anubis left
Anubis - Analysis Report
anubis right

Analysis Report for ma.exe

Comment on this report

Summary:

Description Risk
Autostart capabilities: This executable registers processes to be executed at system start. This could result in unwanted actions to be performed automatically. medium
Creates files in the Windows system directory: Malware often keeps copies of itself in the Windows directory to stay undetected by users. medium
Performs File Modification and Destruction: The executable modifies and destructs files which are not temporary. high
Performs Registry Activities: The executable reads and modifies registry values. It may also create and monitor registry keys. low


Table of Contents

expand all expand all   collapse all collapse all

1. General Information

  - Information about Anubis' invocation  
Time needed: 241 s 
Report created: 05/09/09, 00:02:40 UTC 
Termination reason: Timeout 
Program version: 1.67.0 

1.a) - Network Activity

  -  Unknown UDP Traffic:  
from ANUBIS:1025 to 192.168.0.1:53
State: Normal establishment and termination - Transferred outbound Bytes: 136 - Transferred inbound Bytes: 675

2. sample.exe

  - General information about this executable  
Analysis Reason: Primary Analysis Subject 
Filename: sample.exe 
MD5: 52ed7ae99a6db1adb2a3910a0af70ebe 
SHA-1: c59f1b80d4b36a6e8a222c9618a62880a5247711 
File Size: 46080 Bytes
Command Line: "C:\sample.exe" 
Process-status at analysis end: dead 
Exit Code:

  - Load-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​ntdll.dll  0x7C900000  0x000AF000 
C:\​WINDOWS\​system32\​kernel32.dll  0x7C800000  0x000F6000 
C:\​WINDOWS\​system32\​wsock32.dll  0x71AD0000  0x00009000 
C:\​WINDOWS\​system32\​WS2_32.dll  0x71AB0000  0x00017000 
C:\​WINDOWS\​system32\​ADVAPI32.dll  0x77DD0000  0x0009B000 
C:\​WINDOWS\​system32\​RPCRT4.dll  0x77E70000  0x00092000 
C:\​WINDOWS\​system32\​Secur32.dll  0x77FE0000  0x00011000 
C:\​WINDOWS\​system32\​msvcrt.dll  0x77C10000  0x00058000 
C:\​WINDOWS\​system32\​WS2HELP.dll  0x71AA0000  0x00008000 
C:\​WINDOWS\​system32\​user32.dll  0x7E410000  0x00091000 
C:\​WINDOWS\​system32\​GDI32.dll  0x77F10000  0x00049000 
C:\​WINDOWS\​system32\​IMM32.DLL  0x76390000  0x0001D000 

  - Ikarus Virus Scanner  
Trojan.Win32.Inject (Sig-Id:463978)

2.a) sample.exe - Registry Activities

  - Registry Values Deleted:  
Key Name
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​URL  SystemMgr 

  - Registry Values Modified:  
Key Name New Value
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​URL  SystemMgr  Del 

  - Registry Values Read:  
Key Name Value Times
HKLM\​System\​CurrentControlSet\​Control\​ComputerName\​ActiveComputerName  ComputerName  USER 

2.b) sample.exe - File Activities

  - Files Created:  
C:\WINDOWS\system32\zzeab.exe

  - Files Read:  
C:\sample.exe
PIPE\lsarpc

  - Files Modified:  
C:\WINDOWS\system32\zzeab.exeinfo
PIPE\lsarpcinfo

  - File System Control Communication:  
File Control Code Times
PIPE\lsarpc  0x0011C017 

2.c) sample.exe - Process Activities

  - Remote Threads Created:  
Affected Process
C:\WINDOWS\explorer.exe

  - Thread Overview:  
Time Number of threads
After 13 seconds
After 14 seconds
After 17 seconds
After 81 seconds

  - Foreign Memory Regions Written:  
Process: C:\WINDOWS\explorer.exe

2.d) sample.exe - Other Activities

  - Windows SEH exceptions:  
Description Times
Exception 0x80000003 (STATUS_BREAKPOINT) at 0x40b10c 
Exception 0x80000003 (STATUS_BREAKPOINT) at 0x40ad5a  64 
Exception 0x80000003 (STATUS_BREAKPOINT) at 0x40aad8 
Exception 0x80000003 (STATUS_BREAKPOINT) at 0x40a6c8 
Exception 0x80000003 (STATUS_BREAKPOINT) at 0x40a583 
Exception 0xc0000005 (STATUS_ACCESS_VIOLATION) at 0x4a8e670d 
Exception 0x80000003 (STATUS_BREAKPOINT) at 0x40a437 
Exception 0x80000003 (STATUS_BREAKPOINT) at 0x40a16a 
Exception 0x80000003 (STATUS_BREAKPOINT) at 0x40a2db 
Exception 0x80000003 (STATUS_BREAKPOINT) at 0x40a962 

