Following a detailed report on the Malware:
[ General information ]
* File name: c:documents and settingsadministratordesktopimage96523489.exe
* File length: 65024 bytes
* File signature: Microsoft Visual C++ 7.0
* MD5 hash: 085ecb8b600c3b4b105674ed27cdcbaf
* SHA1 hash: 5c20fe20a5f0a86d1b0455f8d20299dfe583b30b
* SHA256 hash: f2a17d30d9e921fdc9e0d7f927f20c8820869552d8ba1cfa5f7fbc68d64f970a
[ Changes to filesystem ]
* Creates file C:windowsndl.dl
* Creates file (hidden) C:windowsnvsvc32.exe
* Creates file (hidden) C:windowswibrf.jpg
* Creates file (hidden) C:windowswiybr.png
* Creates file C:Documents and SettingsAdministratorCookiesadministrator@facebook[1].txt
* Creates file C:Documents and SettingsAdministratorCookiesadministrator@myspace[2].txt
* Creates file C:Documents and SettingsAdministratorCookiesadministrator@www.myspace[1].txt
* Creates file C:Documents and SettingsAdministratorLocal SettingsHistoryHistory.IE5MSHist012010121320101220index.dat
* Creates file C:Documents and SettingsAdministratorLocal SettingsHistoryHistory.IE5MSHist012010122020101221index.dat
* Creates file C:Documents and SettingsAdministratorLocal SettingsTemporary Internet FilesContent.IE5F7YBJYVWbg_browserSection[1].jpg
* Creates file C:Documents and SettingsAdministratorLocal SettingsTemporary Internet FilesContent.IE5F7YBJYVWbrowserunsupported[1].htm
* Creates file C:Documents and SettingsAdministratorLocal SettingsTemporary Internet FilesContent.IE5JRQBGGX3icon_information[1].gif
* Creates file C:Documents and SettingsAdministratorLocal SettingsTemporary Internet FilesContent.IE5JRQBGGX3index[4].htm
* Creates file C:Documents and SettingsAdministratorLocal SettingsTemporary Internet FilesContent.IE5LPI195Q5bg_infobox[1].jpg
* Creates file C:Documents and SettingsAdministratorLocal SettingsTemporary Internet FilesContent.IE5LPI195Q5browserLogos_med[1].jpg
* Creates file C:Documents and SettingsAdministratorLocal SettingsTemporary Internet FilesContent.IE5ZQFMUB46cornersSheet[1].png
[ Changes to registry ]
* Creates value "FileTracingMask=0000FFFF" in key HKEY_LOCAL_MACHINEsoftwaremicrosoftTracingFWCFG
* Creates value "ConsoleTracingMask=0000FFFF" in key HKEY_LOCAL_MACHINEsoftwaremicrosoftTracingFWCFG
* Creates value "MaxFileSize=00001000" in key HKEY_LOCAL_MACHINEsoftwaremicrosoftTracingFWCFG
* Creates value "FileDirectory=2500770069006E0064006900720025005C00740072006100630069006E0067000000" in key HKEY_LOCAL_MACHINEsoftwaremicrosoftTracingFWCFG
* Creates value "NVIDIA driver monitor=c:windowsnvsvc32.exe" in key HKEY_LOCAL_MACHINEsoftwaremicrosoftWindowsCurrentVersionRun
* Creates value "NVIDIA driver monitor=c:windowsnvsvc32.exe" in key HKEY_LOCAL_MACHINEsoftwaremicrosoftWindows NTCurrentVersionTerminal ServerInstallSoftwareMicrosoftWindowsCurrentVersionRun
* Creates value "LogSessionName=7300740064006F00750074000000" in key HKEY_LOCAL_MACHINEsoftwaremicrosoftWindows NTCurrentVersionTracingMicrosoftNAPNetsh
* Creates value "Active=01000000" in key HKEY_LOCAL_MACHINEsoftwaremicrosoftWindows NTCurrentVersionTracingMicrosoftNAPNetsh
* Creates value "ControlFlags=01000000" in key HKEY_LOCAL_MACHINEsoftwaremicrosoftWindows NTCurrentVersionTracingMicrosoftNAPNetsh
* Creates value "Guid=710adbf0-ce88-40b4-a50d-231ada6593f0" in key HKEY_LOCAL_MACHINEsoftwaremicrosoftWindows NTCurrentVersionTracingMicrosoftNAPNetshNapmontr
* Creates value "BitNames= NAP_TRACE_BASE NAP_TRACE_NETSH" in key HKEY_LOCAL_MACHINEsoftwaremicrosoftWindows NTCurrentVersionTracingMicrosoftNAPNetshNapmontr
* Creates value "LogSessionName=7300740064006F00750074000000" in key HKEY_LOCAL_MACHINEsoftwaremicrosoftWindows NTCurrentVersionTracingMicrosoftqagent
