/68/s_084eede539534198ba70f8b8bc05d24d.jpg
o http://c3.ac-images.myspacecdn.com/images02/137/s_f6c1b6242f9c43f79b34a08185316e16.jpg
o http://c3.ac-images.myspacecdn.com/images02/117/s_f8e90b9760db451e8c2b7dff2f7c86f6.jpg
o http://c3.ac-images.myspacecdn.com/images02/1/s_99f702b8f7cd423c912e514566458d86.jpg
o http://c3.ac-images.myspacecdn.com/images02/17/s_4b5ad8d3d49a473e90096944ae3cd16a.jpg
o http://c3.ac-images.myspacecdn.com/images02/148/s_db64d84668ad463ab8e9af3d43b4e36e.jpg
o http://c3.ac-images.myspacecdn.com/images02/102/s_3557d11428fd4e5ebe841b1db06c6ef2.jpg
o http://c3.ac-images.myspacecdn.com/images02/134/s_9b03a7dcc7e047d8ad75e982e845695e.jpg
o http://c3.ac-images.myspacecdn.com/images02/91/s_c634b937e90447be91dc8476e01a36c2.jpg
o http://c3.ac-images.myspacecdn.com/images02/123/s_93435fb3662d426c8a77890814e5998e.jpg
o http://c3.ac-images.myspacecdn.com/images02/119/s_4628f375419745809aaead7a1f477246.jpg
o http://c3.ac-images.myspacecdn.com/images02/124/s_3a67e9b7c1da4bf59c44187c0e819c3e.jpg
o http://c3.ac-images.myspacecdn.com/images02/149/s_70b5d2b92a524cec87e841d4f3c36d42.jpg
o http://c3.ac-images.myspacecdn.com/images02/98/s_b8803c78848d4e42a13862229b9f08ba.jpg
o http://c1.ac-images.myspacecdn.com/images02/111/s_4b89da9636614a7398ccdceb4ad95ef8.jpg
o http://c1.ac-images.myspacecdn.com/images02/116/s_7b56ba1252f944a39447d8ce385b1884.jpg
o http://c1.ac-images.myspacecdn.com/images02/129/s_51357b95257b44cb83e1a151ac53a2b4.jpg
o http://c1.ac-images.myspacecdn.com/images02/87/s_2f78d5eb03824aaf99c87a9cf28bec14.jpg
o http://c1.ac-images.myspacecdn.com/images02/118/s_d1f89f4606754bb6b82b4eaef89e3660.jpg
o http://c1.ac-images.myspacecdn.com/images02/146/s_ea9417e01c054f598b405fc4c38a6320.jpg
o http://c1.ac-images.myspacecdn.com/images02/57/s_0b554479fbc44c1d825edb012a7f5f68.jpg
o http://c4.ac-images.myspacecdn.com/images02/152/s_73f7909d7c924dd39641a4406b6f9443.jpg
o http://c4.ac-images.myspacecdn.com/images02/150/s_b9e8a59eee9e454f84f2d4036ddccca3.jpg
o http://c4.ac-images.myspacecdn.com/images02/52/s_ba061a6813d64d88b741286df457d56f.jpg
o http://c4.ac-images.myspacecdn.com/images02/141/s_ae4394b4c7904abf826bcdc645d37653.jpg
o http://c4.ac-images.myspacecdn.com/images02/144/s_af3d4004828149438ad2fe0cd3bbb307.jpg
o http://c4.ac-images.myspacecdn.com/images02/4/s_c0ab04fcce264ad9ac2bcd1a8749cd17.jpg
o http://c4.ac-images.myspacecdn.com/images02/74/s_ad5a52edd7e34e8c94bcf1042c1a6607.jpg
o http://c4.ac-images.myspacecdn.com/images02/126/s_31c95fca23ea4393819935591e4d1cff.jpg
o http://c4.ac-images.myspacecdn.com/images02/135/s_b7eee2e0c8be41929595f58395e47893.jpg
o http://c4.ac-images.myspacecdn.com/images02/103/s_dac79a3ce603463686fe4a3c5bda2a63.jpg
o http://c4.ac-images.myspacecdn.com/images02/120/s_c17f19513c2147d99012cbdfdbbbd1eb.jpg
o http://c4.ac-images.myspacecdn.com/images01/76/s_a11b1f8331eea8eec79b43e9497ea35f.jpg
o http://browseusers.myspace.com/Browse/Browse.aspx
o http://desk.opt.fimserve.com/adopt/?r=h&l=24000000&pos=skyscraper&rnd=021902594
o http://delb.opt.fimserve.com/adopt/?r=h&l=24000000&pos=leaderboard&rnd=021902594
o http://fim.adnxs.com/fpt?id=3594&size=160×600&flash=1&cookies=1&callback=C1Mk0Bi8Ej7V.b2Xm0Fc8Pv7L&referrer=www.foxaudiencenetwork.com&age=&gender=&cb=1288927496893
o http://x.myspacecdn.com/modules/splash/static/img/bgSheet.png
o http://x.myspacecdn.com/modules/splash/static/img/moduleBg.gif
o http://x.myspacecdn.com/Modules/Common/Static/img/cornersSheet3.png
o http://x.myspacecdn.com/modules/common/static/css/Sprites/globalNavRefreshSprite.png
o http://x.myspacecdn.com/modules/browse/static/img/btnicons_tiled.gif
o http://cms.myspacecdn.com/cms/js/ad_wrapper0159.js
o http://x.myspacecdn.com/modules/common/static/css/global_-cca62xx.css
o http://x.myspacecdn.com/modules/browse/static/css/browse_qiz4yewv.css
o http://x.myspacecdn.com/modules/profilesdirectory/static/css/browsebyname_4vb3esmf.css
o http://x.myspacecdn.com/modules/common/static/img/spacer.gif
o http://x.myspacecdn.com/modules/common/static/img/onlinenow2.gif
o http://js.myspacecdn.com/modules/common/static/js/atlas/richtexteditor_uvm5sqtf.js
o http://js.myspacecdn.com/modules/common/static/js/atlas/msglobal_uabkhbad.js
o http://js.myspacecdn.com/modules/browse/static/js/browsebundle_kwg2eboy.js
o http://js.myspacecdn.com/modules/common/static/js/jquery/tracking/tynt_zcvgeagv.js?user=bjNOt4bfyr35kFadbiUt4I&lang=en
o http://js.myspacecdn.com/modules/common/static/js/atlas/quickpost_ujzxjul0.js
o http://bid.ace.advertising.com/bid/ebs=1/site=744646/size=728090/tags=1/callback=C1Ce5Sz7Vp3U.b1Fn5Hg7Rv3C/bnum=1288927497065
o http://bid.ace.advertising.com/ctst=1/bid/ebs=1/site=744646/size=728090/tags=1/callback=C1Ce5Sz7Vp3U.b1Fn5Hg7Rv3C/bnum=1288927497065
o http://www.facebook.com/home.php
o http://www.facebook.com/login.php
o http://p.ic.tynt.com/b/p?id=bjNOt4bfyr35kFadbiUt4I&ts=1288927497830&t=Browse%20MySpace%20Friends%20and%20Profiles
o http://ad.turn.com/server/bid/fan.bid?pub=10063193&cch=10063206&l=728×90&requestId=C1Ce5Sz7Vp3U.b0Ry5Ce7Sz3V&ref=http%3A%2F%2Fmyspace-ugc-foxaudiencenetwork.com&rand=1288927497065
o http://ad.turn.com/server/bid/fan.bid?pub=10063193&cch=10063206&l=160×600&requestId=C1Mk0Bi8Ej7V.b0Jg0Of8Hp7R&ref=http%3A%2F%2Fmyspace-ugc-foxaudiencenetwork.com&rand=1288927496893
o http://www.google-analytics.com/ga.js
o http://googleads.g.doubleclick.net/pagead/test_domain.js
o http://googleads.g.doubleclick.net/pagead/imgad?id=COaz6pqtlsOtmwEQoAEYwgQyCPvh_ZWH_GQf
o http://pagead2.googlesyndication.com/pagead/show_ads.js
o http://pagead2.googlesyndication.com/pagead/expansion_embed.js
o http://pagead2.googlesyndication.com/pagead/render_ads.js
o http://ad.yieldmanager.com/getbid?Z=728×90&s=796240&_salt=1288927497065&r=1&callback=C1Ce5Sz7Vp3U.b2Fk5Ho7Ry3C&cookie=1&flash=1&bvs=&hvs=BBJRUOOP&u=http%3A%2F%2Fbrowseusers.myspace.com%2FBrowse%2FBrowse.aspx