3. Explorer.EXE

  - General information about this executable  
Analysis Reason: sample.exe injected a remote thread into this process 
Filename: Explorer.EXE 
MD5: 12896823fb95bfb3dc9b46bcaedc9923 
SHA-1: 9d2bf84874abc5b6e9a2744b7865c193c08d362f 
File Size: 1033728 Bytes
Command Line: C:\WINDOWS\Explorer.EXE 
Process-status at analysis end: alive 
Exit Code:

  - Load-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​ntdll.dll  0x7C900000  0x000AF000 
C:\​WINDOWS\​system32\​kernel32.dll  0x7C800000  0x000F6000 
C:\​WINDOWS\​system32\​ADVAPI32.dll  0x77DD0000  0x0009B000 
C:\​WINDOWS\​system32\​RPCRT4.dll  0x77E70000  0x00092000 
C:\​WINDOWS\​system32\​Secur32.dll  0x77FE0000  0x00011000 
C:\​WINDOWS\​system32\​BROWSEUI.dll  0x75F80000  0x000FD000 
C:\​WINDOWS\​system32\​GDI32.dll  0x77F10000  0x00049000 
C:\​WINDOWS\​system32\​USER32.dll  0x7E410000  0x00091000 
C:\​WINDOWS\​system32\​msvcrt.dll  0x77C10000  0x00058000 
C:\​WINDOWS\​system32\​ole32.dll  0x774E0000  0x0013D000 
C:\​WINDOWS\​system32\​SHLWAPI.dll  0x77F60000  0x00076000 
C:\​WINDOWS\​system32\​OLEAUT32.dll  0x77120000  0x0008B000 
C:\​WINDOWS\​system32\​SHDOCVW.dll  0x7E290000  0x00171000 
C:\​WINDOWS\​system32\​CRYPT32.dll  0x77A80000  0x00095000 
C:\​WINDOWS\​system32\​MSASN1.dll  0x77B20000  0x00012000 
C:\​WINDOWS\​system32\​CRYPTUI.dll  0x754D0000  0x00080000 
C:\​WINDOWS\​system32\​NETAPI32.dll  0x5B860000  0x00055000 
C:\​WINDOWS\​system32\​VERSION.dll  0x77C00000  0x00008000 
C:\​WINDOWS\​system32\​WININET.dll  0x42C10000  0x000CF000 
C:\​WINDOWS\​system32\​Normaliz.dll  0x00400000  0x00009000 
C:\​WINDOWS\​system32\​iertutil.dll  0x42990000  0x00045000 
C:\​WINDOWS\​system32\​WINTRUST.dll  0x76C30000  0x0002E000 
C:\​WINDOWS\​system32\​IMAGEHLP.dll  0x76C90000  0x00028000 
C:\​WINDOWS\​system32\​WLDAP32.dll  0x76F60000  0x0002C000 
C:\​WINDOWS\​system32\​SHELL32.dll  0x7C9C0000  0x00817000 
C:\​WINDOWS\​system32\​UxTheme.dll  0x5AD70000  0x00038000 
C:\​WINDOWS\​system32\​ShimEng.dll  0x5CB70000  0x00026000 
C:\​WINDOWS\​AppPatch\​AcGenral.DLL  0x6F880000  0x001CA000 
C:\​WINDOWS\​system32\​WINMM.dll  0x76B40000  0x0002D000 
C:\​WINDOWS\​system32\​MSACM32.dll  0x77BE0000  0x00015000 
C:\​WINDOWS\​system32\​USERENV.dll  0x769C0000  0x000B4000 
C:\​WINDOWS\​system32\​IMM32.DLL  0x76390000  0x0001D000 
C:\​WINDOWS\​WinSxS\​x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\​comctl32.dll  0x773D0000  0x00103000 
C:\​WINDOWS\​system32\​comctl32.dll  0x5D090000  0x0009A000 
C:\​WINDOWS\​system32\​msctfime.ime  0x755C0000  0x0002E000 
C:\​WINDOWS\​system32\​appHelp.dll  0x77B40000  0x00022000 
C:\​WINDOWS\​system32\​CLBCATQ.DLL  0x76FD0000  0x0007F000 
C:\​WINDOWS\​system32\​COMRes.dll  0x77050000  0x000C5000 
C:\​WINDOWS\​System32\​cscui.dll  0x77A20000  0x00054000 
C:\​WINDOWS\​System32\​CSCDLL.dll  0x76600000  0x0001D000 
C:\​WINDOWS\​system32\​themeui.dll  0x5BA60000  0x00071000 
C:\​WINDOWS\​system32\​MSIMG32.dll  0x76380000  0x00005000 
