anubis left
Anubis - Analysis Report
anubis right

Analysis Report for sample

Comment on this report

Summary:

Description Risk
Performs File Modification and Destruction: The executable modifies and destructs files which are not temporary. high
Spawns Processes: The executable produces processes during the execution. low
Performs Registry Activities: The executable reads and modifies registry values. It may also create and monitor registry keys. low


Table of Contents

expand all expand all   collapse all collapse all

1. General Information

  - Information about Anubis' invocation  
Time needed: 241 s 
Report created: 06/29/09, 18:35:04 UTC 
Termination reason: Timeout 
Program version: 1.68.0 

1.a) - Network Activity

  -  Unknown UDP Traffic:  
from ANUBIS:1025 to 192.168.0.1:53
State: Normal establishment and termination - Transferred outbound Bytes: 33 - Transferred inbound Bytes: 230

  -  TCP Connection Attempts:  
from ANUBIS:1034 to 69.147.241.142:80

2. sample.exe

  - General information about this executable  
Analysis Reason: Primary Analysis Subject 
Filename: sample.exe 
MD5: 05ab61fe1c466e189791623a87f8d98c 
SHA-1: b8c7918e2cdb08c1db8b3ed8a472e2debe1fd79e 
File Size: 57444 Bytes
Command Line: "C:\sample.exe" 
Process-status at analysis end: dead 
Exit Code:

  - Load-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​ntdll.dll  0x7C900000  0x000AF000 
C:\​WINDOWS\​system32\​kernel32.dll  0x7C800000  0x000F6000 
C:\​WINDOWS\​system32\​MsVbVm60.dll  0x73420000  0x00153000 
C:\​WINDOWS\​system32\​USER32.dll  0x7E410000  0x00091000 
C:\​WINDOWS\​system32\​GDI32.dll  0x77F10000  0x00049000 
C:\​WINDOWS\​system32\​ADVAPI32.dll  0x77DD0000  0x0009B000 
C:\​WINDOWS\​system32\​RPCRT4.dll  0x77E70000  0x00092000 
C:\​WINDOWS\​system32\​Secur32.dll  0x77FE0000  0x00011000 
C:\​WINDOWS\​system32\​ole32.dll  0x774E0000  0x0013D000 
C:\​WINDOWS\​system32\​msvcrt.dll  0x77C10000  0x00058000 
C:\​WINDOWS\​system32\​OLEAUT32.dll  0x77120000  0x0008B000 
C:\​WINDOWS\​system32\​IMM32.DLL  0x76390000  0x0001D000 

  - Run-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​MSCTF.dll  0x74720000  0x0004C000 
C:\​WINDOWS\​system32\​msctfime.ime  0x755C0000  0x0002E000 
C:\​WINDOWS\​system32\​version.dll  0x77C00000  0x00008000 
C:\​WINDOWS\​system32\​SXS.DLL  0x7E720000  0x000B0000 

  - Ikarus Virus Scanner  
VirTool.Win32.VBInject (Sig-Id:30245940)

