RAMNIT RAT Trojan Backdoor 66.198.24.243.443 world.taobao.com fget-career.com hhbqxgq.exe PCAP file download traffic C2

SHA256: 654295d26a5f030914a5342624d44358e822b9bfbabd188b602c506724d6e4f6
File name: hhbqxgq.exe
Detection ratio: 51 / 55
Analysis date: 2016-10-28 01:17:33 UTC ( 0 minutes ago )
ALYac Win32.Ramnit 20161028
AVG Agent_r.AJA 20161028
AVware Trojan.Win32.Generic!BT 20161027
Ad-Aware Win32.Ramnit 20161028
AegisLab W32.Nimnul.a!c 20161027
AhnLab-V3 Win32/Ramnit.B 20161027
Antiy-AVL Virus/Win32.Nimnul.a 20161027
Arcabit Win32.Ramnit 20161028
Avast Win32:RmnDrp 20161027
Avira (no cloud) W32/Ramnit.A 20161027
Baidu Win32.Virus.Nimnul.a 20161027
BitDefender Win32.Ramnit 20161028
Bkav W32.RammitNNA.PE 20161027
CAT-QuickHeal W32.Ramnit.A 20161027
ClamAV Win.Trojan.Ramnit-1847 20161027
Comodo Virus.Win32.Ramnit.A 20161028
CrowdStrike Falcon (ML) malicious_confidence_100% (W) 20161024

2016-10-27 19:54:31.458114 IP 192.168.1.102.55840 > 175.6.5.125.80: Flags [P.], seq 0:289, ack 1, win 256, length 289: HTTP: GET /hhbqxgq.exe HTTP/1.1
E..Im.@…. …f…}. .P…     E       l1P….?..GET /hhbqxgq.exe HTTP/1.1
Accept: application/x-shockwave-flash, image/gif, image/jpeg, image/pjpeg, */*
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
Accept-Encoding: gzip, deflate
Host: wt8.52zsoft.com
Connection: Keep-Alive

