Requested Host:
Resulting Address:

* IRC Data
o User Name: zgtlat
o Host Name: “”
o Server Name:
o Real Name: zgtlat
o Password: dickybob
o Nick Name: ncrrpk
o Non RFC Conform: 1
+ Channel

# Name: #ohai3
# Password: trb123trb
+ Notice Message Deleted
# Value: NOTICE AUTH :*** Looking up your hostname…
# Value: NOTICE AUTH :*** Couldn’t resolve your hostname; using your IP address instead

chanel #usb for spreading mesages

# Transport Protocol: TCP
# Remote Address:
# Remote Port: 6667
# Protocol: IRC
PASS dickybob

Joins: ohobwi [qnxgvg@52F1439E.1B24B74B.5FCC8487.IP]
Quits: cwjlgw [nngsix@4AC25E0E.E3C4C12B.345AC400.IP] (Ping timeout)
Joins: Anddosd []
Joins: hhpsvr [nvombw@4AC25E0E.E3C4C12B.345AC400.IP]
Quits: cwsanv [kqnxeh@35D5518B.EFB4043E.560DCF0A.IP] (Ping timeout)

Invisible Users: 599
Channels: 21 channels formed
Clients: I have 612 clients and 0 servers
Local users: Current Local Users: 612 Max: 655
Global users: Current Global Users: 612 Max: 655

File System Modifications

The following files were created in the system:

# Filename(s) File Size File MD5
1 c:RECYCLERS-1-5-21-1482476501-1644491937-682003330-1013Desktop.ini 62 bytes 0x7457A5DF1FF47C957ACF1FA000D7D9AD
2 c:RECYCLERS-1-5-21-1482476501-1644491937-682003330-1013svchost.exe
[file and pathname of the sample #1] 143,360 bytes 0x167B0F3DF365BCB5B239197A3F49F485

The following directory was created:

Registry Modifications

The following Registry Key was created:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftActive SetupInstalled Components{28ABC5C0-4FCB-11CF-AAX5-81CX1C635612}
The newly created Registry Value is:
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftActive SetupInstalled Components{28ABC5C0-4FCB-11CF-AAX5-81CX1C635612}]
StubPath = “c:RECYCLERS-1-5-21-1482476501-1644491937-682003330-1013svchost.exe”

so that svchost.exe runs every time Windows starts

Host Name IP Address
Download URLs (

* C&C Server:
* Server Password:
* Username: erppma
* Nickname: ruxull
* Channel: #ohai3 (Password: trb123trb)
* Channeltopic: :.dl c:p.exe 1

Outgoing connection to remote server: TCP port 80

