anubis left
Anubis - Analysis Report
anubis right

Analysis Report for Jawbreakers_First_CsS_h4ck.exe

Comment on this report

Summary:

Description Risk
Performs File Modification and Destruction: The executable modifies and destructs files which are not temporary. high
Spawns Processes: The executable produces processes during the execution. low
Performs Registry Activities: The executable reads and modifies registry values. It may also create and monitor registry keys. low


Table of Contents

expand all expand all   collapse all collapse all

1. General Information

  - Information about Anubis' invocation  
Time needed: 240 s 
Report created: 10/04/09, 12:48:32 UTC 
Termination reason: Timeout 
Program version: 1.72.0 

2. Jawbreakers_First_CsS_h4ck.exe

  - General information about this executable  
Analysis Reason: Primary Analysis Subject 
Filename: Jawbreakers_First_CsS_h4ck.exe 
MD5: 6f73b14909de5657b588716adfc5b0af 
SHA-1: a4d5ed6c18bab7ddc4430949ff9834e8bb7063a5 
File Size: 638976 Bytes
Command Line: "C:\Jawbreakers_First_CsS_h4ck.exe"  
Process-status at analysis end: alive 
Exit Code:

  - Load-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​ntdll.dll  0x7C900000  0x000AF000 
C:\​WINDOWS\​system32\​kernel32.dll  0x7C800000  0x000F6000 
C:\​WINDOWS\​system32\​MSVBVM60.DLL  0x73420000  0x00153000 
C:\​WINDOWS\​system32\​USER32.dll  0x7E410000  0x00091000 
C:\​WINDOWS\​system32\​GDI32.dll  0x77F10000  0x00049000 
C:\​WINDOWS\​system32\​ADVAPI32.dll  0x77DD0000  0x0009B000 
C:\​WINDOWS\​system32\​RPCRT4.dll  0x77E70000  0x00092000 
C:\​WINDOWS\​system32\​Secur32.dll  0x77FE0000  0x00011000 
C:\​WINDOWS\​system32\​ole32.dll  0x774E0000  0x0013D000 
C:\​WINDOWS\​system32\​msvcrt.dll  0x77C10000  0x00058000 
C:\​WINDOWS\​system32\​OLEAUT32.dll  0x77120000  0x0008B000 

  - Run-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​comctl32.dll  0x5D090000  0x0009A000 
C:\​WINDOWS\​system32\​wshom.ocx  0x60280000  0x00021000 
C:\​WINDOWS\​system32\​MPR.dll  0x71B20000  0x00012000 
C:\​WINDOWS\​system32\​ScrRun.dll  0x735A0000  0x0002A000 
C:\​WINDOWS\​system32\​MSCTF.dll  0x74720000  0x0004C000 
C:\​WINDOWS\​system32\​CLBCATQ.DLL  0x76FD0000  0x0007F000 
C:\​WINDOWS\​system32\​COMRes.dll  0x77050000  0x000C5000 
C:\​WINDOWS\​WinSxS\​x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\​comctl32.dll  0x773D0000  0x00103000 
C:\​WINDOWS\​system32\​VERSION.dll  0x77C00000  0x00008000 
C:\​WINDOWS\​system32\​SHLWAPI.dll  0x77F60000  0x00076000 
C:\​WINDOWS\​system32\​SHELL32.dll  0x7C9C0000  0x00817000 
C:\​WINDOWS\​system32\​SXS.DLL  0x7E720000  0x000B0000 

  - Ikarus Virus Scanner  
Trojan-PWS.Win32.VB (Sig-Id:999745)

