anubis left
Anubis - Analysis Report
anubis right

Analysis Report for 55235076

Comment on this report

Summary:

No threats could be detected by Anubis. This does not imply that execution of this executable is safe.

Table of Contents

expand allexpand all  collapse allcollapse all

1. General Information

 - Information about Anubis' invocation 
Time needed:254 s 
Report created:10/27/11, 21:36:27 UTC 
Termination reason:Timeout 
Program version:1.75.3394 

2. 55235076.exe

 - General information about this executable 
Analysis Reason:Primary Analysis Subject 
Filename:55235076.exe 
MD5:78e2eb95e987f1542d6dfc5d981eade9 
SHA-1:1ff4d279d1ed274ec803182debf73c4239a369b7 
File Size:135206 Bytes
Command Line:"C:\55235076.exe" 
Process-status at analysis end:alive 
Exit Code:

 - Load-time Dlls 
Module NameBase AddressSize
C:\​WINDOWS\​system32\​ntdll.dll  0x7C900000 0x000AF000 
C:\​WINDOWS\​system32\​kernel32.dll  0x7C800000 0x000F6000 
C:\​WINDOWS\​system32\​USER32.dll  0x7E410000 0x00091000 
C:\​WINDOWS\​system32\​GDI32.dll  0x77F10000 0x00049000 
C:\​WINDOWS\​system32\​ADVAPI32.dll  0x77DD0000 0x0009B000 
C:\​WINDOWS\​system32\​RPCRT4.dll  0x77E70000 0x00092000 
C:\​WINDOWS\​system32\​Secur32.dll  0x77FE0000 0x00011000 
C:\​WINDOWS\​system32\​MSVCRT.dll  0x77C10000 0x00058000 

2.a) 55235076.exe - Registry Activities

 - Registry Values Read: 
KeyNameValueTimes
HKLM\​System\​CurrentControlSet\​Control\​Terminal Server  TSAppCompat 
HKLM\​System\​CurrentControlSet\​Control\​Terminal Server  TSUserEnabled 

2.b) 55235076.exe - File Activities

 - Files Read: 
C:\55235076.exe

 - File System Control Communication: 
FileControl CodeTimes
C:\Program Files\Common Files\ 0x00090028 


International Secure Systems Lab
Vienna University of Technology, Eurecom France, UC Santa Barbara
Contact: anubis@iseclab.org