C:\​WINDOWS\​system32\​xpsp2res.dll  0x01100000  0x002C5000 
C:\​WINDOWS\​system32\​actxprxy.dll  0x71D40000  0x0001B000 
C:\​WINDOWS\​system32\​SAMLIB.dll  0x71BF0000  0x00013000 
C:\​WINDOWS\​system32\​SETUPAPI.dll  0x77920000  0x000F3000 
C:\​WINDOWS\​system32\​msi.dll  0x7D1E0000  0x002BC000 
C:\​WINDOWS\​system32\​ntshrui.dll  0x76990000  0x00025000 
C:\​WINDOWS\​system32\​ATL.DLL  0x76B20000  0x00011000 
C:\​WINDOWS\​system32\​ieframe.dll  0x42EF0000  0x005CD000 
C:\​WINDOWS\​system32\​PSAPI.DLL  0x76BF0000  0x0000B000 
C:\​WINDOWS\​system32\​LINKINFO.dll  0x76980000  0x00008000 
C:\​WINDOWS\​system32\​NETSHELL.dll  0x76400000  0x001A5000 
C:\​WINDOWS\​system32\​credui.dll  0x76C00000  0x0002E000 
C:\​WINDOWS\​system32\​dot3api.dll  0x478C0000  0x0000A000 
C:\​WINDOWS\​system32\​rtutils.dll  0x76E80000  0x0000E000 
C:\​WINDOWS\​system32\​dot3dlg.dll  0x736D0000  0x00006000 
C:\​WINDOWS\​system32\​OneX.DLL  0x5DCA0000  0x00028000 
C:\​WINDOWS\​system32\​WTSAPI32.dll  0x76F50000  0x00008000 
C:\​WINDOWS\​system32\​WINSTA.dll  0x76360000  0x00010000 
C:\​WINDOWS\​system32\​eappcfg.dll  0x745B0000  0x00022000 
C:\​WINDOWS\​system32\​MSVCP60.dll  0x76080000  0x00065000 
C:\​WINDOWS\​system32\​eappprxy.dll  0x5DCD0000  0x0000E000 
C:\​WINDOWS\​system32\​iphlpapi.dll  0x76D60000  0x00019000 
C:\​WINDOWS\​system32\​WS2_32.dll  0x71AB0000  0x00017000 
C:\​WINDOWS\​system32\​WS2HELP.dll  0x71AA0000  0x00008000 
C:\​WINDOWS\​system32\​urlmon.dll  0x42CF0000  0x00127000 
C:\​WINDOWS\​system32\​webcheck.dll  0x42E40000  0x0003C000 
C:\​WINDOWS\​system32\​stobject.dll  0x76280000  0x00021000 
C:\​WINDOWS\​system32\​BatMeter.dll  0x74AF0000  0x0000A000 
C:\​WINDOWS\​system32\​POWRPROF.dll  0x74AD0000  0x00008000 
C:\​WINDOWS\​system32\​WPDShServiceObj.dll  0x164A0000  0x00023000 
C:\​WINDOWS\​system32\​WINHTTP.dll  0x4D4F0000  0x00059000 
C:\​WINDOWS\​system32\​mydocs.dll  0x72410000  0x0001A000 
C:\​WINDOWS\​system32\​PortableDeviceTypes.dll  0x109C0000  0x0002C000 
C:\​WINDOWS\​system32\​PortableDeviceApi.dll  0x10930000  0x00049000 
C:\​WINDOWS\​system32\​MSCTF.dll  0x74720000  0x0004C000 
C:\​WINDOWS\​system32\​SXS.DLL  0x7E720000  0x000B0000 
C:\​WINDOWS\​system32\​MPR.dll  0x71B20000  0x00012000 
C:\​WINDOWS\​System32\​drprov.dll  0x75F60000  0x00007000 
C:\​WINDOWS\​System32\​ntlanman.dll  0x71C10000  0x0000E000 
C:\​WINDOWS\​System32\​NETUI0.dll  0x71CD0000  0x00017000 
C:\​WINDOWS\​System32\​NETUI1.dll  0x71C90000  0x00040000 
C:\​WINDOWS\​System32\​NETRAP.dll  0x71C80000  0x00007000 
C:\​WINDOWS\​System32\​davclnt.dll  0x75F70000  0x0000A000 
C:\​WINDOWS\​system32\​browselc.dll  0x71600000  0x00012000 
C:\​WINDOWS\​system32\​MSGINA.dll  0x75970000  0x000F8000 
C:\​WINDOWS\​system32\​ODBC32.dll  0x74320000  0x0003D000 
C:\​WINDOWS\​system32\​comdlg32.dll  0x763B0000  0x00049000 
C:\​WINDOWS\​system32\​odbcint.dll  0x02310000  0x00017000 
C:\​WINDOWS\​system32\​MLANG.dll  0x75CF0000  0x00091000 
C:\​WINDOWS\​system32\​rsaenh.dll  0x68000000  0x00036000 

