Malware Trojan Download UDP 194.165.19.58 port 6892 PCAP File Download Traffic Sample 9|hi00673022 194.165.19.0/24

SHA256: b6fdf9369af7d3663274392de89b1d644f86232311e63a4a395dda474e1200ee
File name: a.exe
Detection ratio: 43 / 56
Analysis date: 2016-11-16 01:56:29 UTC ( 0 minutes ago )

 

ALYac Dropped:Trojan.GenericKD.3694587 20161116
AVG Ransom_c.DDX 20161116
AVware Trojan.Win32.Generic!BT 20161116
Ad-Aware Dropped:Trojan.GenericKD.3694587 20161116
AegisLab Troj.W32.Inject!c 20161115
AhnLab-V3 Trojan/Win32.Miuref.N2153088763 20161115
Arcabit Trojan.Generic.D385FFB 20161115
Avast Win32:Malware-gen 20161116
Avira (no cloud) TR/Crypt.Xpack.uqhcd 20161116
Baidu Win32.Trojan.WisdomEyes.16070401.9500.9667 20161115
BitDefender Dropped:Trojan.GenericKD.3694587 20161116
CAT-QuickHeal Trojan.Inject 20161115
ClamAV Win.Trojan.Generic-4270 20161115
Comodo TrojWare.Win32.UMal.xymtq 20161115
CrowdStrike Falcon (ML) malicious_confidence_100% (W) 20161024
Cyren W32/Trojan.KVEN-6166 20161116
DrWeb Trojan.Encoder.7074 20161116
ESET-NOD32 a variant of Win32/Injector.DHKG 20161116
Emsisoft Dropped:Trojan.GenericKD.3694587 (B) 20161116
F-Secure Trojan.GenericKD.3694587 20161115
Fortinet W32/Injector.DHKG!tr

016-11-15 19:35:38.517445 IP 192.168.1.102.53732 > 92.42.37.34.80: Flags [P.], seq 0:281, ack 1, win 256, length 281: HTTP: GET /js/a.exe HTTP/1.1
E..A{d@…:….f\*%”…P.x.k.FB.P…….GET /js/a.exe HTTP/1.1
Accept: application/x-shockwave-flash, image/gif, image/jpeg, image/pjpeg, */*
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
Accept-Encoding: gzip, deflate
Host: megsan.com
Connection: Keep-Alive

2016-11-15 19:35:38.716636 IP 192.168.1.102.53732 > 92.42.37.34.80: Flags [.], ack 2921, win 256, length 0
E..({e@…<….f\*%”…P.x…FN.P………….

E..(.d@….7…f.”…..P.(_.Y3..P….R……..
2016-11-15 19:35:39.453830 IP 192.168.1.102.53738 > 23.34.0.4.80: Flags [P.], seq 0:213, ack 1, win 256, length 213: HTTP: GET /en-US/livetile/preinstall?region=US&appid=C98EA5B0842DBB9405BBF071E1DA76512D21FE36&FORM=Threshold HTTP/1.1
E….e@….a…f.”…..P.(_.Y3..P….&..GET /en-US/livetile/preinstall?region=US&appid=C98EA5B0842DBB9405BBF071E1DA76512D21FE36&FORM=Threshold HTTP/1.1
Connection: Keep-Alive
User-Agent: Microsoft-WNS/10.0
Host: tile-service.weather.microsoft.com

2016-11-15 19:35:39.454208 IP 192.168.1.102.53741 > 104.244.43.71.443: Flags [.], ack 733953391, win 256, length 0
E..(.L@….:…fh.+G……..+.=oP…vL……..
2016-11-15 19:35:39.454928 IP 192.168.1.102.53741 > 104.244.43.71.443: Flags [P.], seq 0:190, ack 1, win 256, length 190
E….M@….{…fh.+G……..+.=oP………………X+….}PB…..,C.gp…>.+W.1..Z…8.,.+.0./…..$.#.(.’.
.       …..9.3…..=.<.5./.