2.a) sample.exe - Registry Activities

  - Registry Values Read:  
Key Name Value Times
HKLM\​SOFTWARE\​Microsoft\​CTF\​SystemShared\​  CUAS 
HKLM\​Software\​Microsoft\​CTF\​SystemShared  CUAS 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​IMM  Ime File  msctfime.ime 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers  AuthenticodeEnabled 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers  DefaultLevel  262144 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers  PolicyScope 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers  TransparentEnabled 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{349d35ab-37b5-462f-9b89-edd5fbde1328}  HashAlg  32771 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{349d35ab-37b5-462f-9b89-edd5fbde1328}  ItemData  0x5eab304f957a49896a006c1c31154015 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{349d35ab-37b5-462f-9b89-edd5fbde1328}  ItemSize  779 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{349d35ab-37b5-462f-9b89-edd5fbde1328}  SaferFlags 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}  HashAlg  32771 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}  ItemData  0x67b0d48b343a3fd3bce9dc646704f394 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}  ItemSize  517 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}  SaferFlags 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}  HashAlg  32771 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}  ItemData  0x327802dcfef8c893dc8ab006dd847d1d 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}  ItemSize  918 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}  SaferFlags 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{94e3e076-8f53-42a5-8411-085bcc18a68d}  HashAlg  32771 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{94e3e076-8f53-42a5-8411-085bcc18a68d}  ItemData  0xbd9a2adb42ebd8560e250e4df8162f67 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{94e3e076-8f53-42a5-8411-085bcc18a68d}  ItemSize  229 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{94e3e076-8f53-42a5-8411-085bcc18a68d}  SaferFlags 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}  HashAlg  32771 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}  ItemData  0x386b085f84ecf669d36b956a22c01e80 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}  ItemSize  370 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}  SaferFlags 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Paths\​{dda3f824-d8cb-441b-834d-be2efd2c1a33}  ItemData  %HKEY_CURRENT_USER\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders\​Cache%OLK* 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Paths\​{dda3f824-d8cb-441b-834d-be2efd2c1a33}  SaferFlags 
HKLM\​System\​CurrentControlSet\​Control\​Nls\​Codepage  932  c_932.nls 
HKLM\​System\​CurrentControlSet\​Control\​Nls\​Codepage  936  c_936.nls 
HKLM\​System\​CurrentControlSet\​Control\​Nls\​Codepage  949  c_949.nls 
HKLM\​System\​CurrentControlSet\​Control\​Nls\​Codepage  950  c_950.nls 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Cache  C:\​Documents and Settings\​user\​Local Settings\​Temporary Internet Files 

2.b) sample.exe - File Activities

  - Files Read:  
C:\sample.exe

  - Device Control Communication:  
File Control Code Times
unnamed file  0x00390008 

  - Memory Mapped Files:  
File Name
C:\WINDOWS\system32\MSCTF.dll
C:\WINDOWS\system32\SXS.DLL
C:\WINDOWS\system32\msctfime.ime
C:\WINDOWS\system32\rpcss.dll
C:\sample.exe

2.c) sample.exe - Process Activities

  - Processes Created:  
Executable Command Line
C:\sample.exe   
  C:\\sample.exe 

  - Remote Threads Created:  
Affected Process
C:\sample.exe

  - Foreign Memory Regions Read:  
Process: C:\sample.exe

  - Foreign Memory Regions Written:  
Process: C:\sample.exe

3. sample.exe

  - General information about this executable  
Analysis Reason: Started by sample.exe 
Filename: sample.exe 
MD5: 05ab61fe1c466e189791623a87f8d98c 
SHA-1: b8c7918e2cdb08c1db8b3ed8a472e2debe1fd79e 
File Size: 57444 Bytes
Command Line: C:\\sample.exe 
Process-status at analysis end: dead 
Exit Code:

  - Load-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​ntdll.dll  0x7C900000  0x000AF000 
C:\​WINDOWS\​system32\​kernel32.dll  0x7C800000  0x000F6000 
C:\​WINDOWS\​system32\​ADVAPI32.dll  0x77DD0000  0x0009B000 
C:\​WINDOWS\​system32\​RPCRT4.dll  0x77E70000  0x00092000 
C:\​WINDOWS\​system32\​Secur32.dll  0x77FE0000  0x00011000 

  - Run-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​Normaliz.dll  0x00350000  0x00009000 
C:\​WINDOWS\​system32\​iertutil.dll  0x42990000  0x00045000 
C:\​WINDOWS\​system32\​wininet.dll  0x42C10000  0x000CF000 
C:\​WINDOWS\​system32\​comctl32.dll  0x5D090000  0x0009A000 
C:\​WINDOWS\​system32\​WS2HELP.dll  0x71AA0000  0x00008000 
C:\​WINDOWS\​system32\​ws2_32.dll  0x71AB0000  0x00017000 
C:\​WINDOWS\​system32\​IMM32.DLL  0x76390000  0x0001D000 
C:\​WINDOWS\​WinSxS\​x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\​comctl32.dll  0x773D0000  0x00103000 
C:\​WINDOWS\​system32\​msvcrt.dll  0x77C10000  0x00058000 
C:\​WINDOWS\​system32\​GDI32.dll  0x77F10000  0x00049000 
C:\​WINDOWS\​system32\​SHLWAPI.dll  0x77F60000  0x00076000 
C:\​WINDOWS\​system32\​shell32.dll  0x7C9C0000  0x00817000 
C:\​WINDOWS\​system32\​USER32.dll  0x7E410000  0x00091000 

