<?xml version="1.0" encoding="us-ascii"?>
<ioc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" id="d3b52fea-5020-469c-97f8-b23bf4954751" last-modified="2012-06-12T15:11:31" xmlns="http://schemas.mandiant.com/2010/ioc">
  <short_description>htmlba64crew</short_description>
  <description>htmlba64crew</description>
  <authored_by>Jaime Blasco</authored_by>
  <authored_date>2012-06-12T14:36:11</authored_date>
  <links />
  <definition>
    <Indicator operator="OR" id="7a8c591b-e1ff-4a59-bec1-21648f9dfd09">
      <Indicator operator="AND" id="1232ab07-02c9-4e22-b05f-18df3b585bab">
        <IndicatorItem id="1957a88e-8ea4-46ae-9bf4-80ea349d5e12" condition="contains">
          <Context document="FileItem" search="FileItem/FullPath" type="mir" />
          <Content type="string">\LOCALS~1\Temp\</Content>
        </IndicatorItem>
        <Indicator operator="OR" id="7f89c9b1-cc29-4c7c-81eb-ccbbb9eb4f18">
          <IndicatorItem id="b34cf274-711d-4139-8631-5f1162fd19c4" condition="contains">
            <Context document="FileItem" search="FileItem/FileName" type="mir" />
            <Content type="string">spoolsvr.exe</Content>
          </IndicatorItem>
          <IndicatorItem id="b18538f5-2e28-4ffe-b9fe-63e48040fec8" condition="contains">
            <Context document="FileItem" search="FileItem/FileName" type="mir" />
            <Content type="string">svchost.exe</Content>
          </IndicatorItem>
          <IndicatorItem id="b62edd87-9138-4097-bd43-50381e95225f" condition="contains">
            <Context document="FileItem" search="FileItem/FileName" type="mir" />
            <Content type="string">wins.exe</Content>
          </IndicatorItem>
        </Indicator>
      </Indicator>
      <Indicator operator="AND" id="689e8dc6-bc27-48a7-a773-05acc821c5ce">
        <IndicatorItem id="6af36972-bd12-4770-98c0-87099593a3b5" condition="contains">
          <Context document="RegistryItem" search="RegistryItem/Path" type="mir" />
          <Content type="string">SOFTWARE\Microsoft\Windows\CurrentVersion\Run</Content>
        </IndicatorItem>
        <IndicatorItem id="c562dd34-a403-404a-ba50-70733091a894" condition="contains">
          <Context document="RegistryItem" search="RegistryItem/Text" type="mir" />
          <Content type="string">load</Content>
        </IndicatorItem>
        <IndicatorItem id="21f18faa-0476-4e7e-8431-9268d315a2fd" condition="contains">
          <Context document="RegistryItem" search="RegistryItem/Value" type="mir" />
          <Content type="string">\LOCALS~1\Temp\</Content>
        </IndicatorItem>
        <Indicator operator="OR" id="8c1e6073-2927-4e32-99e5-19e92e48dc30">
          <IndicatorItem id="9670d531-cf04-48b2-b265-d441b5616280" condition="contains">
            <Context document="RegistryItem" search="RegistryItem/Value" type="mir" />
            <Content type="string">spoolsvr.exe</Content>
          </IndicatorItem>
          <IndicatorItem id="5b6d98ca-0b56-4cb3-bd9b-f4ef3a666eea" condition="contains">
            <Context document="RegistryItem" search="RegistryItem/Path" type="mir" />
            <Content type="string">svchost.exe</Content>
          </IndicatorItem>
          <IndicatorItem id="f2051465-757b-4988-8bc4-ad2de2b008e8" condition="contains">
            <Context document="RegistryItem" search="RegistryItem/Path" type="mir" />
            <Content type="string">wins.exe</Content>
          </IndicatorItem>
        </Indicator>
      </Indicator>
      <Indicator operator="OR" id="9b5fea3a-e9db-4b61-88a1-902ce095c258">
        <IndicatorItem id="05ff11bb-22d2-489a-bd24-8421b7f53c8e" condition="is">
          <Context document="Network" search="Network/DNS" type="network" />
          <Content type="string">hint.happyforever.com</Content>
        </IndicatorItem>
        <IndicatorItem id="7ad41911-7a3b-43fa-b508-3dfdfa08526d" condition="is">
          <Context document="Network" search="Network/DNS" type="network" />
          <Content type="string">update.slowblog.com</Content>
        </IndicatorItem>
        <IndicatorItem id="5717f73d-b61b-4af6-845b-db48d4967b1c" condition="is">
          <Context document="Network" search="Network/DNS" type="network" />
          <Content type="string">report.crabdance.com</Content>
        </IndicatorItem>
      </Indicator>
      <Indicator operator="OR" id="8bd15edb-5a9f-4170-8f36-557c2a132b3f">
        <IndicatorItem id="5f71a84a-c49a-4a96-80fd-52c016addefe" condition="is">
          <Context document="PortItem" search="PortItem/remoteIP" type="mir" />