* Creates value "Active=01000000" in key HKEY_LOCAL_MACHINEsoftwaremicrosoftWindows NTCurrentVersionTracingMicrosoftqagent
* Creates value "ControlFlags=01000000" in key HKEY_LOCAL_MACHINEsoftwaremicrosoftWindows NTCurrentVersionTracingMicrosoftqagent
* Creates value "Guid=b0278a28-76f1-4e15-b1df-14b209a12613" in key HKEY_LOCAL_MACHINEsoftwaremicrosoftWindows NTCurrentVersionTracingMicrosoftqagenttraceIdentifier
* Creates value "BitNames= Error Unusual Info Debug" in key HKEY_LOCAL_MACHINEsoftwaremicrosoftWindows NTCurrentVersionTracingMicrosoftqagenttraceIdentifier
* Creates Registry key HKEY_LOCAL_MACHINEsystemCurrentControlSetServicesnapagentLocalConfigEnrollHcsGroups
* Creates Registry key HKEY_LOCAL_MACHINEsystemCurrentControlSetServicesnapagentLocalConfigUI
* Creates value "image96523489.exe=c:windowsnvsvc32.exe:*:Enabled:NVIDIA driver monitor" in key HKEY_LOCAL_MACHINEsystemCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsListC:Documents and SettingsAdministratorDesktop
* Modifies value "Start=00000004" in key HKEY_LOCAL_MACHINEsystemCurrentControlSetServiceswuauserv
old value "Start=00000002"
* Modifies value "Window_Placement=2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF62000000920000005903000041030000" in key HKEY_CURRENT_USERsoftwareMicrosoftInternet ExplorerMain
old value "Window_Placement=2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFA00000000000000097030000AF020000"
* Deletes Registry key HKEY_CURRENT_USERsoftwareMicrosoftWindowsCurrentVersionExplorerMountPoints2CPCVolume
* Modifies value "HRZR_PGYFRFFVBA=10015D0E14000000" in key HKEY_CURRENT_USERsoftwareMicrosoftWindowsCurrentVersionExplorerUserAssist{5E6AB780-7743-11CF-A12B-00AA004AE837}Count
old value "HRZR_PGYFRFFVBA=FDED5C0E13000000"
* Modifies value "Count=00000010" in key HKEY_CURRENT_USERsoftwareMicrosoftWindowsCurrentVersionExtStats{E2E2DD38-D088-4134-82B7-F2BA38496583}iexplore
old value "Count=0000000F"
* Modifies value "Time=DA070C000100140008002A0022006C00" in key HKEY_CURRENT_USERsoftwareMicrosoftWindowsCurrentVersionExtStats{E2E2DD38-D088-4134-82B7-F2BA38496583}iexplore
old value "Time=DA070C0005001100070037003000A802"
* Modifies value "Count=00000010" in key HKEY_CURRENT_USERsoftwareMicrosoftWindowsCurrentVersionExtStats{FB5F1910-F110-11D2-BB9E-00C04F795683}iexplore
old value "Count=0000000F"
* Modifies value "Time=DA070C000100140008002A0022007C00" in key HKEY_CURRENT_USERsoftwareMicrosoftWindowsCurrentVersionExtStats{FB5F1910-F110-11D2-BB9E-00C04F795683}iexplore
old value "Time=DA070C0005001100070037003000A802"
* Creates value "CachePath=25005500530045005200500052004F00460049004C00450025005C004C006F00630061006C002000530065007400740069006E00670073005C0048006900730074006F00720079005C0048006900730074006F00720079002E004900450035005C004D00530048006900730074003000310032003000310030003100320031003300320030003100300031003200320030005C000000" in key HKEY_CURRENT_USERsoftwareMicrosoftWindowsCurrentVersionInternet Settings5.0CacheExtensible CacheMSHist012010121320101220
* Creates value "CachePrefix=:2010121320101220: " in key HKEY_CURRENT_USERsoftwareMicrosoftWindowsCurrentVersionInternet Settings5.0CacheExtensible CacheMSHist012010121320101220
* Creates value "CacheLimit=00200000" in key HKEY_CURRENT_USERsoftwareMicrosoftWindowsCurrentVersionInternet Settings5.0CacheExtensible CacheMSHist012010121320101220
* Creates value "CacheOptions=0B000000" in key HKEY_CURRENT_USERsoftwareMicrosoftWindowsCurrentVersionInternet Settings5.0CacheExtensible CacheMSHist012010121320101220
* Deletes Registry key HKEY_CURRENT_USERsoftwareMicrosoftWindowsCurrentVersionInternet Settings5.0CacheExtensible CacheMSHist012010121420101215