  - Ikarus Virus Scanner  
VirTool.Win32.VBInject (Sig-Id:30245940)

3.a) sample.exe - Registry Activities

  - Registry Values Read:  
Key Name Value Times
HKLM\​SYSTEM\​Setup  SystemSetupInProgress 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​Windows  AppInit_DLLs   
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers  TransparentEnabled 
HKLM\​System\​CurrentControlSet\​Control\​ComputerName\​ActiveComputerName  ComputerName  USER 

3.b) sample.exe - File Activities

  - Files Read:  
PIPE\lsarpc

  - Files Modified:  
PIPE\lsarpcinfo
WMIDataDeviceinfo

  - File System Control Communication:  
File Control Code Times
PIPE\lsarpc  0x0011C017 

  - Device Control Communication:  
File Control Code Times
WMIDataDevice  0x0022414C 
WMIDataDevice  0x00228144 

  - Memory Mapped Files:  
File Name
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
C:\WINDOWS\WindowsShell.Manifest
C:\WINDOWS\system32\IMM32.DLL
C:\WINDOWS\system32\WS2HELP.dll
C:\WINDOWS\system32\comctl32.dll
C:\WINDOWS\system32\shell32.dll
C:\WINDOWS\system32\ws2_32.dll

3.c) sample.exe - Process Activities

  - Remote Threads Created:  
Affected Process
C:\WINDOWS\explorer.exe

  - Thread Overview:  
Time Number of threads
After 91 seconds

  - Foreign Memory Regions Written:  
Process: C:\WINDOWS\explorer.exe

4. Explorer.EXE

  - General information about this executable  
Analysis Reason: sample.exe injected a remote thread into this process 
Filename: Explorer.EXE 
MD5: 12896823fb95bfb3dc9b46bcaedc9923 
SHA-1: 9d2bf84874abc5b6e9a2744b7865c193c08d362f 
File Size: 1033728 Bytes
Command Line: C:\WINDOWS\Explorer.EXE 
Process-status at analysis end: alive 
Exit Code:

