Analysis Summary:
| Analysis Date | 23.11.2006 13:12:12 |
|---|---|
| Sandbox Version | Beta 1.83 |
| Filename | 508ffdec653b5e75cdd7d7312d9648c1.exe |
Technical Details:
| Analysis Number | 1 | ||||||
|---|---|---|---|---|---|---|---|
| Parent ID | 0 | ||||||
| Process ID | 1540 | ||||||
| Filename | c:\508ffdec653b5e75cdd7d7312d9648c1.exe | ||||||
| Filesize | 21879 bytes | ||||||
| MD5 | 508ffdec653b5e75cdd7d7312d9648c1 | ||||||
| Start Reason | AnalysisTarget | ||||||
| Termination Reason | Timeout | ||||||
| Start Time | 00:00.047 | ||||||
| Stop Time | 02:00.187 | ||||||
| COM |
COM Get Class Object: C:\WINDOWS\system32\urlmon.dll, Interface ID: ({00000001-0000-0000-C000-000000000046}) |
||||||
| DLL-Handling |
|
||||||
| Filesystem |
|
||||||
| INI Files |
|
||||||
| Mutexes |
Creates Mutex: ZonesCounterMutex Creates Mutex: ZonesCacheCounterMutex Creates Mutex: ZonesLockedCacheCounterMutex Creates Mutex: RasPbFile |
||||||
| Registry |
|
||||||
| Process Management |
Creates Process - Filename (c:\loaders.exe) CommandLine: () As User: () Creation Flags: () |
||||||
| Service Management |
Open Service Manager - Name: "SCM" Open Service - Name: "RASMAN" |
||||||
| System Info |
Get System Directory Get Computer Name |
||||||
| User Management |
Impersonate User - Domain: () User: (foobar) Get User Name |
||||||
| Network Activity |
|
| Analysis Number | 2 |
|---|---|
| Parent ID | 0 |
| Process ID | 704 |
| Filename | services.exe |
| Filesize | -1 bytes |
| MD5 | |
| Start Reason | SCM |
| Termination Reason | Timeout |
| Start Time | 00:05.828 |
| Stop Time | 02:00.422 |
| Process Management | Creates Process - Filename ()
CommandLine: ("C:\WINDOWS\system32\lxsys.exe") As User: () Creation
Flags: (CREATE_SUSPENDED,CREATE_UNICODE_ENVIRONMENT,DETACHED_PROCESS) |
| Analysis Number | 3 | ||||||
|---|---|---|---|---|---|---|---|
| Parent ID | 1 | ||||||
| Process ID | 1416 | ||||||
| Filename | c:\loaders.exe c:\loaders.exe | ||||||
| Filesize | -1 bytes | ||||||
| MD5 | |||||||
| Start Reason | CreateProcess | ||||||
| Termination Reason | NormalTermination | ||||||
| Start Time | 00:13.953 | ||||||
| Stop Time | 00:25.812 | ||||||
| DLL-Handling |
|
||||||
| Filesystem |
|
||||||
| Registry |
|
||||||
| Process Management |
Kill Process - Filename () CommandLine: () Target PID: (1416) As User: () Creation Flags: () |
||||||
| Service Management |
Open Service Manager - Name: "SCM" Open Service - Name: "Window LFX Services" Create Service - Name: (Window LFX Services) Display Name: (Window LFX Services) File Name: ("C:\WINDOWS\system32\lxsys.exe") Control: () Start Type: (SERVICE_AUTO_START) Start Service - Name: (Window LFX Services) Display Name: () File Name: () Control: () Start Type: () Change Service Configuration - Name: (Window LFX Services) Display Name: () File Name: () Control: () Start Type: (SERVICE_NO_CHANGE) Change Service Configuration - Name: (Window LFX Services) Display Name: (Window LFX Services) File Name: () Control: () Start Type: (SERVICE_NO_CHANGE) |
||||||
| System Info |
Get Windows Directory |
||||||
| Network Activity |
| Analysis Number | 4 | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Parent ID | 2 | ||||||||
| Process ID | 1484 | ||||||||
| Filename | C:\WINDOWS\system32\lxsys.exe | ||||||||
| Filesize | 46372 bytes | ||||||||
| MD5 | ad09bf5997fc4a30012eb73e553c6830 | ||||||||
| Start Reason | CreateProcess | ||||||||
| Termination Reason | Timeout | ||||||||
| Start Time | 00:20.734 | ||||||||
| Stop Time | 02:00.250 | ||||||||
| DLL-Handling |
|
||||||||
| Filesystem |
|
||||||||
| Mutexes |
Creates Mutex: NC�I_CHAR(0x08)_� Creates Mutex: RasPbFile |
||||||||
| Network Shares |
Delete Share - Host: () Network Ressource: (IPC$) Filename: () As User: () Delete Share - Host: () Network Ressource: (ADMIN$) Filename: () As User: () Delete Share - Host: () Network Ressource: (C$) Filename: () As User: () Enum Network Shares - Network Ressource: () Host: () |
||||||||
| Registry |
|
||||||||
| Service Management |
Open Service Manager - Name: "SCM" Open Service - Name: "Tlntsvr" Open Service - Name: "RemoteRegistry" Open Service - Name: "RASMAN" Open Service - Name: "Messenger" Open Service - Name: "SharedAccess" Open Service - Name: "wscsvc" Control Service - Name: (Tlntsvr) Display Name: () File Name: () Control: (SERVICE_CONTROL_STOP) Start Type: () Control Service - Name: (RemoteRegistry) Display Name: () File Name: () Control: (SERVICE_CONTROL_STOP) Start Type: () Control Service - Name: (Messenger) Display Name: () File Name: () Control: (SERVICE_CONTROL_STOP) Start Type: () Control Service - Name: (SharedAccess) Display Name: () File Name: () Control: (SERVICE_CONTROL_STOP) Start Type: () Control Service - Name: (wscsvc) Display Name: () File Name: () Control: (SERVICE_CONTROL_STOP) Start Type: () |
||||||||
| System Info |
Get Computer Name |
||||||||
| Window |
Find Window - Class Name (mIRC) Window Name () Find Window - Class Name (AIM_CSignOnWnd) Window Name () |
||||||||
| Network Activity |
Outgoing connection to remote server: hi.ircstyle.net port 8080 Outgoing connection to remote server: hi.ircstyle.net port 8080 Outgoing connection to remote server: hi.ircstyle.net port 8080 Outgoing connection to remote server: hi.ircstyle.net port 8080 Outgoing connection to remote server: hi.ircstyle.net port 8080 Outgoing connection to remote server: hi.ircstyle.net port 8080 Outgoing connection to remote server: hi.ircstyle.net port 8080 |
||||||||
Report generated at 23.11.2006 13:12:12 with CWSandbox Version Beta 1.83
This analysis was created by the CWSandbox Copyright © 2006 Carsten Willems
Copyright © 1996-2006 Sunbelt Software. All rights reserved.