  - Run-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​hnetcfg.dll  0x662B0000  0x00058000 
C:\​WINDOWS\​System32\​mswsock.dll  0x71A50000  0x0003F000 
C:\​WINDOWS\​System32\​wshtcpip.dll  0x71A90000  0x00008000 
C:\​WINDOWS\​system32\​DNSAPI.dll  0x76F20000  0x00027000 
C:\​WINDOWS\​System32\​winrnr.dll  0x76FB0000  0x00008000 
C:\​WINDOWS\​system32\​rasadhlp.dll  0x76FC0000  0x00006000 

3.a) Explorer.EXE - Registry Activities

  - Registry Values Modified:  
Key Name New Value
HKLM\​SOFTWARE\​Microsoft\​Windows NT\​CurrentVersion\​Winlogon  info Userinit  C:\​WINDOWS\​system32\​userinit.exe,zzeab.exe 

  - Registry Values Read:  
Key Name Value Times
HKLM\​SYSTEM\​CONTROLSET001\​SERVICES\​TCPIP\​LINKAGE  Bind  0x5c004400650076006900630065005c007b00420032004200350031003000  288 
HKLM\​SYSTEM\​CONTROLSET001\​SERVICES\​WINSOCK2\​PARAMETERS\​NAMESPACE_CATALOG5  Serial_Access_Num 
HKLM\​SYSTEM\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Interfaces\​{B2B51064-BBF5-4528-B62B-E6D62A782874}  DhcpServer  255.255.255.255  288 
HKLM\​SYSTEM\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Interfaces\​{B2B51064-BBF5-4528-B62B-E6D62A782874}  EnableDHCP  144 
HKLM\​SYSTEM\​CurrentControlSet\​Services\​Winsock\​Parameters  Transports  0x5400630070006900700000004e0065007400420049004f00530000000000 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters  Domain   
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters  Hostname  user 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters  UseDomainNameDevolution 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  HelperDllName  %SystemRoot%\​System32\​wshtcpip.dll 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  Mapping  0x0b0000000300000002000000010000000600000002000000010000000000 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  MaxSockaddrLength  16 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  MinSockaddrLength  16 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  UseDelayedAcceptance 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters  WinSock_Registry_Version  2.0 
HKLM\​System\​Setup  SystemSetupInProgress 

  - Monitored Registry Keys:  
Key Name Watch subtree Notify Filter Count
HKLM\​SYSTEM\​CONTROLSET001\​SERVICES\​WINSOCK2\​PARAMETERS\​NAMESPACE_CATALOG5  Key Change 

3.b) Explorer.EXE - File Activities

  - Files Read:  
PIPE\lsarpc

  - Files Modified:  
PIPE\lsarpcinfo
\Device\Afd\Endpointinfo
\Device\NetBT_Tcpip_{B2B51064-BBF5-4528-B62B-E6D62A782874}info
\Device\RasAcdinfo

  - File System Control Communication:  
File Control Code Times
PIPE\lsarpc  0x0011C017 

  - Device Control Communication:  
File Control Code Times
\Device\{B2B51064-BBF5-4528-B62B-E6D62A782874}  0x0017003E  72 
unnamed file  0x00120003  1872 
unnamed file  0x00120040  288 
unnamed file  0x00120090  144 
\Device\NetBT_Tcpip_{B2B51064-BBF5-4528-B62B-E6D62A782874}  0x0021009A  144 
\Device\RasAcd  0x00F14014 
\Device\Afd\Endpoint  AFD_GET_INFO (0x0001207B) 
\Device\Afd\Endpoint  AFD_SET_CONTEXT (0x00012047) 
\Device\Afd\Endpoint  AFD_BIND (0x00012003) 
\Device\Afd\Endpoint  AFD_GET_TDI_HANDLES (0x00012037) 
\Device\Afd\Endpoint  AFD_CONNECT (0x00012007) 
\Device\Afd\Endpoint  AFD_SELECT (0x00012024) 
\Device\Afd\Endpoint  AFD_SEND (0x0001201F) 
\Device\Afd\Endpoint  AFD_RECV (0x00012017) 

