<?xml version="1.0"?>
<!-- This analysis was created by the CWSandbox (c) Carsten Willems 2006--> 
<analysis cwsversion="Beta 1.80" time="05.10.2006 01:17:22" file="d337a417c3e62c6e134b23a431fc8ccd.exe" logpath="c:\analysis\log\d337a417c3e62c6e134b23a431fc8ccd.exe\run_1\">
<calltree>
<process_call filename="c:\analysis\binary\d337a417c3e62c6e134b23a431fc8ccd.exe" starttime="00:00.047" startreason="AnalysisTarget"/>
<process_call filename="services.exe" starttime="00:02.641" startreason="SCM"/>
</calltree>

<processes>
<process index="1" pid="516" filename="c:\analysis\binary\d337a417c3e62c6e134b23a431fc8ccd.exe" filesize="872448" md5="d337a417c3e62c6e134b23a431fc8ccd" username="foobar" parentindex="0" starttime="00:00.047" terminationtime="02:00.735" startreason="AnalysisTarget" terminationreason="Timeout" executionstatus="OK">
<virusscan_section>
<scanner name="ClamAV" application_version="0.88.2" signature_file_version="1997">
<classification>Trojan.Spy.Banker-126</classification>
<additional_info/>
</scanner>
<scanner name="BDC/Linux-Console" application_version="7.0.2492" signature_file_version="473949">
<classification>Generic.Banker.Delf.7E6456EC</classification>
<additional_info/>
</scanner>
<scanner name="AntiVir Workstation" application_version="2.1.8-49" signature_file_version="6.36.0.94">
<classification>Trojan/Spy.Banbra.BD</classification>
<additional_info/>
</scanner>