2016-10-27 19:55:06.095117 IP 192.168.1.102.51598 > 75.75.75.75.53: 15147+ A? world.taobao.com. (34)
E..>(%………fKKKK…5.*..;+………..world.taobao.com…..
2016-10-27 19:55:06.141276 IP 192.168.1.102.55856 > 66.198.24.243.443: Flags [.], ack 4848, win 256, length 0
E..(*.@….@…fB….0….f
..O.P………….
2016-10-27 19:55:06.188302 IP 192.168.1.102.55856 > 66.198.24.243.443: Flags [.], ack 4848, win 256, options [nop,nop,sack 1 {4846:4847}], length 0
E..4*.@….3…fB….0….f
..O……W…..
..O…O.
2016-10-27 19:55:06.239455 IP 192.168.1.102.55857 > 66.198.24.243.443: Flags [S], seq 1404369026, win 8192, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
E..4*.@….2…fB….1..S……… .    %…………..
2016-10-27 19:55:06.879911 IP 192.168.1.102.55857 > 66.198.24.243.443: Flags [.], ack 1349710297, win 256, length 0
E..(*.@….=…fB….1..S…Pr..P…&………
2016-10-27 19:55:07.202952 IP 192.168.1.102.55857 > 66.198.24.243.443: Flags [P.], seq 0:77, ack 1, win 256, length 77
E..u*.@……..fB….1..S…Pr..P…O[……H…D..X…..(.7…..6…>0…U .Q3{..t……..
.       .d.b………c………
2016-10-27 19:55:07.360973 IP 192.168.1.102.55857 > 66.198.24.243.443: Flags [.], ack 1, win 256, options [nop,nop,sack 1 {4198:4199}], length 0
E..4*.@…./…fB….1..S…Pr……J……
Ps.>Ps.?
2016-10-27 19:55:07.513544 IP 192.168.1.102.55857 > 66.198.24.243.443: Flags [.], ack 1, win 256, options [nop,nop,sack 2 {4198:4199}{4197:4199}], length 0
E..<*.@….&…fB….1..S…Pr…….a……Ps.>Ps.?Ps.=Ps.?
2016-10-27 19:55:07.564129 IP 192.168.1.102.55857 > 66.198.24.243.443: Flags [.], ack 1461, win 256, options [nop,nop,sack 1 {4197:4199}], length 0
E..4*.@….-…fB….1..S…Pr……E!…..
Ps.=Ps.?
2016-10-27 19:55:07.623980 IP 192.168.1.102.55857 > 66.198.24.243.443: Flags [.], ack 1461, win 256, options [nop,nop,sack 2 {4197:4199}{2921:4200}], length 0
E..<*.@….$…fB….1..S…Pr…………..Ps.=Ps.?Pr.APs.@
2016-10-27 19:55:07.723051 IP 192.168.1.102.55857 > 66.198.24.243.443: Flags [.], ack 4200, win 256, length 0
E..(*.@….7…fB….1..S…Ps.@P………….
2016-10-27 19:55:07.724548 IP 192.168.1.102.55857 > 66.198.24.243.443: Flags [P.], seq 77:395, ack 4200, win 256, length 318
E..f*.@……..fB….1..S…Ps.@P………………,….Z;…-a…..!.y…      .Ii.c+.!’..f<.d.xcU……….   .2.w..RNU6;.n..C}I..”……._..s.5…\.i.;.>.   .<…#.Y.a.Y…%B.|0…….5…_.u.X+B…G…RD…m
.{+.9b?.;..A}.L..E.,n.       .)…..5..JY…….._.K-.”..)……]………….(..^.2Z.WvLY…*./Z…..%.R{.Q..j……….(…Q………Y..#.d..]D.A….K.^p.c../zP
2016-10-27 19:55:07.854706 IP 192.168.1.102.55850 > 205.204.101.182.443: Flags [.], ack 4678, win 64760, length 0
E..(..@….|…f..e..*……….P…1X……..
2016-10-27 19:55:08.033477 IP 192.168.1.102.55857 > 66.198.24.243.443: Flags [P.], seq 395:640, ack 4251, win 256, length 245
E…*.@….@…fB….1..S…Ps.sP…;C…….UP.K…..P_..m…F.^t.”..(I4.}7%…:…n).@……..U.u..68<:.!.Y….D^.q.$….D._I…..T:..M.g.Q….*..ay.#…;3.L..j.g…..9j*.(.f.Gs.3..U….L….@.:.9G.U0..O…H./
..A.+….Y}n.=…..8..^K….^……hiV….vF.%..*.=…%…{..%.TQ………
2016-10-27 19:55:08.092131 IP 192.168.1.102.55857 > 66.198.24.243.443: Flags [.], ack 5680, win 256, options [nop,nop,sack 1 {7140:8600}], length 0
E..4*.@….(…fB….1..S…Ps………….
Ps..Ps.p
2016-10-27 19:55:08.121216 IP 192.168.1.102.55857 > 66.198.24.243.443: Flags [F.], seq 640, ack 5680, win 256, length 0
E..(*.@….3…fB….1..S…Ps..P………….
2016-10-27 19:55:08.170573 IP 192.168.1.102.55857 > 66.198.24.243.443: Flags [.], ack 5680, win 256, options [nop,nop,sack 1 {7140:10060}], length 0
E..4*.@….&…fB….1..S…Ps………….
Ps..Ps.$
2016-10-27 19:55:08.171022 IP 192.168.1.102.55857 > 66.198.24.243.443: Flags [.], ack 5680, win 256, options [nop,nop,sack 1 {7140:11520}], length 0
E..4*.@….%…fB….1..S…Ps……
Z…..
Ps..Ps..

2016-10-27 19:55:10.755309 IP 192.168.1.102.51599 > 75.75.75.75.53: 15716+ A? fget-career.com. (33)
E..=(&………fKKKK…5.)..=d………..fget-career.com…..
2016-10-27 19:55:10.863607 IP 192.168.1.102.55858 > 89.185.44.