  - Memory Mapped Files:  
File Name
C:\WINDOWS\System32\mswsock.dll
C:\WINDOWS\System32\winrnr.dll
C:\WINDOWS\System32\wshtcpip.dll
C:\WINDOWS\system32\DNSAPI.dll
C:\WINDOWS\system32\hnetcfg.dll
C:\WINDOWS\system32\rasadhlp.dll

3.c) Explorer.EXE - Process Activities

  - Foreign Memory Regions Read:  
Process: C:\WINDOWS\explorer.exe

3.d) Explorer.EXE - Network Activity

  - DNS Queries:  
Name Query Type Query Result Successful Protocol
www.suniuqing.com  DNS_TYPE_A  202.109.114.70   
www.china.com  DNS_TYPE_A     
www.microsoft.com  DNS_TYPE_A     

  -  HTTP Conversations:  
From ANUBIS:1032 to 124.238.253.102:80 - [www.china.com]
Request: GET /images/china.gif
Response: 404 "Not Found"
Request: GET /images/china.jpg
Response: 404 "Not Found"
Request: GET /images/china.bmp
Response: 404 "Not Found"

  -  Unknown TCP Traffic:  
from ANUBIS:1033 to 124.238.253.102:80
State: Normal establishment and termination - Transferred outbound Bytes: 217 - Transferred inbound Bytes: 1020
Data sent:
    
4745 5420 2f69 6d61 6765 732f 6368 696e    GET /images/chin
612e 6a70 6720 4854 5450 2f31 2e31 0d0a    a.jpg HTTP/1.1..
4163 6365 7074 3a20 2a2f 2a0d 0a41 6363    Accept: */*..Acc
6570 742d 4c61 6e67 7561 6765 3a20 7a68    ept-Language: zh
2d74 770d 0a41 6363 6570 742d 456e 636f    -tw..Accept-Enco
6469 6e67 3a20 677a 6970 2c20 6465 666c    ding: gzip, defl
6174 650d 0a55 7365 722d 4167 656e 743a    ate..User-Agent:
204d 6f7a 696c 6c61 2f34 2e30 2028 636f     Mozilla/4.0 (co
6d70 6174 6962 6c65 3b20 4d53 4945 2035    mpatible; MSIE 5
2e30 3b20 5769 6e64 6f77 7320 3938 3b20    .0; Windows 98; 
4469 6745 7874 290d 0a48 6f73 743a 2077    DigExt)..Host: w
7777 2e63 6869 6e61 2e63 6f6d 0d0a 436f    ww.china.com..Co
6e6e 6563 7469 6f6e 3a20 4b65 6570 2d41    nnection: Keep-A
6c69 7665 0d0a 0d0a 00                     live.....
Data received:
    