</virusscan_section>
<dll_handling_section>
<load_dll dll="c:\analysis\binary\d337a417c3e62c6e134b23a431fc8ccd.exe" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ntdll.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\kernel32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\user32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\GDI32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\advapi32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\RPCRT4.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\oleaut32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\msvcrt.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ole32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\version.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\comctl32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wininet.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\CRYPT32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\MSASN1.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\SHLWAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\wsock32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2_32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WS2HELP.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Wship6.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\pstorec.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\ATL.DLL" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\mswsock.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\DNSAPI.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\System32\winrnr.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\WLDAP32.dll" successful="1"/>
<load_dll dll="C:\WINDOWS\system32\Secur32.dll" successful="1"/>
<load_dll dll="c:\analysis\binary\d337a417c3e62c6e134b23a431fc8ccd.DEU" successful="0"/>
<load_dll dll="c:\analysis\binary\d337a417c3e62c6e134b23a431fc8ccd.DE" successful="0"/>
<load_dll dll="uxtheme.dll" successful="1"/>
<load_dll dll="olepro32.dll" successful="1"/>
<load_dll dll="WS2_32.DLL" successful="1"/>
<load_dll dll="comctl32.dll" successful="1"/>
<load_dll dll="RASAPI32.DLL" successful="1"/>
<load_dll dll="RTUTILS.DLL" successful="1"/>
<load_dll dll="SHELL32.dll" successful="1"/>
<load_dll dll="USERENV.dll" successful="1"/>
<load_dll dll="netapi32.dll" successful="1"/>
<load_dll dll="rpcrt4.dll" successful="1"/>
</dll_handling_section>
<filesystem_section>
<copy_file filetype="File" srcfile="c:\analysis\binary\d337a417c3e62c6e134b23a431fc8ccd.exe" dstfile="C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\system32.exe" creationdistribution="CREATE_ALWAYS" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<copy_file filetype="File" srcfile="c:\analysis\binary\d337a417c3e62c6e134b23a431fc8ccd.exe" dstfile="C:\Documents and Settings\All Users\start menu\programs\startup\system32.exe" creationdistribution="CREATE_ALWAYS" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<copy_file filetype="File" srcfile="c:\analysis\binary\d337a417c3e62c6e134b23a431fc8ccd.exe" dstfile="C:\WINDOWS\system32\system32.exe" creationdistribution="CREATE_ALWAYS" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="namedpipe" srcfile="\\.\PIPE\lsarpc" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ,SHARE_WRITE" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<get_file_attributes filetype="File" srcfile="c:\autoexec.bat" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<open_file filetype="File" srcfile="c:\autoexec.bat" creationdistribution="OPEN_EXISTING" desiredaccess="FILE_ANY_ACCESS" shareaccess="SHARE_READ" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\&#x2A;.pbk" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\WINDOWS\system32\Ras\&#x2A;.pbk" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\Documents and Settings\foobar\Application Data\Microsoft\Network\Connections\Pbk\&#x2A;.pbk" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<create_open_file filetype="File" srcfile="\Device\RasAcd" creationdistribution="OPEN_ALWAYS" desiredaccess="FILE_ANY_ACCESS,FILE_READ_ACCESS,FILE_READ_DATA,FILE_LIST_DIRECTORY,FILE_WRITE_ACCESS,FILE_WRITE_DATA,FILE_ADD_FILE" shareaccess="SHARE_READ,SHARE_WRITE" flags="FILE_ATTRIBUTE_NORMAL,SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
<find_file filetype="File" srcfile="C:\WINDOWS\system32\Netaps.txt" desiredaccess="FILE_ANY_ACCESS" flags="SECURITY_ANONYMOUS" fileinformationclass="FileBasicInformation"/>
</filesystem_section>
<mutex_section>
<create_mutex name="fataL MuTexXx" owned="0"/>
<create_mutex name="RasPbFile" owned="0"/>
</mutex_section>
<registry_section>
<query_value key="Software\Microsoft\Windows\CurrentVersion\ThemeManager" subkey_or_value="Compositing"/>
<query_value key="Control Panel\Desktop" subkey_or_value="LameButtonText"/>
<create_open_key key="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run" subkey_or_value="Software\Microsoft\Windows\CurrentVersion\Run"/>
<set_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run" subkey_or_value="system32" data="C:\WINDOWS\system32\system32.exe"/>
<query_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion" subkey_or_value="ProductName"/>
<query_value key="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion" subkey_or_value="CurrentVersion"/>
<create_open_key key="HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\MS SETUP &#x28;ACME&#x29;\" subkey_or_value="SOFTWARE\MICROSOFT\MS SETUP &#x28;ACME&#x29;\"/>
<query_value key="HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService" subkey_or_value="DefaultAuthLevel"/>
</registry_section>
<process_section>
<create_process commandline="IExplore WWW_GetWindowInfo" showwindow="SW_SHOWMINNOACTIVE" apifunction="WinExec" successful="0"/>
</process_section>
<service_section>
<open_scmanager servicename="SCM"/>
<open_service servicename="RASMAN" desiredaccess="SERVICE_ALL_ACCESS"/>
</service_section>
<system_info_section>
<get_system_directory/>
<get_computer_name/>
<get_system_time/>
</system_info_section>
<user_section>
<impersonate_user user="foobar" tokenhandle="1392"/>
</user_section>
<window_section>
<enum_window/>
</window_section>
<winsock_section>
<connections_unknown>
<connection connectionestablished="0" socket="0">
<gethostbyname requested_host="foo3" resulting_addr="123.456.789.abc"/>
<gethostbyname requested_host="gsmtp185.google.com" resulting_addr="64.233.185.27"/>
</connection>
</connections_unknown>
<connections_outgoing>
<connection transportprotocol="TCP" remoteaddr="64.233.185.27" remoteport="25" protocol="SMTP" connectionestablished="1" socket="1404">
<smtp_data>
<send_mail rcpts="&#x3C;xtinfecs&#x40;gmail.com&#x3E;" behavior="Simulate_And_Log">From: &#x22;!Mensagem [Cartao]!&#x22; &#x3C;infecs&#x40;isbt.com.br&#x3E;&#x0D;&#x0A;Subject: FOO3 [Infectado por fataL]&#x0D;&#x0A;To: xtinfecs&#x40;gmail.com&#x0D;&#x0A;Date: Thu, 5 Oct 2006 01:15:26 &#x2B;0200&#x0D;&#x0A;X-Priority: 1&#x0D;&#x0A;X-Library: Indy 9.00.10&#x0D;&#x0A;&#x0D;&#x0A;!============fataL CorP============!&#x0D;&#x0A;!Maquina&#x3F;: FOO3!&#x0D;&#x0A;!V&#xED;tima LOGADA: !&#x0D;&#x0A;!IP: 123.456.789.abc!&#x0D;&#x0A;!Data de Abertura: 05.10.2006 Hora de Abertura: 01:15:24 &#x0D;&#x0A;!Sistema&#x3F;: Microsoft Windows XP &#x28;version 5.1&#x29;!&#x0D;&#x0A;!Endere&#xE7;o da Placa: 00-0C-29-43-21-5A!&#x0D;&#x0A;!============fataL CorP============!&#x0D;&#x0A;</send_mail>
</smtp_data>
</connection>
</connections_outgoing>
</winsock_section>

</process>
<process index="2" pid="704" filename="services.exe" filesize="-1" username="SYSTEM" parentindex="0" starttime="00:02.641" terminationtime="02:00.766" startreason="SCM" terminationreason="Timeout" executionstatus="OK">
</process>
</processes>
</analysis>