2.a) Jawbreakers_First_CsS_h4ck.exe - Registry Activities

  - Registry Values Read:  
Key Name Value Times
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{72C24DD5-D70A-438B-8A42-98424B88AFB8}\​INPROCSERVER32    C:\​WINDOWS\​system32\​wshom.ocx 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{72C24DD5-D70A-438B-8A42-98424B88AFB8}\​INPROCSERVER32  ThreadingModel  Apartment 
HKLM\​SOFTWARE\​CLASSES\​TYPELIB\​{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\​1.0\​0\​WIN32    C:\​WINDOWS\​system32\​wshom.ocx 
HKLM\​SOFTWARE\​CLASSES\​WSCRIPT.SHELL\​CLSID    {72C24DD5-D70A-438B-8A42-98424B88AFB8} 
HKLM\​SOFTWARE\​Microsoft\​CTF\​SystemShared\​  CUAS 
HKLM\​SYSTEM\​CurrentControlSet\​Control\​Session Manager  CriticalSectionTimeout  2592000 
HKLM\​SYSTEM\​Setup  SystemSetupInProgress 
HKLM\​Software\​Microsoft\​COM3  Com+Enabled 
HKLM\​Software\​Microsoft\​COM3  REGDBVersion  0x0700000000000000 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​Windows  AppInit_DLLs   
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers  AuthenticodeEnabled 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers  DefaultLevel  262144 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers  PolicyScope 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers  TransparentEnabled 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{349d35ab-37b5-462f-9b89-edd5fbde1328}  HashAlg  32771 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{349d35ab-37b5-462f-9b89-edd5fbde1328}  ItemData  0x5eab304f957a49896a006c1c31154015 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{349d35ab-37b5-462f-9b89-edd5fbde1328}  ItemSize  779 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{349d35ab-37b5-462f-9b89-edd5fbde1328}  SaferFlags 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}  HashAlg  32771 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}  ItemData  0x67b0d48b343a3fd3bce9dc646704f394 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}  ItemSize  517 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}  SaferFlags 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}  HashAlg  32771 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}  ItemData  0x327802dcfef8c893dc8ab006dd847d1d 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}  ItemSize  918 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}  SaferFlags 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{94e3e076-8f53-42a5-8411-085bcc18a68d}  HashAlg  32771 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{94e3e076-8f53-42a5-8411-085bcc18a68d}  ItemData  0xbd9a2adb42ebd8560e250e4df8162f67 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{94e3e076-8f53-42a5-8411-085bcc18a68d}  ItemSize  229 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{94e3e076-8f53-42a5-8411-085bcc18a68d}  SaferFlags 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}  HashAlg  32771 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}  ItemData  0x386b085f84ecf669d36b956a22c01e80 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}  ItemSize  370 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}  SaferFlags 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Paths\​{dda3f824-d8cb-441b-834d-be2efd2c1a33}  ItemData  %HKEY_CURRENT_USER\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders\​Cache%OLK* 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Paths\​{dda3f824-d8cb-441b-834d-be2efd2c1a33}  SaferFlags 
HKLM\​System\​CurrentControlSet\​Control\​Nls\​Codepage  932  c_932.nls 
HKLM\​System\​CurrentControlSet\​Control\​Nls\​Codepage  936  c_936.nls 
HKLM\​System\​CurrentControlSet\​Control\​Nls\​Codepage  949  c_949.nls 
HKLM\​System\​CurrentControlSet\​Control\​Nls\​Codepage  950  c_950.nls 
HKLM\​System\​CurrentControlSet\​Control\​Terminal Server  TSAppCompat 
HKLM\​System\​CurrentControlSet\​Control\​Terminal Server  TSUserEnabled 
HKU\​S-1-5-21-842925246-1425521274-308236825-500\​Keyboard Layout\​Toggle  Language Hotkey 
HKU\​S-1-5-21-842925246-1425521274-308236825-500\​Keyboard Layout\​Toggle  Layout Hotkey 
HKU\​S-1-5-21-842925246-1425521274-308236825-500\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Cache  C:\​Documents and Settings\​Administrator\​Local Settings\​Temporary Internet Files 

  - Monitored Registry Keys:  
Key Name Watch subtree Notify Filter Count
HKLM\​Software\​Classes  Key Change,Value Change 
HKLM\​Software\​Classes\​CLSID  Key Change,Value Change 
HKLM\​Software\​Microsoft\​COM3  Key Change,Value Change 
HKLM\​system\​CurrentControlSet\​control\​NetworkProvider\​HwOrder  Value Change 
HKU  Key Change,Value Change 