Other details

* The following ports were open in the system:

Port Protocol Process
1054 TCP nvsvc32.exe (%Windir%nvsvc32.exe)
1058 TCP nvsvc32.exe (%Windir%nvsvc32.exe)
1098 TCP nvsvc32.exe (%Windir%nvsvc32.exe)

Registry Modifications

* The newly created Registry Values are:
o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
+ NVIDIA driver monitor = “%Windir%nvsvc32.exe”

so that nvsvc32.exe runs every time Windows starts
o [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionTerminal ServerInstallSoftwareMicrosoftWindowsCurrentVersionRun]
+ NVIDIA driver monitor = “%Windir%nvsvc32.exe”

so that nvsvc32.exe runs every time Windows starts
o [HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
+ NVIDIA driver monitor = “%Windir%nvsvc32.exe”

so that nvsvc32.exe runs every time Windows starts

Memory Modifications

* There was a new process created in the system:

Process Name Process Filename Main Module Size
nvsvc32.exe %Windir%nvsvc32.exe 3 125 248 bytes

* The following system service was modified:

Service Name Display Name New Status Service Filename
wuauserv Automatic Updates “Stopped” %System%svchost.exe -k netsvcs

File System Modifications

* The following files were created in the system:

# Filename(s) File Size File Hash
1 %Windir%ndl.dl 2 293 bytes MD5: 0xF80E4F20D63E212B92CE115BC268F185
SHA-1: 0x1D33F09F2298DD3B72A44BA1F11C5880F0CA471A
2 %Windir%nvsvc32.exe
[file and pathname of the sample #1] 90 112 bytes MD5: 0x47DC9B72EC28005FC52C450235ED15C5
SHA-1: 0xA79FEDD202F276AA940D527562643F504445818E
3 %Windir%wibrf.jpg 3 968 bytes MD5: 0xE246233F7DCFE923D7A54F29B63CC30E
SHA-1: 0xB512DA23F7D01E8BD23133583103A83DC6D5C787
4 %Windir%wiybr.png 3 416 bytes MD5: 0xD3A3A9391EA080EDFEF8BA202CC36D2E
SHA-1: 0xD771C5BA93DC6FC0438AF3FF1E909338F63EC283

infos about hoster :
http://whois.domaintools.com/75.102.21.13

Categories: Uncategorized