Analysis Summary:
| Analysis Date | 24.09.2006 04:04:01 |
|---|---|
| Sandbox Version | Beta 1.81 |
| Filename | 41ba68620a5aa57b1e3b9ebcd45fbbd0.exe |
Technical Details:
| Analysis Number | 1 | ||||
|---|---|---|---|---|---|
| Parent ID | 0 | ||||
| Process ID | 684 | ||||
| Filename | c:\analysis\binary\41ba68620a5aa57b1e3b9ebcd45fbbd0.exe | ||||
| Filesize | 15872 bytes | ||||
| MD5 | 41ba68620a5aa57b1e3b9ebcd45fbbd0 | ||||
| Start Reason | AnalysisTarget | ||||
| Termination Reason | NormalTermination | ||||
| Start Time | 00:00.187 | ||||
| Stop Time | 00:29.562 | ||||
| Detection | Trojan.Clicker-4
(ClamAV) OK (BDC/Linux-Console) OK (AntiVir Workstation) |
||||
| COM |
COM Create Instance: %SystemRoot%\system32\shdocvw.dll, ProgID: (), Interface ID: ({000214E6-0000-0000-C000-000000000046}) COM Create Instance: %SystemRoot%\system32\webcheck.dll, ProgID: (), Interface ID: ({085FB2C0-0DF8-11D1-8F4B-00A0C905413F}) COM Create Instance: shdocvw.dll, ProgID: (InternetShortcut), Interface ID: ({CABB0DA0-DA57-11CF-9974-0020AFD79762}) COM Create Instance: C:\WINDOWS\system32\urlmon.dll, ProgID: (), Interface ID: ({79EAC9EE-BAF9-11CE-8C82-00AA004BA90B}) |
||||
| DLL-Handling |
|
||||
| Filesystem |
|
||||
| Mutexes |
Creates Mutex: ZonesCounterMutex Creates Mutex: ZonesCacheCounterMutex Creates Mutex: ZonesLockedCacheCounterMutex |
||||
| Registry |
|
||||
| Process Management |
Creates Process - Filename (http://www.ifreeclub.com/redir.aspx?oid=1105) CommandLine: () As User: () Creation Flags: () Creates Process - Filename (http://www.ifreeclub.com/redir.aspx?oid=1105) CommandLine: () As User: () Creation Flags: () |
||||
| System Info |
Get System Directory Get Computer Name Get System Time |
||||
| User Management |
Get User Name |
||||
| Window |
Enum Windows |
||||
| Network Activity |
| Analysis Number | 2 | |||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Parent ID | 1 | |||||||||||||||||||||||||||||||||||||||||||||
| Process ID | 1320 | |||||||||||||||||||||||||||||||||||||||||||||
| Filename | C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe -nohome | |||||||||||||||||||||||||||||||||||||||||||||
| Filesize | -1 bytes | |||||||||||||||||||||||||||||||||||||||||||||
| MD5 | ||||||||||||||||||||||||||||||||||||||||||||||
| Start Reason | CreateProcess | |||||||||||||||||||||||||||||||||||||||||||||
| Termination Reason | Timeout | |||||||||||||||||||||||||||||||||||||||||||||
| Start Time | 00:11.031 | |||||||||||||||||||||||||||||||||||||||||||||
| Stop Time | 02:00.156 | |||||||||||||||||||||||||||||||||||||||||||||
| COM |
COM Create Instance: %SystemRoot%\system32\shdocvw.dll, ProgID: (), Interface ID: ({00000000-0000-0000-C000-000000000046}) COM Create Instance: %SystemRoot%\system32\shdocvw.dll, ProgID: (), Interface ID: ({47851649-A2EF-4E67-BAEC-C6A153AC72EC}) COM Create Instance: %SystemRoot%\system32\SHELL32.dll, ProgID: (), Interface ID: ({EE1F7637-E138-11D1-8379-00C04FD918D0}) COM Create Instance: %SystemRoot%\System32\cscui.dll, ProgID: (), Interface ID: ({0C6C4200-C589-11D0-999A-00C04FD655E1}) COM Create Instance: %SystemRoot%\system32\shdocvw.dll, ProgID: (), Interface ID: ({85CB6900-4D95-11CF-960C-0080C7F4EE85}) COM Create Instance: , ProgID: (), Interface ID: ({00000149-0000-0000-C000-000000000046}) COM Create Instance: C:\WINDOWS\system32\urlmon.dll, ProgID: (), Interface ID: ({79EAC9EF-BAF9-11CE-8C82-00AA004BA90B}) COM Create Instance: %SystemRoot%\system32\shdocvw.dll, ProgID: (), Interface ID: ({000214E6-0000-0000-C000-000000000046}) COM Create Instance: C:\WINDOWS\system32\urlmon.dll, ProgID: (), Interface ID: ({79EAC9EE-BAF9-11CE-8C82-00AA004BA90B}) COM Create Instance: %SystemRoot%\system32\shdocvw.dll, ProgID: (), Interface ID: ({A5ACA655-7FB8-43DC-A433-8D87B69C70A0}) COM Create Instance: C:\WINDOWS\system32\msimtf.dll, ProgID: (), Interface ID: ({08C0E040-62D1-11D1-9326-0060B067B86E}) COM Create Instance: C:\WINDOWS\system32\jscript.dll, ProgID: (JScript), Interface ID: ({BB1A2AE1-A4F9-11CF-8F20-00805F2CD064}) COM Create Instance: , ProgID: (), Interface ID: ({00000146-0000-0000-C000-000000000046}) COM Create Instance: , ProgID: (), Interface ID: ({6C736DC1-AB0D-11D0-A2AD-00A0C90F27E8}) COM Create Instance: C:\WINDOWS\system32\mlang.dll, ProgID: (), Interface ID: ({275C23E1-3747-11D0-9FEA-00AA003F8646}) COM Create Instance: %SystemRoot%\system32\shdocvw.dll, ProgID: (), Interface ID: ({062E1261-A60E-11D0-82C2-00C04FD5AE38}) COM Get Class Object: %SystemRoot%\system32\shdocvw.dll, Interface ID: ({00000001-0000-0000-C000-000000000046}) COM Get Class Object: oleaut32.dll, Interface ID: ({D5F569D0-593B-101A-B569-08002B2DBF7A}) COM Get Class Object: %SystemRoot%\system32\mshtml.dll, Interface ID: ({00000001-0000-0000-C000-000000000046}) COM Get Class Object: %SystemRoot%\system32\mshtml.dll, Interface ID: ({00000001-0000-0000-C000-000000000046}) COM Get Class Object: C:\WINDOWS\system32\urlmon.dll, Interface ID: ({00000001-0000-0000-C000-000000000046}) |
|||||||||||||||||||||||||||||||||||||||||||||
| DLL-Handling |
|
|||||||||||||||||||||||||||||||||||||||||||||
| Filesystem |
|
|||||||||||||||||||||||||||||||||||||||||||||
| INI Files |
|
|||||||||||||||||||||||||||||||||||||||||||||
| Mutexes |
Creates Mutex: Shell.CMruPidlList Creates Mutex: ZonesCounterMutex Creates Mutex: ZonesCacheCounterMutex Creates Mutex: ZonesLockedCacheCounterMutex Creates Mutex: RasPbFile Creates Mutex: CTF.LBES.MutexDefaultS-1-5-21-1757981266-1202660629-839522115-1003 Creates Mutex: CTF.Compart.MutexDefaultS-1-5-21-1757981266-1202660629-839522115-1003 Creates Mutex: CTF.Asm.MutexDefaultS-1-5-21-1757981266-1202660629-839522115-1003 Creates Mutex: CTF.Layouts.MutexDefaultS-1-5-21-1757981266-1202660629-839522115-1003 Creates Mutex: CTF.TMD.MutexDefaultS-1-5-21-1757981266-1202660629-839522115-1003 Creates Mutex: MSIMGSIZECacheMutex Opens Mutex: WininetStartupMutex Opens Mutex: _!SHMSFTHISTORY!_ |
|||||||||||||||||||||||||||||||||||||||||||||
| Registry |
|
|||||||||||||||||||||||||||||||||||||||||||||
| Process Management |
Open Process - Filename (C:\WINDOWS\Explorer.EXE) Target PID: (1584) |
|||||||||||||||||||||||||||||||||||||||||||||
| Service Management |
Open Service Manager - Name: "SCM" Open Service - Name: "RASMAN" |
|||||||||||||||||||||||||||||||||||||||||||||
| System Info |
Get System Directory Get Computer Name Get System Time |
|||||||||||||||||||||||||||||||||||||||||||||
| User Management |
Impersonate User - Domain: () User: (foobar) Impersonate User - Domain: () User: (foobar) Get User Name |
|||||||||||||||||||||||||||||||||||||||||||||
| Window |
Find Window - Class Name ($C0C7) Window Name () Find Window - Class Name (Shell_TrayWnd) Window Name () Find Window - Class Name (IEFrame) Window Name () Find Window - Class Name (MS_AutodialMonitor) Window Name () Find Window - Class Name (MS_WebcheckMonitor) Window Name () Enum Windows |
|||||||||||||||||||||||||||||||||||||||||||||
| Network Activity |
Outgoing connection to remote server: 64.34.179.202 TCP port 80 |
| Analysis Number | 3 |
|---|---|
| Parent ID | 0 |
| Process ID | 528 |
| Filename | services.exe |
| Filesize | -1 bytes |
| MD5 | |
| Start Reason | SCM |
| Termination Reason | Timeout |
| Start Time | 00:28.797 |
| Stop Time | 02:00.156 |
Report generated at 24.09.2006 04:04:01 with CWSandbox Version Beta 1.81
This analysis was created by the CWSandbox Copyright © 2006 Carsten Willems
Copyright © 1996-2006 Sunbelt Software. All rights reserved.