Anubis - Analysis Report Analysis Report for virus.exe I n t e r n a t i o n a lS e c u r eS y s t e m sL a b V i e n n aU n i v e r s i t yo fT e c h n o l o g y, Eu r e c o mF r a n c e, UC Sa n t aB a r b a r a C o n t a c t :a n u b i s @ i s e c l a b . o r g Dependency overview: virus.exeC:\virus.exe Analysis reason: Primary Analysis Subject iexplore.exeC:\Program Files\Internet Explorer\iexplore.exe Analysis reason: Started by virus.exe iexplore.exeC:\Program Files\Internet Explorer\iexplore.exe Analysis reason: Started by virus.exe Table of Contents: 1. General Information..............................................................................................................................................................................................4 2. virus.exe................................................................................................................................................................................................................4 a) Registry Activities.............................................................................................................................................................................................4 b) File Activities....................................................................................................................................................................................................5 c) Process Activities................................
I n t e r n a t i o n a l S e c u r e S y s t e m s L a b V i e n n a U n i v e r s i t y o f T e c h n o l o g y , E u r e c o m F r a n c e , U C S a n t a B a r b a r a C o n t a c t : a n u b i s @ i s e c l a b . o r g
Dependency overview:
virus.exeC:\virus.exe Analysis reason: Primary Analysis Subject iexplore.exeC:\Program Files\Internet Explorer\iexplore.exe Analysis reason: Started by virus.exe iexplore.exeC:\Program Files\Internet Explorer\iexplore.exe Analysis reason: Started by virus.exe
Table of Contents:
1. General Information.............................................................................................................................................................................................. 4 2. virus.exe................................................................................................................................................................................................................ 4 a) Registry Activities............................................................................................................................................................................................. 4 b) File Activities.................................................................................................................................................................................................... 5 c) Process Activities............................................................................................................................................................................................. 6 3. iexplore.exe........................................................................................................................................................................................................... 6 a) Registry Activities............................................................................................................................................................................................. 7 b) File Activities.................................................................................................................................................................................................. 10 c) Network Activities........................................................................................................................................................................................... 11 4. iexplore.exe......................................................................................................................................................................................................... 11 a) Registry Activities........................................................................................................................................................................................... 12 b) File Activities.................................................................................................................................................................................................. 12
Analysis Report for virus.exe - submitted on 04/13/15, 18:50:01 UTC
1. General Information
Information about Anubis' invocation Time needed: Report created: Termination reason: Program version:
2. virus.exe
General information about this executable Analysis Reason: Filename: Command Line: Process-status at analysis end: Exit Code:
Load-time Dlls Module Name C:\WINDOWS\system32\ntdll.dll C:\WINDOWS\system32\kernel32.dll C:\WINDOWS\system32\user32.dll C:\WINDOWS\system32\GDI32.dll
Run-time Dlls Module Name C:\WINDOWS\system32\Apphelp.dll C:\WINDOWS\system32\VERSION.dll C:\WINDOWS\system32\ADVAPI32.DLL C:\WINDOWS\system32\RPCRT4.dll C:\WINDOWS\system32\Secur32.dll
2.a) virus.exe - Registry Activities
264 s 04/13/15, 18:50:01 UTC Timeout 1.76.3886
Primary Analysis Subject virus.exe "C:\virus.exe" dead 0