E..({.@……..f…N…Pz#…P..P…v<……..
2016-11-15 19:35:39.483056 IP 192.168.1.102.53740 > 23.198.217.78.80: Flags [P.], seq 0:217, ack 1, win 256, length 217: HTTP: GET /Market.svc/AppTileV3?symbols=30.10.%21DJI.30.%24INDU&contentType=0&tileType=0&locale=EN-US&symbolTypes=I HTTP/1.1
E…|.@……..f…N…Pz#…P..P…….GET /Market.svc/AppTileV3?symbols=30.10.%21DJI.30.%24INDU&contentType=0&tileType=0&locale=EN-US&symbolTypes=I HTTP/1.1
Connection: Keep-Alive
User-Agent: Microsoft-WNS/10.0
Host: finance.services.appex.bing.com

2016-11-15 19:35:39.483061 IP 192.168.1.102.53737 > 23.198.217.78.80: Flags [P.], seq 0:193, ack 1, win 256, length 193: HTTP: GET /Market.svc/AppTileV3?symbols=&contentType=3&tileType=0&locale=EN-US&symbolTypes= HTTP/1.1
E…|.@……..f…N…PC.[Dy’..P…E…GET /Market.svc/AppTileV3?symbols=&contentType=3&tileType=0&locale=EN-US&symbolTypes= HTTP/1.1
Connection: Keep-Alive
User-Agent: Microsoft-WNS/10.0
Host: finance.services.appex.bing.com

2016-11-15 19:35:39.483129 IP 192.168.1.102.53739 > 23.198.217.78.80: Flags [P.], seq 0:214, ack 1, win 256, length 214: HTTP: GET /Market.svc/AppTileV3?symbols=29.10.%40CCO.29.COMP&contentType=0&tileType=0&locale=EN-US&symbolTypes=I HTTP/1.1
E…|.@……..f…N…P…….#P…….GET /Market.svc/AppTileV3?symbols=29.10.%40CCO.29.COMP&contentType=0&tileType=0&locale=EN-US&symbolTypes=I HTTP/1.1
Connection: Keep-Alive
User-Agent: Microsoft-WNS/10.0
Host: finance.services.appex.bing.com