          <Content type="IP">1.234.1.68</Content>
        </IndicatorItem>
        <IndicatorItem id="204f2ddd-0c45-42a3-bdf1-a4bddc603372" condition="is">
          <Context document="PortItem" search="PortItem/remoteIP" type="mir" />
          <Content type="IP">128.175.21.189</Content>
        </IndicatorItem>
        <IndicatorItem id="bb994671-d0f9-40c1-a5fe-89a989d0e53c" condition="is">
          <Context document="PortItem" search="PortItem/remoteIP" type="mir" />
          <Content type="IP">143.89.35.7</Content>
        </IndicatorItem>
        <IndicatorItem id="a933fac6-481d-406e-82de-b90947edb9f0" condition="is">
          <Context document="PortItem" search="PortItem/remoteIP" type="mir" />
          <Content type="IP">173.10.48.242</Content>
        </IndicatorItem>
        <IndicatorItem id="944c9214-6d2e-4638-8776-aab0881734a6" condition="is">
          <Context document="PortItem" search="PortItem/remoteIP" type="mir" />
          <Content type="IP">203.200.205.245</Content>
        </IndicatorItem>
        <IndicatorItem id="4cc240f9-eda6-4345-8423-3844638c434e" condition="is">
          <Context document="PortItem" search="PortItem/remoteIP" type="mir" />
          <Content type="IP">203.231.234.23</Content>
        </IndicatorItem>
        <IndicatorItem id="674ff552-0b00-4176-b7c4-d92df1ce8698" condition="is">
          <Context document="PortItem" search="PortItem/remoteIP" type="mir" />
          <Content type="IP">210.249.80.141</Content>
        </IndicatorItem>
        <IndicatorItem id="9cceed80-7c32-4862-9492-7c25e318c1c2" condition="is">
          <Context document="PortItem" search="PortItem/remoteIP" type="mir" />
          <Content type="IP">74.93.92.50</Content>
        </IndicatorItem>
      </Indicator>
      <Indicator operator="AND" id="9923a43f-8332-467c-af39-e1ae55f21dff">
        <IndicatorItem id="c050cc46-6fbc-48df-99d4-2c2354b8f2ff" condition="contains">
          <Context document="FileItem" search="FileItem/StringList/string" type="mir" />
          <Content type="string">releaseexe</Content>
        </IndicatorItem>
        <IndicatorItem id="27094186-28a1-4d46-991c-fab5ab577070" condition="contains">
          <Context document="FileItem" search="FileItem/StringList/string" type="mir" />
          <Content type="string">sleep:</Content>
        </IndicatorItem>
        <IndicatorItem id="ce6aeb5c-cb9a-47ee-971c-7ca19580d947" condition="contains">
          <Context document="FileItem" search="FileItem/StringList/string" type="mir" />
          <Content type="string">content=</Content>
        </IndicatorItem>
        <IndicatorItem id="53e1001a-bfbc-4fe1-8985-8737a1f0236a" condition="contains">
          <Context document="FileItem" search="FileItem/StringList/string" type="mir" />
          <Content type="string">download</Content>
        </IndicatorItem>
        <IndicatorItem id="878c150f-957b-4092-9b25-20500e927797" condition="contains">
          <Context document="FileItem" search="FileItem/StringList/string" type="mir" />
          <Content type="string">reqpath=</Content>
        </IndicatorItem>
        <IndicatorItem id="def3ba62-3a28-4ef7-a590-32e0b6360e51" condition="contains">
          <Context document="FileItem" search="FileItem/StringList/string" type="mir" />
          <Content type="string">command=</Content>
        </IndicatorItem>
      </Indicator>
      <Indicator operator="AND" id="3a4df0c1-62c4-475b-98dc-6239b2e7b6ab">
        <IndicatorItem id="333e15cb-3408-464f-a8e6-2ed5b8445dc7" condition="contains">
          <Context document="FileItem" search="FileItem/StringList/string" type="mir" />
          <Content type="string">sleep:</Content>
        </IndicatorItem>
        <IndicatorItem id="f7958de4-b3d1-4c2a-b5f0-8422ebcb6862" condition="contains">
          <Context document="FileItem" search="FileItem/StringList/string" type="mir" />
          <Content type="string">downloadcopy:</Content>
        </IndicatorItem>
        <IndicatorItem id="28c20b8a-0fb7-4042-8a70-c7359ce06c53" condition="contains">
          <Context document="FileItem" search="FileItem/StringList/string" type="mir" />
          <Content type="string">download:</Content>
        </IndicatorItem>
        <IndicatorItem id="9b5d64f8-043b-4854-8e4a-105a1b6da267" condition="contains">
          <Context document="FileItem" search="FileItem/StringList/string" type="mir" />
          <Content type="string">geturl:</Content>
        </IndicatorItem>
      </Indicator>
    </Indicator>
  </definition>
</ioc>