  - Load-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​ntdll.dll  0x7C900000  0x000AF000 
C:\​WINDOWS\​system32\​kernel32.dll  0x7C800000  0x000F6000 
C:\​WINDOWS\​system32\​ADVAPI32.dll  0x77DD0000  0x0009B000 
C:\​WINDOWS\​system32\​RPCRT4.dll  0x77E70000  0x00092000 
C:\​WINDOWS\​system32\​Secur32.dll  0x77FE0000  0x00011000 
C:\​WINDOWS\​system32\​BROWSEUI.dll  0x75F80000  0x000FD000 
C:\​WINDOWS\​system32\​GDI32.dll  0x77F10000  0x00049000 
C:\​WINDOWS\​system32\​USER32.dll  0x7E410000  0x00091000 
C:\​WINDOWS\​system32\​msvcrt.dll  0x77C10000  0x00058000 
C:\​WINDOWS\​system32\​ole32.dll  0x774E0000  0x0013D000 
C:\​WINDOWS\​system32\​SHLWAPI.dll  0x77F60000  0x00076000 
C:\​WINDOWS\​system32\​OLEAUT32.dll  0x77120000  0x0008B000 
C:\​WINDOWS\​system32\​SHDOCVW.dll  0x7E290000  0x00171000 
C:\​WINDOWS\​system32\​CRYPT32.dll  0x77A80000  0x00095000 
C:\​WINDOWS\​system32\​MSASN1.dll  0x77B20000  0x00012000 
C:\​WINDOWS\​system32\​CRYPTUI.dll  0x754D0000  0x00080000 
C:\​WINDOWS\​system32\​NETAPI32.dll  0x5B860000  0x00055000 
C:\​WINDOWS\​system32\​VERSION.dll  0x77C00000  0x00008000 
C:\​WINDOWS\​system32\​WININET.dll  0x42C10000  0x000CF000 
C:\​WINDOWS\​system32\​Normaliz.dll  0x00400000  0x00009000 
C:\​WINDOWS\​system32\​iertutil.dll  0x42990000  0x00045000 
C:\​WINDOWS\​system32\​WINTRUST.dll  0x76C30000  0x0002E000 
C:\​WINDOWS\​system32\​IMAGEHLP.dll  0x76C90000  0x00028000 
C:\​WINDOWS\​system32\​WLDAP32.dll  0x76F60000  0x0002C000 
C:\​WINDOWS\​system32\​SHELL32.dll  0x7C9C0000  0x00817000 
C:\​WINDOWS\​system32\​UxTheme.dll  0x5AD70000  0x00038000 
C:\​WINDOWS\​system32\​ShimEng.dll  0x5CB70000  0x00026000 
C:\​WINDOWS\​AppPatch\​AcGenral.DLL  0x6F880000  0x001CA000 
C:\​WINDOWS\​system32\​WINMM.dll  0x76B40000  0x0002D000 
C:\​WINDOWS\​system32\​MSACM32.dll  0x77BE0000  0x00015000 
C:\​WINDOWS\​system32\​USERENV.dll  0x769C0000  0x000B4000 
C:\​WINDOWS\​system32\​IMM32.DLL  0x76390000  0x0001D000 
C:\​WINDOWS\​WinSxS\​x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\​comctl32.dll  0x773D0000  0x00103000 
C:\​WINDOWS\​system32\​comctl32.dll  0x5D090000  0x0009A000 
C:\​WINDOWS\​system32\​msctfime.ime  0x755C0000  0x0002E000 
C:\​WINDOWS\​system32\​appHelp.dll  0x77B40000  0x00022000 
C:\​WINDOWS\​system32\​CLBCATQ.DLL  0x76FD0000  0x0007F000 
C:\​WINDOWS\​system32\​COMRes.dll  0x77050000  0x000C5000 
C:\​WINDOWS\​System32\​cscui.dll  0x77A20000  0x00054000 
C:\​WINDOWS\​System32\​CSCDLL.dll  0x76600000  0x0001D000 
C:\​WINDOWS\​system32\​themeui.dll  0x5BA60000  0x00071000 
C:\​WINDOWS\​system32\​MSIMG32.dll  0x76380000  0x00005000 
C:\​WINDOWS\​system32\​xpsp2res.dll  0x01100000  0x002C5000 
C:\​WINDOWS\​system32\​actxprxy.dll  0x71D40000  0x0001B000 
C:\​WINDOWS\​system32\​SAMLIB.dll  0x71BF0000  0x00013000 
