anubis left
Anubis - Analysis Report
anubis right

Analysis Report for ff0a575442a6e865fbcd52ab80770a2f

Comment on this report

Summary:

Description Risk
Performs File Modification and Destruction: The executable modifies and destructs files which are not temporary. high
Performs Registry Activities: The executable reads and modifies registry values. It may also create and monitor registry keys. low


Table of Contents

expand all expand all   collapse all collapse all

1. General Information

  - Information about Anubis' invocation  
Time needed: 242 s 
Report created: 03/20/09, 11:49:16 UTC 
Termination reason: Timeout 
Program version: 1.67.0 

1.a) - Network Activity

  -  Unknown UDP Traffic:  
from ANUBIS:1025 to 192.168.0.1:53
State: Normal establishment and termination - Transferred outbound Bytes: 38 - Transferred inbound Bytes: 199

  -  TCP Connection Attempts:  
from ANUBIS:1034 to 77.31.211.112:3460

2. sample.exe

  - General information about this executable  
Analysis Reason: Primary Analysis Subject 
Filename: sample.exe 
MD5: ff0a575442a6e865fbcd52ab80770a2f 
SHA-1: fe557312d8500ce815f7e31def70ffe3876b3bbd 
File Size: 7424 Bytes
Command Line: "C:\sample.exe" 
Process-status at analysis end: alive 
Exit Code:

  - Load-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​ntdll.dll  0x7C900000  0x000AF000 
C:\​WINDOWS\​system32\​kernel32.dll  0x7C800000  0x000F6000 

  - Run-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​advpack.dll  0x42EC0000  0x0002E000 
C:\​WINDOWS\​system32\​hnetcfg.dll  0x662B0000  0x00058000 
C:\​WINDOWS\​system32\​mswsock.dll  0x71A50000  0x0003F000 
C:\​WINDOWS\​System32\​wshtcpip.dll  0x71A90000  0x00008000 
C:\​WINDOWS\​system32\​WS2HELP.dll  0x71AA0000  0x00008000 
C:\​WINDOWS\​system32\​ws2_32.dll  0x71AB0000  0x00017000 
C:\​WINDOWS\​system32\​IMM32.DLL  0x76390000  0x0001D000 
C:\​WINDOWS\​system32\​DNSAPI.dll  0x76F20000  0x00027000 
C:\​WINDOWS\​system32\​WLDAP32.dll  0x76F60000  0x0002C000 
C:\​WINDOWS\​System32\​winrnr.dll  0x76FB0000  0x00008000 
C:\​WINDOWS\​system32\​rasadhlp.dll  0x76FC0000  0x00006000 
C:\​WINDOWS\​system32\​ole32.dll  0x774E0000  0x0013D000 
C:\​WINDOWS\​system32\​SETUPAPI.dll  0x77920000  0x000F3000 
C:\​WINDOWS\​system32\​VERSION.dll  0x77C00000  0x00008000 
C:\​WINDOWS\​system32\​msvcrt.dll  0x77C10000  0x00058000 
C:\​WINDOWS\​system32\​advapi32.dll  0x77DD0000  0x0009B000 
C:\​WINDOWS\​system32\​RPCRT4.dll  0x77E70000  0x00092000 
C:\​WINDOWS\​system32\​GDI32.dll  0x77F10000  0x00049000 
C:\​WINDOWS\​system32\​SHLWAPI.dll  0x77F60000  0x00076000 
C:\​WINDOWS\​system32\​Secur32.dll  0x77FE0000  0x00011000 
C:\​WINDOWS\​system32\​user32.dll  0x7E410000  0x00091000 

  - Ikarus Virus Scanner  
Virus.Win32.Poison (Sig-Id:461069)

2.a) sample.exe - Registry Activities

  - Registry Keys Created:  
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​{DF6E1E46-4EFA-CC86-1444-5B7BD3B240D1}

  - Registry Values Modified:  
Key Name New Value
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​{DF6E1E46-4EFA-CC86-1444-5B7BD3B240D1}  StubPath  C:\​sample.exe 

