anubis left
Anubis - Analysis Report
anubis right

Analysis Report for 5267dddec3543a388f5a982f5081e940.zeustracker

Comment on this report

Summary:

No threats could be detected by Anubis. This does not imply that execution of this executable is safe.

Table of Contents

expand allexpand all  collapse allcollapse all

1. General Information

 - Information about Anubis' invocation 
Time needed:256 s 
Report created:04/22/12, 17:28:31 UTC 
Termination reason:Timeout 
Program version:1.76.3886 

2. 5267dddec3.exe

 - General information about this executable 
Analysis Reason:Primary Analysis Subject 
Filename:5267dddec3.exe 
MD5:5267dddec3543a388f5a982f5081e940 
SHA-1:efeb348a12455ba0c06848c77073570e3f44825b 
File Size:208834 Bytes
Command Line:"C:\5267dddec3.exe" 
Process-status at analysis end:alive 
Exit Code:

 - Load-time Dlls 
Module NameBase AddressSize
C:\​WINDOWS\​system32\​ntdll.dll  0x7C900000 0x000AF000 
C:\​WINDOWS\​system32\​kernel32.dll  0x7C800000 0x000F6000 
C:\​WINDOWS\​system32\​USER32.dll  0x7E410000 0x00091000 
C:\​WINDOWS\​system32\​GDI32.dll  0x77F10000 0x00049000 
C:\​WINDOWS\​system32\​OLEAUT32.dll  0x77120000 0x0008B000 
C:\​WINDOWS\​system32\​ADVAPI32.dll  0x77DD0000 0x0009B000 
C:\​WINDOWS\​system32\​RPCRT4.dll  0x77E70000 0x00092000 
C:\​WINDOWS\​system32\​Secur32.dll  0x77FE0000 0x00011000 
C:\​WINDOWS\​system32\​msvcrt.dll  0x77C10000 0x00058000 
C:\​WINDOWS\​system32\​ole32.dll  0x774E0000 0x0013D000 

2.a) 5267dddec3.exe - Registry Activities

 - Registry Values Read: 
KeyNameValueTimes
HKLM\​SYSTEM\​CurrentControlSet\​Control\​Session Manager  CriticalSectionTimeout 2592000 
HKLM\​System\​CurrentControlSet\​Control\​Terminal Server  TSAppCompat 
HKLM\​System\​CurrentControlSet\​Control\​Terminal Server  TSUserEnabled 

2.b) 5267dddec3.exe - File Activities

 - Files Read: 
C:\5267dddec3.exe

 - File System Control Communication: 
FileControl CodeTimes
C:\Program Files\Common Files\ 0x00090028 

 - Device Control Communication: 
FileControl CodeTimes
\Device\KsecDD 0x00390008 

2.c) 5267dddec3.exe - Other Activities

 - Windows SEH exceptions: 
DescriptionTimes
Exception 0xc0000005 (STATUS_ACCESS_VIOLATION) at 0x77546b5d 13853 


International Secure Systems Lab
Vienna University of Technology, Eurecom France, UC Santa Barbara
Contact: anubis@iseclab.org