2016-11-15 19:36:23.889906 IP 192.168.1.102.57172 > 194.165.19.8.6892: UDP, length 10
E..&
……….f…..T….9.hi00673022……..
2016-11-15 19:36:23.889957 IP 192.168.1.102.57172 > 194.165.19.9.6892: UDP, length 10
E..&<G….g….f…    .T….9.hi00673022……..
2016-11-15 19:36:23.889961 IP 192.168.1.102.57172 > 194.165.19.10.6892: UDP, length 10
E..&.’………f…
.T….9.hi00673022……..
2016-11-15 19:36:23.890008 IP 192.168.1.102.57172 > 194.165.19.11.6892: UDP, length 10
E..&#i………f…..T….9.hi00673022……..
2016-11-15 19:36:23.890096 IP 192.168.1.102.57172 > 194.165.19.12.6892: UDP, length 10
E..&}…..&n…f…..T….9.hi00673022……..
2016-11-15 19:36:23.890149 IP 192.168.1.102.57172 > 194.165.19.13.6892: UDP, length 10
E..&/…..t+…f…..T….9.hi00673022……..
2016-11-15 19:36:23.890154 IP 192.168.1.102.57172 > 194.165.19.14.6892: UDP, length 10
E..&…….J…f…..T….9.hi00673022……..
2016-11-15 19:36:23.890205 IP 192.168.1.102.57172 > 194.165.19.15.6892: UDP, length 10
E..&&…..}….f…..T….9.hi00673022……..
2016-11-15 19:36:23.890269 IP 192.168.1.102.57172 > 194.165.19.16.6892: UDP, length 10
E..&Ei….^….f…..T….9.hi00673022……..
2016-11-15 19:36:23.890320 IP 192.168.1.102.57172 > 194.165.19.17.6892: UDP, length 10
E..&w+….,….f…..T….9.hi00673022……..
2016-11-15 19:36:23.890382 IP 192.168.1.102.57172 > 194.165.19.18.6892: UDP, length 10
E..&NK….U….f…..T….9.hi00673022……..
2016-11-15 19:36:23.890432 IP 192.168.1.102.57172 > 194.165.19.19.6892: UDP, length 10
E..&`…..C….f…..T….9.hi00673022……..
2016-11-15 19:36:23.890483 IP 192.168.1.102.57172 > 194.165.19.20.6892: UDP, length 10
E..&@…..c….f…..T….9.hi00673022……..
2016-11-15 19:36:23.890487 IP 192.168.1.102.57172 > 194.165.19.21.6892: UDP, length 10
E..&r…..1?…f…..T….9.hi00673022……..
2016-11-15 19:36:23.890584 IP 192.168.1.102.57172 > 194.165.19.22.6892: UDP, length 10
E..&Y…..J….f…..T….9.hi00673022……..
2016-11-15 19:36:23.890633 IP 192.168.1.102.57172 > 194.165.19.23.6892: UDP, length 10
E..&k…..8[…f…..T….9.hi00673022……..
2016-11-15 19:36:23.890636 IP 192.168.1.102.57172 > 194.165.19.24.6892: UDP, length 10
E..&K9….X….f…..T….9.hi00673022……..
2016-11-15 19:36:23.890734 IP 192.168.1.102.57172 > 194.165.19.25.6892: UDP, length 10
E..&y{….*….f…..T….9.hi00673022……..
2016-11-15 19:36:23.890784 IP 192.168.1.102.57172 > 194.165.19.26.6892: UDP, length 10
E..&T…..O….f…..T….9.hi00673022……..
2016-11-15 19:36:23.890835 IP 192.168.1.102.57172 > 194.165.19.27.6892: UDP, length 10
E..&b]….A….f…..T….9.hi00673022……..
2016-11-15 19:36:23.890885 IP 192.168.1.102.57172 > 194.165.19.28.6892: UDP, length 10
E..&>…..e*…f…..T….9.hi00673022……..
2016-11-15 19:36:23.890935 IP 192.168.1.102.57172 > 194.165.19.29.6892: UDP, length 10
E..&m…..6….f…..T….9.hi00673022……..
2016-11-15 19:36:23.890996 IP 192.168.1.102.57172 > 194.165.19.30.6892: UDP, length 10
E..&W…..LF…f…..T….9.hi00673022……..
2016-11-15 19:36:23.891047 IP 192.168.1.102.57172 > 194.165.19.31.6892: UDP, length 10
E..&e…..>….f…..T….9.hi00673022……..
2016-11-15 19:36:23.891096 IP 192.168.1.102.57172 > 194.165.19.32.6892: UDP, length 10
E..&&…..}….f… .T….9.hi00673022……..
2016-11-15 19:36:23.891099 IP 192.168.1.102.57172 > 194.165.19.33.6892: UDP, length 10
E..&…….M…f…!.T….9.hi00673022……..