2.b) Jawbreakers_First_CsS_h4ck.exe - File Activities

  - Files Read:  
C:\WINDOWS\Registration\R000000000007.clb
C:\WINDOWS\system32\wshom.ocx

  - File System Control Communication:  
File Control Code Times
C:\  0x00090028 

  - Device Control Communication:  
File Control Code Times
\Device\KsecDD  0x00390008 

  - Memory Mapped Files:  
File Name
C:\Jawbreakers_First_CsS_h4ck.exe
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
C:\WINDOWS\WindowsShell.Manifest
C:\WINDOWS\system32\CLBCATQ.DLL
C:\WINDOWS\system32\COMRes.dll
C:\WINDOWS\system32\MSCTF.dll
C:\WINDOWS\system32\MSVBVM60.DLL
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\system32\SXS.DLL
C:\WINDOWS\system32\ScrRun.dll
C:\WINDOWS\system32\comctl32.dll
C:\WINDOWS\system32\imm32.dll
C:\WINDOWS\system32\rpcss.dll
C:\WINDOWS\system32\wshom.ocx

2.c) Jawbreakers_First_CsS_h4ck.exe - Process Activities

  - Processes Created:  
Executable Command Line
C:\Jawbreakers_First_CsS_h4ck.exe   
  C:\\Jawbreakers_First_CsS_h4ck.exe /scomma C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\msg.txt 

  - Remote Threads Created:  
Affected Process
C:\Jawbreakers_First_CsS_h4ck.exe

  - Foreign Memory Regions Read:  
Process: C:\Jawbreakers_First_CsS_h4ck.exe

  - Foreign Memory Regions Written:  
Process: C:\Jawbreakers_First_CsS_h4ck.exe

2.d) Jawbreakers_First_CsS_h4ck.exe - Other Activities

  - Mutexes Created:  
CTF.Asm.MutexDefaultS-​1-​5-​21-​842925246-​1425521274-​308236825-​500
CTF.Compart.MutexDefaultS-​1-​5-​21-​842925246-​1425521274-​308236825-​500
CTF.LBES.MutexDefaultS-​1-​5-​21-​842925246-​1425521274-​308236825-​500
CTF.Layouts.MutexDefaultS-​1-​5-​21-​842925246-​1425521274-​308236825-​500
CTF.TMD.MutexDefaultS-​1-​5-​21-​842925246-​1425521274-​308236825-​500
CTF.TimListCache.FMPDefaultS-​1-​5-​21-​842925246-​1425521274-​308236825-​500MUTEX.DefaultS-​1-​5-​21-​842925246-​1425521274-​308236825-​500

  - Windows SEH exceptions:  
Description Times
Exception 0xc000008f (STATUS_FLOAT_INEXACT_RESULT) at 0x7c812aeb 

3. Jawbreakers_First_CsS_h4ck.exe

  - General information about this executable  
Analysis Reason: Started by Jawbreakers_First_CsS_h4ck.exe 
Filename: Jawbreakers_First_CsS_h4ck.exe 
MD5: 6f73b14909de5657b588716adfc5b0af 
SHA-1: a4d5ed6c18bab7ddc4430949ff9834e8bb7063a5 
File Size: 638976 Bytes
Command Line: C:\\Jawbreakers_First_CsS_h4ck.exe /scomma C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\msg.txt 
Process-status at analysis end: dead 
Exit Code:

  - Load-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​ntdll.dll  0x7C900000  0x000AF000 
C:\​Jawbreakers_First_CsS_h4ck.exe  0x00400000  0x00025000 
C:\​WINDOWS\​system32\​kernel32.dll  0x7C800000  0x000F6000 
C:\​WINDOWS\​system32\​ADVAPI32.dll  0x77DD0000  0x0009B000 
C:\​WINDOWS\​system32\​RPCRT4.dll  0x77E70000  0x00092000 
C:\​WINDOWS\​system32\​Secur32.dll  0x77FE0000  0x00011000 
C:\​WINDOWS\​system32\​COMCTL32.dll  0x5D090000  0x0009A000 
C:\​WINDOWS\​system32\​GDI32.dll  0x77F10000  0x00049000 
C:\​WINDOWS\​system32\​USER32.dll  0x7E410000  0x00091000 
C:\​WINDOWS\​system32\​comdlg32.dll  0x763B0000  0x00049000 
C:\​WINDOWS\​system32\​SHELL32.dll  0x7C9C0000  0x00817000 
C:\​WINDOWS\​system32\​msvcrt.dll  0x77C10000  0x00058000 
C:\​WINDOWS\​system32\​SHLWAPI.dll  0x77F60000  0x00076000 
C:\​WINDOWS\​WinSxS\​x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\​comctl32.dll  0x773D0000  0x00103000 

  - Run-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​rsaenh.dll  0x68000000  0x00036000 
C:\​WINDOWS\​system32\​crypt32.dll  0x77A80000  0x00095000 
C:\​WINDOWS\​system32\​MSASN1.dll  0x77B20000  0x00012000 

  - Ikarus Virus Scanner  
Trojan-PWS.Win32.VB (Sig-Id:999745)

3.a) Jawbreakers_First_CsS_h4ck.exe - Registry Activities

  - Registry Values Modified:  
Key Name New Value
HKU\​S-1-5-21-842925246-1425521274-308236825-500\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  AppData  C:\​Documents and Settings\​Administrator\​Application Data 
HKU\​S-1-5-21-842925246-1425521274-308236825-500\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Local AppData  C:\​Documents and Settings\​Administrator\​Local Settings\​Application Data 

  - Registry Values Read:  
Key Name Value Times
HKLM\​SOFTWARE\​Microsoft\​Cryptography\​Defaults\​Provider Types\​Type 001  Name  Microsoft Strong Cryptographic Provider 
HKLM\​SOFTWARE\​Microsoft\​Cryptography\​Defaults\​Provider\​Microsoft Strong Cryptographic Provider  Image Path  rsaenh.dll 
HKLM\​SOFTWARE\​Microsoft\​Cryptography\​Defaults\​Provider\​Microsoft Strong Cryptographic Provider  Type 
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion  ProgramFilesDir  C:\​Program Files 
HKLM\​SYSTEM\​Setup  SystemSetupInProgress 
HKLM\​Software\​Microsoft\​Cryptography  MachineGuid  4604e8cc-5b9c-4ffb-a374-a62e6d0494fc 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​Windows  AppInit_DLLs   
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers  TransparentEnabled 
HKLM\​System\​CurrentControlSet\​Control\​ComputerName\​ActiveComputerName  ComputerName  PC 
HKLM\​System\​CurrentControlSet\​Control\​Terminal Server  TSAppCompat 
HKLM\​System\​CurrentControlSet\​Control\​Terminal Server  TSUserEnabled 
HKU\​S-1-5-21-842925246-1425521274-308236825-500\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  AppData  %USERPROFILE%\​Application Data 
HKU\​S-1-5-21-842925246-1425521274-308236825-500\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Local AppData  %USERPROFILE%\​Local Settings\​Application Data 

3.b) Jawbreakers_First_CsS_h4ck.exe - File Activities

  - Files Created:  
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\msg.txt

  - Files Read:  
C:\Jawbreakers_First_CsS_h4ck.exe
C:\WINDOWS\system32\rsaenh.dll
PIPE\lsarpc

  - Files Modified:  
PIPE\lsarpcinfo

  - File System Control Communication:  
File Control Code Times
C:\  0x00090028 
PIPE\lsarpc  0x0011C017 

  - Device Control Communication:  
File Control Code Times
\Device\KsecDD  0x00390008 

  - Memory Mapped Files:  
File Name
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
C:\WINDOWS\WindowsShell.Manifest
C:\WINDOWS\system32\COMCTL32.dll
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\system32\crypt32.dll
C:\WINDOWS\system32\rsaenh.dll


International Secure Systems Lab
Vienna University of Technology, Eurecom France, UC Santa Barbara
Contact: anubis@iseclab.org