4854 5450 2f31 2e30 2034 3034 204e 6f74    HTTP/1.0 404 Not
2046 6f75 6e64 0d0a 4461 7465 3a20 5361     Found..Date: Sa
742c 2030 3920 4d61 7920 3230 3039 2030    t, 09 May 2009 0
303a 3030 3a32 3520 474d 540d 0a53 6572    0:00:25 GMT..Ser
7665 723a 2041 7061 6368 650d 0a41 6363    ver: Apache..Acc
6570 742d 5261 6e67 6573 3a20 6279 7465    ept-Ranges: byte
730d 0a56 6172 793a 2041 6363 6570 742d    s..Vary: Accept-
456e 636f 6469 6e67 0d0a 436f 6e74 656e    Encoding..Conten
742d 456e 636f 6469 6e67 3a20 677a 6970    t-Encoding: gzip
0d0a 436f 6e74 656e 742d 4c65 6e67 7468    ..Content-Length
3a20 3731 390d 0a43 6f6e 7465 6e74 2d54    : 719..Content-T
7970 653a 2074 6578 742f 6874 6d6c 0d0a    ype: text/html..
582d 4361 6368 653a 204d 4953 5320 6672    X-Cache: MISS fr
6f6d 2063 6163 6865 362e 6368 696e 612e    om cache6.china.
636f 6d0d 0a56 6961 3a20 312e 3020 6361    com..Via: 1.0 ca
6368 6536 2e63 6869 6e61 2e63 6f6d 3a38    che6.china.com:8
3020 2873 7175 6964 2f32 2e36 2e53 5441    0 (squid/2.6.STA
424c 4531 3929 0d0a 436f 6e6e 6563 7469    BLE19)..Connecti
6f6e 3a20 636c 6f73 650d 0a0d 0a1f 8b08    on: close.......
0000 0000 0000 038d 53cf 6b13 4114 be0b    ........S.k.A...
fe0f d301 2101 b393 1fa6 21bb d91e 4cab    ....!.....!...L.
2d54 5b34 a21e 27bb b3bb a3b3 3b71 7636    -T[4..'.....;qv6
9b58 fac7 140f 4215 a1a4 a054 eaa5 0525    .X....B....T...%
480f 15ea c54b 2f5e 4a4f 0529 3d39 fb23    H....K/^JO.)=9.#
2555 0f5e 76de 7bfb bdf7 bdf7 cdbc d6cc    %U.^v.{.........
fc4a bbf3 7475 0178 d267 60f5 d1ed e5a5    .J..tu.x.g`.....
3680 2584 1ed7 da08 cd77 e6c1 93c5 cebd    6.%......w......
6550 d1ca a023 7010 5249 7980 1942 0bf7    eP...#p.RIy..B..
2180 9e94 3d1d a138 8eb5 b8a6 71e1 a2ce    !...=..8....q...
0334 486a 5592 e4dc 2cc9 a94c cd96 369c    .4HjU...,..L..6.
bb7e ad95 320e 7c16 84e6 3fea 549a cd66    .~..2.|...?.T..f
969e 8109 b693 d327 1283 045d 222f 22da    .......'...]"/".
3761 9b07 9204 b2d4 19f6 0804 56e6 9950    7a..........V..P
9281 4449 b601 2c0f 8b90 48d3 ed56 6b95    ..DI..,...H..Vk.
2a04 28a9 23a9 6464 6efb f4e0 eceb f1f8    *.(.#.ddn.......
d3e1 086c 6c6e 6c2a 280d b066 71bf 8532    ...llnl*(..fq..2
8042 a29c 5a99 5d6e 0f41 2887 8c64 0425    .B..Z.]n.A(..d.%
cca8 1be8 9662 24c2 003e 162e 0df4 b201    .....b$..>......
7ad8 b669 e02a 336d dea6 fd49 5a17 5bcf    z..i.*3m...IZ.[.
5dc1 a3c0 d623 c10a 88f4 50d7 d55c ea14    ]....#....P..\..
0d10 535b 7afa ec6c a337 3080 47a8 eb49    ..S[z..l.70.G..I
bd5a ab27 5e5e ba5a be01 7024 b962 e099    .Z.'^^.Z..p$.b..
9eba 200c 4bda 2706 98ea 8811 47a6 d400    .. .K.'.....G...
4c93 5f26 e16e c859 2455 5282 d433 46c9    L._&.n.Y$UR..3F.
7b7a a3a9 2c38 d7a2 be0b 4261 9930 6990    {z..,8....Ba.0i.
7197 272d 4280 9992 f652 24b0 bc72 7705    q.'-B....R$..rw.
666d 9bb0 72ab 01f3 ae4d 58af 243a b790    fm..r....MX.$:..
22ff ef2e aaf5 f295 3672 3d6a cd2c fcb7    ".......6r=j.,..
de8e baec 5248 5f12 bd32 9b40 52df c13e    ....RH_..2.@R..>
6543 3da4 7e18 0579 2cce b4ec 7266 2b2e    eC=.~..y,...rf+.
1a90 d244 dd46 3aee ce8f add7 9f3f bc7a    ...D.F:......?.z
bb7f f17e ef60 7c38 dafb 39de 1afd da3e    ...~.`|8..9....>
6d75 45fa 5a00 a8ef 9d1c 7d3b 7ab7 73b6    muE.Z.....};z.s.
fbe6 e3f1 f6f9 fec5 eef9 9793 f1f7 c3d1    ................
cc64 c6cb 33b4 04ed 4920 d57b cc9f e133    .d..3...I .{...3
dcc7 5934 b912 270a ac64 7c40 c3a5 3b02    ..Y4..'..d|@..;.
fbe4 2161 4ea1 b826 c570 8d3a 8598 0636    ..!aN..&.p.:...6
8f35 a502 30cd cc29 ae09 2223 11a8 5ccc    .5..0..).."#..\.
4262 ac13 f5cd 6340 8a48 45d6 2d2c 2daf    Bb....c@.HE.-,-.
408a 7f84 a7e8 245f e43e 5144 40b1 cc5c    @.....$_.>QD@..\
2557 c19c 9771 5549 c135 4f10 475d 3f4c    %W...qUI.5O.G]?L
8be4 3fd5 1675 a84f 7824 0b70 520e deac    ..?..u.Ox$.pR...
97cb e5a2 9128 900d 998a 91ac 4ab6 3d6a    .....(......J.=j
0795 f11b 06f1 8bfb 6904 0000              ........i...
from ANUBIS:1034 to 124.238.253.102:80
State: Normal establishment and termination - Transferred outbound Bytes: 217 - Transferred inbound Bytes: 1020
Data sent:
    