C:\​WINDOWS\​system32\​SETUPAPI.dll  0x77920000  0x000F3000 
C:\​WINDOWS\​system32\​msi.dll  0x7D1E0000  0x002BC000 
C:\​WINDOWS\​system32\​ntshrui.dll  0x76990000  0x00025000 
C:\​WINDOWS\​system32\​ATL.DLL  0x76B20000  0x00011000 
C:\​WINDOWS\​system32\​ieframe.dll  0x42EF0000  0x005CD000 
C:\​WINDOWS\​system32\​PSAPI.DLL  0x76BF0000  0x0000B000 
C:\​WINDOWS\​system32\​LINKINFO.dll  0x76980000  0x00008000 
C:\​WINDOWS\​system32\​NETSHELL.dll  0x76400000  0x001A5000 
C:\​WINDOWS\​system32\​credui.dll  0x76C00000  0x0002E000 
C:\​WINDOWS\​system32\​dot3api.dll  0x478C0000  0x0000A000 
C:\​WINDOWS\​system32\​rtutils.dll  0x76E80000  0x0000E000 
C:\​WINDOWS\​system32\​dot3dlg.dll  0x736D0000  0x00006000 
C:\​WINDOWS\​system32\​OneX.DLL  0x5DCA0000  0x00028000 
C:\​WINDOWS\​system32\​WTSAPI32.dll  0x76F50000  0x00008000 
C:\​WINDOWS\​system32\​WINSTA.dll  0x76360000  0x00010000 
C:\​WINDOWS\​system32\​eappcfg.dll  0x745B0000  0x00022000 
C:\​WINDOWS\​system32\​MSVCP60.dll  0x76080000  0x00065000 
C:\​WINDOWS\​system32\​eappprxy.dll  0x5DCD0000  0x0000E000 
C:\​WINDOWS\​system32\​iphlpapi.dll  0x76D60000  0x00019000 
C:\​WINDOWS\​system32\​WS2_32.dll  0x71AB0000  0x00017000 
C:\​WINDOWS\​system32\​WS2HELP.dll  0x71AA0000  0x00008000 
C:\​WINDOWS\​system32\​urlmon.dll  0x42CF0000  0x00127000 
C:\​WINDOWS\​system32\​webcheck.dll  0x42E40000  0x0003C000 
C:\​WINDOWS\​system32\​stobject.dll  0x76280000  0x00021000 
C:\​WINDOWS\​system32\​BatMeter.dll  0x74AF0000  0x0000A000 
C:\​WINDOWS\​system32\​POWRPROF.dll  0x74AD0000  0x00008000 
C:\​WINDOWS\​system32\​WPDShServiceObj.dll  0x164A0000  0x00023000 
C:\​WINDOWS\​system32\​WINHTTP.dll  0x4D4F0000  0x00059000 
C:\​WINDOWS\​system32\​mydocs.dll  0x72410000  0x0001A000 
C:\​WINDOWS\​system32\​PortableDeviceTypes.dll  0x109C0000  0x0002C000 
C:\​WINDOWS\​system32\​PortableDeviceApi.dll  0x10930000  0x00049000 
C:\​WINDOWS\​system32\​MSCTF.dll  0x74720000  0x0004C000 
C:\​WINDOWS\​system32\​SXS.DLL  0x7E720000  0x000B0000 
C:\​WINDOWS\​system32\​MPR.dll  0x71B20000  0x00012000 
C:\​WINDOWS\​System32\​drprov.dll  0x75F60000  0x00007000 
C:\​WINDOWS\​System32\​ntlanman.dll  0x71C10000  0x0000E000 
C:\​WINDOWS\​System32\​NETUI0.dll  0x71CD0000  0x00017000 
C:\​WINDOWS\​System32\​NETUI1.dll  0x71C90000  0x00040000 
C:\​WINDOWS\​System32\​NETRAP.dll  0x71C80000  0x00007000 
C:\​WINDOWS\​System32\​davclnt.dll  0x75F70000  0x0000A000 
C:\​WINDOWS\​system32\​browselc.dll  0x71600000  0x00012000 
C:\​WINDOWS\​system32\​MSGINA.dll  0x75970000  0x000F8000 
C:\​WINDOWS\​system32\​ODBC32.dll  0x74320000  0x0003D000 
C:\​WINDOWS\​system32\​comdlg32.dll  0x763B0000  0x00049000 
C:\​WINDOWS\​system32\​odbcint.dll  0x02310000  0x00017000 
C:\​WINDOWS\​system32\​MLANG.dll  0x75CF0000  0x00091000 
C:\​WINDOWS\​system32\​rsaenh.dll  0x68000000  0x00036000 

