anubis left
Anubis - Analysis Report
anubis right

Analysis Report for 3a5b095ca282916717bc522ff6b80a37.zeustracker

Comment on this report

Summary:

No threats could be detected by Anubis. This does not imply that execution of this executable is safe.

Table of Contents

expand allexpand all  collapse allcollapse all

1. General Information

 - Information about Anubis' invocation 
Time needed:254 s 
Report created:04/01/12, 13:26:00 UTC 
Termination reason:Timeout 
Program version:1.75.3394 

2. 3a5b095ca2.exe

 - General information about this executable 
Analysis Reason:Primary Analysis Subject 
Filename:3a5b095ca2.exe 
MD5:3a5b095ca282916717bc522ff6b80a37 
SHA-1:adbb6d8fb7e7df77c177adc8122a1f78f7692f46 
File Size:156160 Bytes
Command Line:"C:\3a5b095ca2.exe" 
Process-status at analysis end:alive 
Exit Code:

 - Load-time Dlls 
Module NameBase AddressSize
C:\​WINDOWS\​system32\​ntdll.dll  0x7C900000 0x000AF000 
C:\​WINDOWS\​system32\​kernel32.dll  0x7C800000 0x000F6000 
C:\​WINDOWS\​system32\​SHLWAPI.dll  0x77F60000 0x00076000 
C:\​WINDOWS\​system32\​ADVAPI32.dll  0x77DD0000 0x0009B000 
C:\​WINDOWS\​system32\​RPCRT4.dll  0x77E70000 0x00092000 
C:\​WINDOWS\​system32\​Secur32.dll  0x77FE0000 0x00011000 
C:\​WINDOWS\​system32\​GDI32.dll  0x77F10000 0x00049000 
C:\​WINDOWS\​system32\​USER32.dll  0x7E410000 0x00091000 
C:\​WINDOWS\​system32\​msvcrt.dll  0x77C10000 0x00058000 

2.a) 3a5b095ca2.exe - Registry Activities

 - Registry Values Read: 
KeyNameValueTimes
HKLM\​System\​CurrentControlSet\​Control\​Terminal Server  TSAppCompat 
HKLM\​System\​CurrentControlSet\​Control\​Terminal Server  TSUserEnabled 

2.b) 3a5b095ca2.exe - File Activities

 - File System Control Communication: 
FileControl CodeTimes
C:\Program Files\Common Files\ 0x00090028 


International Secure Systems Lab
Vienna University of Technology, Eurecom France, UC Santa Barbara
Contact: anubis@iseclab.org