* Deletes Registry key HKEY_CURRENT_USERsoftwareMicrosoftWindowsCurrentVersionInternet Settings5.0CacheExtensible CacheMSHist012010121620101217
* Creates value "CachePath=25005500530045005200500052004F00460049004C00450025005C004C006F00630061006C002000530065007400740069006E00670073005C0048006900730074006F00720079005C0048006900730074006F00720079002E004900450035005C004D00530048006900730074003000310032003000310030003100320032003000320030003100300031003200320031005C000000" in key HKEY_CURRENT_USERsoftwareMicrosoftWindowsCurrentVersionInternet Settings5.0CacheExtensible CacheMSHist012010122020101221
* Creates value "CachePrefix=:2010122020101221: " in key HKEY_CURRENT_USERsoftwareMicrosoftWindowsCurrentVersionInternet Settings5.0CacheExtensible CacheMSHist012010122020101221
* Creates value "CacheLimit=00200000" in key HKEY_CURRENT_USERsoftwareMicrosoftWindowsCurrentVersionInternet Settings5.0CacheExtensible CacheMSHist012010122020101221
* Creates value "CacheOptions=0B000000" in key HKEY_CURRENT_USERsoftwareMicrosoftWindowsCurrentVersionInternet Settings5.0CacheExtensible CacheMSHist012010122020101221
* Modifies value "SavedLegacySettings=3C00000020000000010000000000000000000000000000000400000000000000A0C4FAAF62D0CA0101000000AC10268B0000000000000000" in key HKEY_CURRENT_USERsoftwareMicrosoftWindowsCurrentVersionInternet SettingsConnections
old value "SavedLegacySettings=3C0000001E000000010000000000000000000000000000000400000000000000A0C4FAAF62D0CA0101000000AC10268B0000000000000000"
* Creates value "NVIDIA driver monitor=c:windowsnvsvc32.exe" in key HKEY_CURRENT_USERsoftwareMicrosoftWindowsCurrentVersionRun
* Modifies value "MRUListEx=02000000010000000800000016000000170000000F0000000D0000001500000014000000130000001200000010000000110000000300000000000000050000000E0000000C0000000B0000000A00000009000000070000000600000004000000FFFFFFFF" in key HKEY_CURRENT_USERsoftwareMicrosoftWindowsShellNoRoamBagMRU
old value "MRUListEx=01000000020000000800000016000000170000000F0000000D0000001500000014000000130000001200000010000000110000000300000000000000050000000E0000000C0000000B0000000A00000009000000070000000600000004000000FFFFFFFF"
* Modifies value "WinPos1286x734(1).left=00000062" in key HKEY_CURRENT_USERsoftwareMicrosoftWindowsShellNoRoamBags8Shell
old value "WinPos1286x734(1).left=000000A0"
* Modifies value "WinPos1286x734(1).top=00000092" in key HKEY_CURRENT_USERsoftwareMicrosoftWindowsShellNoRoamBags8Shell
old value empty
* Modifies value "WinPos1286x734(1).right=00000359" in key HKEY_CURRENT_USERsoftwareMicrosoftWindowsShellNoRoamBags8Shell
old value "WinPos1286x734(1).right=00000397"
* Modifies value "WinPos1286x734(1).bottom=00000341" in key HKEY_CURRENT_USERsoftwareMicrosoftWindowsShellNoRoamBags8Shell
old value "WinPos1286x734(1).bottom=000002AF"
* Deletes Registry key HKEY_CURRENT_USERsoftwareclasses*shellsandbox
[ Network services ]
* Looks for an Internet connection.
* Backdoor functionality on port 0.
* Queries DNS astro.ic.ac.uk
* Queries DNS ale.pakibili.com
* Queries DNS versatek.com
* Queries DNS journalofaccountancy.com
* Queries DNS transnationale.org
* Queries DNS browseusers.myspace.com
* Queries DNS mas.0730ip.com
* Queries DNS www.myspace.com
* Queries DNS ds.phoenix-cc.net
* Queries DNS stayontime.info
* Queries DNS www.shearman.com
* Queries DNS insidehighered.com
* Queries DNS ate.lacoctelera.net
* Queries DNS websitetrafficspy.com
* Queries DNS qun.51.com
* Queries DNS x.myspacecdn.com
* Queries DNS www.facebook.com
* Queries DNS summer-uni-sw.eesp.ch
* Queries DNS shopstyle.com
* Queries DNS xxx.stopklatka.pl
* Queries DNS xxx.stopklatka.pl.localdomain
* Connects to "63.135.80.224" on port 80 (TCP - HTTP).
* Connects to "63.135.80.46" on port 80 (TCP - HTTP).