2016-11-15 19:36:23.891147 IP 192.168.1.102.57172 > 194.165.19.34.6892: UDP, length 10
E..&0…..s….f…”.T….9.hi00673022……..
2016-11-15 19:36:23.891235 IP 192.168.1.102.57172 > 194.165.19.35.6892: UDP, length 10
E..&}…..&)…f…#.T….9.hi00673022……..
2016-11-15 19:36:23.891284 IP 192.168.1.102.57172 > 194.165.19.36.6892: UDP, length 10
E..&#W………f…$.T….9~hi00673022……..
2016-11-15 19:36:23.891335 IP 192.168.1.102.57172 > 194.165.19.37.6892: UDP, length 10
E..&………..f…%.T….9}hi00673022……..
2016-11-15 19:36:23.891385 IP 192.168.1.102.57172 > 194.165.19.38.6892: UDP, length 10
E..&<y….gt…f…&.T….9|hi00673022……..
2016-11-15 19:36:23.891387 IP 192.168.1.102.57172 > 194.165.19.39.6892: UDP, length 10
E..&
;………f…’.T….9{hi00673022……..
2016-11-15 19:36:23.891435 IP 192.168.1.102.57172 > 194.165.19.40.6892: UDP, length 10
E..&(…..{8…f…(.T….9zhi00673022……..
2016-11-15 19:36:23.891503 IP 192.168.1.102.57172 > 194.165.19.41.6892: UDP, length 10
E..&………..f…).T….9yhi00673022……..
2016-11-15 19:36:23.891572 IP 192.168.1.102.57172 > 194.165.19.42.6892: UDP, length 10
E..&1…..r….f…*.T….9xhi00673022……..
2016-11-15 19:36:23.891621 IP 192.168.1.102.57172 > 194.165.19.43.6892: UDP, length 10
E..&………..f…+.T….9whi00673022……..
2016-11-15 19:36:23.891624 IP 192.168.1.102.57172 > 194.165.19.44.6892: UDP, length 10
E..&.’………f…,.T….9vhi00673022……..
2016-11-15 19:36:23.891721 IP 192.168.1.102.57172 > 194.165.19.45.6892: UDP, length 10
E..&.i…..}…f…-.T….9uhi00673022……..
2016-11-15 19:36:23.891771 IP 192.168.1.102.57172 > 194.165.19.46.6892: UDP, length 10
E..&6I….m….f…..T….9thi00673022……..
2016-11-15 19:36:23.891774 IP 192.168.1.102.57172 > 194.165.19.47.6892: UDP, length 10
E..&…….Y…f…/.T….9shi00673022……..
2016-11-15 19:36:23.891823 IP 192.168.1.102.57172 > 194.165.19.48.6892: UDP, length 10
E..&f…..=….f…0.T….9rhi00673022……..
2016-11-15 19:36:23.891908 IP 192.168.1.102.57172 > 194.165.19.49.6892: UDP, length 10
E..&W…..L    …f…1.T….9qhi00673022……..
2016-11-15 19:36:23.891958 IP 192.168.1.102.57172 > 194.165.19.50.6892: UDP, length 10
E..&l…..6….f…2.T….9phi00673022……..
2016-11-15 19:36:23.892008 IP 192.168.1.102.57172 > 194.165.19.51.6892: UDP, length 10
E..&>…..e%…f…3.T….9ohi00673022……..
2016-11-15 19:36:23.892058 IP 192.168.1.102.57172 > 194.165.19.52.6892: UDP, length 10
E..&b…..AT…f…4.T….9nhi00673022……..
2016-11-15 19:36:23.892062 IP 192.168.1.102.57172 > 194.165.19.53.6892: UDP, length 10
E..&TM….O….f…5.T….9mhi00673022……..
2016-11-15 19:36:23.892145 IP 192.168.1.102.57172 > 194.165.19.54.6892: UDP, length 10
E..&ym….*p…f…6.T….9lhi00673022……..
2016-11-15 19:36:23.892195 IP 192.168.1.102.57172 > 194.165.19.55.6892: UDP, length 10
E..&K/….X….f…7.T….9khi00673022……..
2016-11-15 19:36:23.892245 IP 192.168.1.102.57172 > 194.165.19.56.6892: UDP, length 10
E..&k…..7….f…8.T….9jhi00673022……..
2016-11-15 19:36:23.892248 IP 192.168.1.102.57172 > 194.165.19.57.6892: UDP, length 10
E..&Z)….I….f…9.T….9ihi00673022……..
2016-11-15 19:36:23.892329 IP 192.168.1.102.57172 > 194.165.19.58.6892: UDP, length 10
E..&r…..1….f…:.T….9hhi00673022……..
2016-11-15 19:36:23.892385 IP 192.168.1.102.57172 > 194.165.19.59.6892: UDP, length 10
E..&A…..b….f…;.T….9ghi00673022……..