4745 5420 2f69 6d61 6765 732f 6368 696e    GET /images/chin
612e 626d 7020 4854 5450 2f31 2e31 0d0a    a.bmp HTTP/1.1..
4163 6365 7074 3a20 2a2f 2a0d 0a41 6363    Accept: */*..Acc
6570 742d 4c61 6e67 7561 6765 3a20 7a68    ept-Language: zh
2d74 770d 0a41 6363 6570 742d 456e 636f    -tw..Accept-Enco
6469 6e67 3a20 677a 6970 2c20 6465 666c    ding: gzip, defl
6174 650d 0a55 7365 722d 4167 656e 743a    ate..User-Agent:
204d 6f7a 696c 6c61 2f34 2e30 2028 636f     Mozilla/4.0 (co
6d70 6174 6962 6c65 3b20 4d53 4945 2035    mpatible; MSIE 5
2e30 3b20 5769 6e64 6f77 7320 3938 3b20    .0; Windows 98; 
4469 6745 7874 290d 0a48 6f73 743a 2077    DigExt)..Host: w
7777 2e63 6869 6e61 2e63 6f6d 0d0a 436f    ww.china.com..Co
6e6e 6563 7469 6f6e 3a20 4b65 6570 2d41    nnection: Keep-A
6c69 7665 0d0a 0d0a 00                     live.....
Data received:
    