  - Registry Values Read:  
Key Name Value Times
HKLM\​SYSTEM\​CurrentControlSet\​Control\​Session Manager  CriticalSectionTimeout  2592000 
HKLM\​SYSTEM\​CurrentControlSet\​Services\​Winsock\​Parameters  Transports  0x5400630070006900700000004e0065007400420049004f00530000000000 
HKLM\​SYSTEM\​Setup  OsLoaderPath  \​ 
HKLM\​SYSTEM\​Setup  SystemPartition  \​Device\​HarddiskVolume1 
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}  StubPath  C:\​WINDOWS\​system32\​ieudinit.exe 
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}  StubPath  C:\​WINDOWS\​inf\​unregmp2.exe /ShowWMP 
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​>{26923b43-4d38-484f-9b9e-de460746276c}  StubPath  %systemroot%\​system32\​shmgrate.exe OCInstallUserConfigIE 
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​>{60B49E34-C7CC-11D0-8953-00A0C90347FF}  StubPath  RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP 
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS  StubPath  RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP 
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}  StubPath  %systemroot%\​system32\​shmgrate.exe OCInstallUserConfigOE 
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}  StubPath   
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​{22d6f312-b0f6-11d0-94ab-0080c74c7e95}  StubPath   
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​{2C7339CF-2B09-4501-B3F3-F3508C9228ED}  StubPath  %SystemRoot%\​system32\​regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\​system32\​themeui.dll 
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​{44BBA840-CC51-11CF-AAFA-00AA00B6015C}  StubPath  "%ProgramFiles%\​Outlook Express\​setup50.exe" /APP:OE /CALLER:WINNT /user /install 
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​{44BBA842-CC51-11CF-AAFA-00AA00B6015B}  StubPath  rundll32.exe advpack.dll,LaunchINFSection C:\​WINDOWS\​INF\​msnetmtg.inf,NetMtg.Install.PerUser.NT 
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​{5945c046-1e7d-11d1-bc44-00c04fd912be}  StubPath  rundll32.exe advpack.dll,LaunchINFSection C:\​WINDOWS\​INF\​msmsgs.inf,BLC.QuietInstall.PerUser 
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​{6BF52A52-394A-11d3-B153-00C04F79FAA6}  StubPath  rundll32.exe advpack.dll,LaunchINFSection C:\​WINDOWS\​INF\​wmp11.inf,PerUserStub 
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​{73FA19D0-2D75-11D2-995D-00C04F98BBC9}  StubPath   
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​{7790769C-0471-11d2-AF11-00C04FA35D02}  StubPath  "%ProgramFiles%\​Outlook Express\​setup50.exe" /APP:WAB /CALLER:WINNT /user /install 
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​{89820200-ECBD-11cf-8B85-00AA005B4340}  StubPath  regsvr32.exe /s /n /i:U shell32.dll 
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​{89820200-ECBD-11cf-8B85-00AA005B4383}  StubPath  C:\​WINDOWS\​system32\​ie4uinit.exe -BaseSettings 
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​{89B4C1CD-B018-4511-B0A1-5476DBF70820}  StubPath  C:\​WINDOWS\​system32\​Rundll32.exe C:\​WINDOWS\​system32\​mscories.dll,Install 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​Windows  AppInit_DLLs   
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion  DevicePath  %SystemRoot%\​inf 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Setup  DriverCachePath  %SystemRoot%\​Driver Cache 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Setup  LogLevel 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Setup  ServicePackCachePath  c:\​windows\​ServicePackFiles\​ServicePackCache 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Setup  ServicePackSourcePath  c:\​windows\​ServicePackFiles 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Setup  SourcePath  D:\​ 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers  TransparentEnabled 
HKLM\​System\​CurrentControlSet\​Control\​ComputerName\​ActiveComputerName  ComputerName  USER 
HKLM\​System\​CurrentControlSet\​Control\​Terminal Server  TSAppCompat 
HKLM\​System\​CurrentControlSet\​Control\​Terminal Server  TSUserEnabled 
HKLM\​System\​CurrentControlSet\​Services\​LDAP  LdapClientIntegrity 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters  Domain   
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters  Hostname  user 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters  UseDomainNameDevolution 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  HelperDllName  %SystemRoot%\​System32\​wshtcpip.dll 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  Mapping  0x0b0000000300000002000000010000000600000002000000010000000000 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  MaxSockaddrLength  16 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  MinSockaddrLength  16 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  UseDelayedAcceptance 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters  WinSock_Registry_Version  2.0 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5  Num_Catalog_Entries 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5  Serial_Access_Num 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  DisplayString  Tcpip 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  Enabled 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  LibraryPath  %SystemRoot%\​System32\​mswsock.dll 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  ProviderId  0x409d05229e7ecf11ae5a00aa00a7112b 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  StoresServiceClassInfo 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  SupportedNameSpace  12 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  Version 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  DisplayString  NTDS 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  Enabled 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  LibraryPath  %SystemRoot%\​System32\​winrnr.dll 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  ProviderId  0xee37263b80e5cf11a55500c04fd8d4ac 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  StoresServiceClassInfo 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  SupportedNameSpace  32 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  Version 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  DisplayString  Network Location Awareness (NLA) Namespace 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  Enabled 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  LibraryPath  %SystemRoot%\​System32\​mswsock.dll 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  ProviderId  0x3a244266a83ba64abaa52e0bd71fdd83 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  StoresServiceClassInfo 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  SupportedNameSpace  15 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  Version 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9  Next_Catalog_Entry_ID  1012 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9  Num_Catalog_Entries  11 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9  Serial_Access_Num 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000001  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000002  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000003  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000004  PackedCatalogItem  %SystemRoot%\​system32\​rsvpsp.d 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000005  PackedCatalogItem  %SystemRoot%\​system32\​rsvpsp.d 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000006  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000007  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000008  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000009  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000010  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000011  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​Setup  SystemSetupInProgress 
HKLM\​System\​WPA\​PnP  seed  1374283966 