* Connects to "205.234.253.15" on port 1234 (TCP).
* Connects to "46.40.191.11" on port 80 (TCP - HTTP).
* Connects to "66.220.158.18" on port 80 (TCP - HTTP).
* Connects to "174.37.200.82" on port 80 (TCP - HTTP).
* Opens next URLs:
https://174.37.200.82/index.php
[ Process/window information ]
* Keylogger functionality.
* Creates process "(null),net stop ,(null)".
* Injects code into process "net.exe".
* Creates a mutex "SHIMLIB_LOG_MUTEX".
* Creates an event named "DINPUTWINMM".
* Creates an event named "Globaluserenv: User Profile setup event".
* Creates process "(null),net1 stop ,(null)".
* Injects code into process "net1.exe".
* Creates process "(null),C:Documents and SettingsAdministratorDesktopimage96523489.exe,(null)".
* Injects code into process "image96523489.exe".
* Creates an event named "Globalcrypt32LogoffEvent".
* Creates a mutex "Nvidia Drive Mon".
* Creates a mutex "_!MSFTHISTORY!_".
* Creates a mutex "c:!documents and settings!administrator!local settings!temporary internet files!content.ie5!".
* Creates a mutex "c:!documents and settings!administrator!cookies!".
* Creates a mutex "c:!documents and settings!administrator!local settings!history!history.ie5!".
* Creates process "(null),netsh firewall add allowedprogram 1.exe 1 ENABLE,(null)".
* Creates process "c:windowsnvsvc32.exe,(null),c:windows".
* Creates process "(null),explorer.exe https://browseusers.myspace.com/Browse/Browse.aspx,(null)".
* Injects code into process "explorer.exe".
* Opens a service named "ShellHWDetection".
* Creates process "(null),C:windowsnvsvc32.exe,(null)".
* Injects code into process "nvsvc32.exe".
* Injects code into process "iexplore.exe".
* Creates a mutex "Shell.CMruPidlList".
* Creates process "(null),net stop wuauserv,(null)".
* Creates a mutex "RasPbFile".
* Creates a mutex "ZonesCounterMutex".
* Creates a mutex "ZonesCacheCounterMutex".
* Creates a mutex "ZonesLockedCacheCounterMutex".
* Creates a mutex "oleacc-msaa-loaded".
* Creates process "(null),net stop MsMpSvc,(null)".
* Enumerates running processes.
* Creates process "(null),sc config wuauserv start= disabled,(null)".
* Opens a service named "RASMAN".
* Creates process "(null),sc config MsMpSvc start= disabled,(null)".
* Injects code into process "sc.exe".
* Creates process "(null),net1 stop wuauserv,(null)".
* Creates process "(null),net1 stop MsMpSvc,(null)".
* Opens a service named "wuauserv".
* Opens a service named "MsMpSvc".
* Lists all entry names in a remote access phone book.
* Injects code into process "netsh.exe".
* Creates a mutex "CTF.LBES.MutexDefaultS-1-5-21-1078081533-1677128483-1801674531-500".
* Creates a mutex "CTF.Compart.MutexDefaultS-1-5-21-1078081533-1677128483-1801674531-500".
* Creates a mutex "CTF.Asm.MutexDefaultS-1-5-21-1078081533-1677128483-1801674531-500".
* Creates a mutex "CTF.Layouts.MutexDefaultS-1-5-21-1078081533-1677128483-1801674531-500".
* Creates a mutex "CTF.TMD.MutexDefaultS-1-5-21-1078081533-1677128483-1801674531-500".
* Opens a service named "NapAgent".
* Creates a mutex "_!SHMSFTHISTORY!_".
* Creates a mutex "c:!documents and settings!administrator!local settings!history!history.ie5!mshist012010121420101215!".
* Creates a mutex "c:!documents and settings!administrator!local settings!history!history.ie5!mshist012010121320101220!".
* Creates a mutex "c:!documents and settings!administrator!local settings!history!history.ie5!mshist012010121620101217!".
* Creates a mutex "c:!documents and settings!administrator!local settings!history!history.ie5!mshist012010122020101221!".
* Creates a mutex "HGFSMUTEX".
* Opens a service named "WebClient".
* Creates a mutex "Globalwinlogon: Logon UserProfileMapping Mutex".
* Creates a mutex "_SHuassist.mtx".
* Opens a service named "AudioSrv".
* Creates a mutex "MidiMapper_modLongMessage_RefCnt".
* Creates a mutex "MidiMapper_Configure".

Introduction i-SOON (上海安洵), a prominent contractor for various Chinese government agencies such […]
When I saw a threat actor hijacking the X account of Google's […]
LOCKBIT 3.0 is a notorious Ransomware Group that was first identified on […]