4854 5450 2f31 2e30 2034 3034 204e 6f74    HTTP/1.0 404 Not
2046 6f75 6e64 0d0a 4461 7465 3a20 5361     Found..Date: Sa
742c 2030 3920 4d61 7920 3230 3039 2030    t, 09 May 2009 0
303a 3030 3a32 3720 474d 540d 0a53 6572    0:00:27 GMT..Ser
7665 723a 2041 7061 6368 650d 0a41 6363    ver: Apache..Acc
6570 742d 5261 6e67 6573 3a20 6279 7465    ept-Ranges: byte
730d 0a56 6172 793a 2041 6363 6570 742d    s..Vary: Accept-
456e 636f 6469 6e67 0d0a 436f 6e74 656e    Encoding..Conten
742d 456e 636f 6469 6e67 3a20 677a 6970    t-Encoding: gzip
0d0a 436f 6e74 656e 742d 4c65 6e67 7468    ..Content-Length
3a20 3731 390d 0a43 6f6e 7465 6e74 2d54    : 719..Content-T
7970 653a 2074 6578 742f 6874 6d6c 0d0a    ype: text/html..
582d 4361 6368 653a 204d 4953 5320 6672    X-Cache: MISS fr
6f6d 2063 6163 6865 362e 6368 696e 612e    om cache6.china.
636f 6d0d 0a56 6961 3a20 312e 3020 6361    com..Via: 1.0 ca
6368 6536 2e63 6869 6e61 2e63 6f6d 3a38    che6.china.com:8
3020 2873 7175 6964 2f32 2e36 2e53 5441    0 (squid/2.6.STA
424c 4531 3929 0d0a 436f 6e6e 6563 7469    BLE19)..Connecti
6f6e 3a20 636c 6f73 650d 0a0d 0a1f 8b08    on: close.......
0000 0000 0000 038d 53cf 6b13 4114 be0b    ........S.k.A...
fe0f d301 2101 b393 1fa6 21bb d91e 4cab    ....!.....!...L.
2d54 5b34 a21e 27bb b3bb a3b3 3b71 7636    -T[4..'.....;qv6
9b58 fac7 140f 4215 a1a4 a054 eaa5 0525    .X....B....T...%
480f 15ea c54b 2f5e 4a4f 0529 3d39 fb23    H....K/^JO.)=9.#
2555 0f5e 76de 7bfb bdf7 bdf7 cdbc d6cc    %U.^v.{.........
fc4a bbf3 7475 0178 d267 60f5 d1ed e5a5    .J..tu.x.g`.....
3680 2584 1ed7 da08 cd77 e6c1 93c5 cebd    6.%......w......
6550 d1ca a023 7010 5249 7980 1942 0bf7    eP...#p.RIy..B..
2180 9e94 3d1d a138 8eb5 b8a6 71e1 a2ce    !...=..8....q...
0334 486a 5592 e4dc 2cc9 a94c cd96 369c    .4HjU...,..L..6.
bb7e ad95 320e 7c16 84e6 3fea 549a cd66    .~..2.|...?.T..f
969e 8109 b693 d327 1283 045d 222f 22da    .......'...]"/".
3761 9b07 9204 b2d4 19f6 0804 56e6 9950    7a..........V..P
9281 4449 b601 2c0f 8b90 48d3 ed56 6b95    ..DI..,...H..Vk.
2a04 28a9 23a9 6464 6efb f4e0 eceb f1f8    *.(.#.ddn.......
d3e1 086c 6c6e 6c2a 280d b066 71bf 8532    ...llnl*(..fq..2
8042 a29c 5a99 5d6e 0f41 2887 8c64 0425    .B..Z.]n.A(..d.%
cca8 1be8 9662 24c2 003e 162e 0df4 b201    .....b$..>......
7ad8 b669 e02a 336d dea6 fd49 5a17 5bcf    z..i.*3m...IZ.[.
5dc1 a3c0 d623 c10a 88f4 50d7 d55c ea14    ]....#....P..\..
0d10 535b 7afa ec6c a337 3080 47a8 eb49    ..S[z..l.70.G..I
bd5a ab27 5e5e ba5a be01 7024 b962 e099    .Z.'^^.Z..p$.b..
9eba 200c 4bda 2706 98ea 8811 47a6 d400    .. .K.'.....G...
4c93 5f26 e16e c859 2455 5282 d433 46c9    L._&.n.Y$UR..3F.
7b7a a3a9 2c38 d7a2 be0b 4261 9930 6990    {z..,8....Ba.0i.
7197 272d 4280 9992 f652 24b0 bc72 7705    q.'-B....R$..rw.
666d 9bb0 72ab 01f3 ae4d 58af 243a b790    fm..r....MX.$:..
22ff ef2e aaf5 f295 3672 3d6a cd2c fcb7    ".......6r=j.,..
de8e baec 5248 5f12 bd32 9b40 52df c13e    ....RH_..2.@R..>
6543 3da4 7e18 0579 2cce b4ec 7266 2b2e    eC=.~..y,...rf+.
1a90 d244 dd46 3aee ce8f add7 9f3f bc7a    ...D.F:......?.z
bb7f f17e ef60 7c38 dafb 39de 1afd da3e    ...~.`|8..9....>
6d75 45fa 5a00 a8ef 9d1c 7d3b 7ab7 73b6    muE.Z.....};z.s.
fbe6 e3f1 f6f9 fec5 eef9 9793 f1f7 c3d1    ................
cc64 c6cb 33b4 04ed 4920 d57b cc9f e133    .d..3...I .{...3
dcc7 5934 b912 270a ac64 7c40 c3a5 3b02    ..Y4..'..d|@..;.
fbe4 2161 4ea1 b826 c570 8d3a 8598 0636    ..!aN..&.p.:...6
8f35 a502 30cd cc29 ae09 2223 11a8 5ccc    .5..0..).."#..\.
4262 ac13 f5cd 6340 8a48 45d6 2d2c 2daf    Bb....c@.HE.-,-.
408a 7f84 a7e8 245f e43e 5144 40b1 cc5c    @.....$_.>QD@..\
2557 c19c 9771 5549 c135 4f10 475d 3f4c    %W...qUI.5O.G]?L
8be4 3fd5 1675 a84f 7824 0b70 520e deac    ..?..u.Ox$.pR...
97cb e5a2 9128 900d 998a 91ac 4ab6 3d6a    .....(......J.=j
0795 f11b 06f1 8bfb 6904 0000              ........i...

  -  TCP Connection Attempts:  
from ANUBIS:1033 to 124.238.253.102:80
from ANUBIS:1034 to 124.238.253.102:80

3.e) Explorer.EXE - Other Activities

  - Keyboard Keys Monitored:  
Virtual Key Code Times
VK_LBUTTON (1)  298 


International Secure Systems Lab
Vienna University of Technology, Eurecom France, UC Santa Barbara
Contact: anubis@iseclab.org