  - Monitored Registry Keys:  
Key Name Watch subtree Notify Filter Count
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5  Key Change 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9  Key Change 

2.b) sample.exe - File Activities

  - Files Modified:  
\Device\Afd\Endpointinfo
\Device\RasAcdinfo

  - Device Control Communication:  
File Control Code Times
\Device\KsecDD  0x00390008 
\Device\Afd\Endpoint  AFD_GET_INFO (0x0001207B) 
\Device\Afd\Endpoint  AFD_SET_CONTEXT (0x00012047) 
\Device\RasAcd  0x00F14014 
\Device\Afd\Endpoint  AFD_BIND (0x00012003) 
\Device\Afd\Endpoint  AFD_GET_TDI_HANDLES (0x00012037) 
\Device\Afd\Endpoint  AFD_CONNECT (0x00012007) 

  - Memory Mapped Files:  
File Name
C:\WINDOWS\System32\winrnr.dll
C:\WINDOWS\System32\wshtcpip.dll
C:\WINDOWS\system32\DNSAPI.dll
C:\WINDOWS\system32\IMM32.DLL
C:\WINDOWS\system32\SETUPAPI.dll
C:\WINDOWS\system32\WS2HELP.dll
C:\WINDOWS\system32\advpack.dll
C:\WINDOWS\system32\hnetcfg.dll
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\rasadhlp.dll
C:\WINDOWS\system32\ws2_32.dll

2.c) sample.exe - Process Activities

  - Thread Overview:  
Time Number of threads
After 25 seconds

2.d) sample.exe - Network Activity

  - DNS Queries:  
Name Query Type Query Result Successful Protocol
craazeman.No-IP.info  DNS_TYPE_A  77.31.211.112   

  -  TCP Connection Attempts:  
from ANUBIS:1032 to 77.31.211.112:3460
from 77.31.211.112:3460 to ANUBIS:1032
from ANUBIS:1033 to 77.31.211.112:3460


International Secure Systems Lab
Vienna University of Technology, Eurecom France, UC Santa Barbara
Contact: anubis@iseclab.org