  - Run-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​hnetcfg.dll  0x662B0000  0x00058000 
C:\​WINDOWS\​System32\​mswsock.dll  0x71A50000  0x0003F000 
C:\​WINDOWS\​System32\​wshtcpip.dll  0x71A90000  0x00008000 
C:\​WINDOWS\​system32\​DNSAPI.dll  0x76F20000  0x00027000 
C:\​WINDOWS\​System32\​winrnr.dll  0x76FB0000  0x00008000 
C:\​WINDOWS\​system32\​rasadhlp.dll  0x76FC0000  0x00006000 

4.a) Explorer.EXE - Registry Activities

  - Registry Keys Created:  
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​{28ABC5C0-4FCB-11CF-AAX5-81CX1C635612}

  - Registry Values Modified:  
Key Name New Value
HKLM\​Software\​Microsoft\​Active Setup\​Installed Components\​{28ABC5C0-4FCB-11CF-AAX5-81CX1C635612}  StubPath  c:\​RECYCLER\​S-51-9-25-3434476501-1644491937-601003330-1213\​Mrgsv.exe 

  - Registry Values Read:  
Key Name Value Times
HKLM\​SYSTEM\​CONTROLSET001\​SERVICES\​TCPIP\​LINKAGE  Bind  0x5c004400650076006900630065005c007b00420032004200350031003000  268 
HKLM\​SYSTEM\​CONTROLSET001\​SERVICES\​WINSOCK2\​PARAMETERS\​NAMESPACE_CATALOG5  Serial_Access_Num 
HKLM\​SYSTEM\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Interfaces\​{B2B51064-BBF5-4528-B62B-E6D62A782874}  DhcpServer  255.255.255.255  270 
HKLM\​SYSTEM\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Interfaces\​{B2B51064-BBF5-4528-B62B-E6D62A782874}  EnableDHCP  135 
HKLM\​SYSTEM\​CurrentControlSet\​Services\​Winsock\​Parameters  Transports  0x5400630070006900700000004e0065007400420049004f00530000000000 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters  Domain   
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters  Hostname  user 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters  UseDomainNameDevolution 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  HelperDllName  %SystemRoot%\​System32\​wshtcpip.dll 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  Mapping  0x0b0000000300000002000000010000000600000002000000010000000000 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  MaxSockaddrLength  16 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  MinSockaddrLength  16 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  UseDelayedAcceptance 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters  WinSock_Registry_Version  2.0 
HKLM\​System\​Setup  SystemSetupInProgress 

  - Monitored Registry Keys:  
Key Name Watch subtree Notify Filter Count
HKLM\​SYSTEM\​CONTROLSET001\​SERVICES\​WINSOCK2\​PARAMETERS\​NAMESPACE_CATALOG5  Key Change 

4.b) Explorer.EXE - File Activities

  - Files Created:  
c:\RECYCLER\S-51-9-25-3434476501-1644491937-601003330-1213
c:\RECYCLER\S-51-9-25-3434476501-1644491937-601003330-1213\Desktop.ini
c:\RECYCLER\S-51-9-25-3434476501-1644491937-601003330-1213\Mrgsv.exe

  - Files Modified:  
\Device\Afd\Endpointinfo
\Device\NetBT_Tcpip_{B2B51064-BBF5-4528-B62B-E6D62A782874}info
\Device\RasAcdinfo
c:\RECYCLER\S-51-9-25-3434476501-1644491937-601003330-1213\Desktop.iniinfo
c:\RECYCLER\S-51-9-25-3434476501-1644491937-601003330-1213\Mrgsv.exeinfo

  - Directories Created:  
c:\RECYCLER\S-51-9-25-3434476501-1644491937-601003330-1213

  - Device Control Communication:  
File Control Code Times
unnamed file  0x00120090  135 
unnamed file  0x00120003  1746 
\Device\NetBT_Tcpip_{B2B51064-BBF5-4528-B62B-E6D62A782874}  0x0021009A  135 
\Device\{B2B51064-BBF5-4528-B62B-E6D62A782874}  0x0017003E  67 
unnamed file  0x00120040  268 
\Device\RasAcd  0x00F14014 
\Device\Afd\Endpoint  AFD_GET_INFO (0x0001207B) 
\Device\Afd\Endpoint  AFD_SET_CONTEXT (0x00012047) 
\Device\Afd\Endpoint  AFD_BIND (0x00012003) 
\Device\Afd\Endpoint  AFD_GET_TDI_HANDLES (0x00012037) 
\Device\Afd\Endpoint  AFD_CONNECT (0x00012007) 

  - Memory Mapped Files:  
File Name
C:\WINDOWS\System32\mswsock.dll
C:\WINDOWS\System32\winrnr.dll
C:\WINDOWS\System32\wshtcpip.dll
C:\WINDOWS\system32\DNSAPI.dll
C:\WINDOWS\system32\hnetcfg.dll
C:\WINDOWS\system32\rasadhlp.dll
C:\sample.exe

4.c) Explorer.EXE - Process Activities

  - Thread Overview:  
Time Number of threads
After 123 seconds

  - Foreign Memory Regions Read:  
Process: C:\WINDOWS\explorer.exe

4.d) Explorer.EXE - Network Activity

  - DNS Queries:  
Name Query Type Query Result Successful Protocol
www.MSNAREA.COM  DNS_TYPE_A  69.147.241.142   

  -  TCP Connection Attempts:  
from ANUBIS:1032 to 69.147.241.142:80
from ANUBIS:1033 to 69.147.241.142:80

4.e) Explorer.EXE - Other Activities

  - Mutexes Created:  
a94997

  - Keyboard Keys Monitored:  
Virtual Key Code Times
VK_LBUTTON (1)  308 


International Secure Systems Lab
Vienna University of Technology, Eurecom France, UC Santa Barbara
Contact: anubis@iseclab.org