PDF

Print

ThreatScope Analysis Report

For file Cry-XOR-file001.hex uploaded 2013-01-25 at 06:10:09 AM

Threat level: Suspicious

This file is suspicious. Monitor communications from any machine that has run the file to detect suspicious behavior.

Threat Assessment

Drops executable file(s)

Writes to the filesystem in a Windows system directory

Screenshots: None

File details:

Hash MD5

1ad6afeec913f4c3a0ffce0093cddf21

File size

82.17 KB

Hash SHA-1

64a5a3d125a2d1fa16bc24adfbe0ef44d4a023b7

File uploaded

2013-01-25 06:10:09 AM

Hash SHA-256

a9500f44ef6e7c70b41b3fe42da26861d8efd7dad15fb8234b26e163076dfe07

Report created

2013-01-25 06:11:51 AM

Technical Details

Requested HTTP URLs


No HTTP communications were detected.

Resolved hostnames


DNS was not used to resolve any hostnames.

IP addresses


No IP addresses were requested.

File system modifications

The analyzed file changes the following items in the file system. This type of change can be performed by both malicious and benign files.

Event

File path

Creates file

c:\WINDOWS\system32\xmlcore.dat

Writes file

c:\WINDOWS\system32\xmlcore.dat

Creates file

c:\WINDOWS\ntshrui.dll

Writes file

c:\WINDOWS\ntshrui.dll

Process modifications

The analyzed file affected the following system processes.

Event

File path

Creates process

Sample started

Creates process

C:\WINDOWS\explorer.exe

Registry


No Windows Registry changes were made.

Global system events

The following global system events were detected.

Event

Name

Creates semaphore

shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1}df21.exe

Creates mutex

SHIMLIB_LOG_MUTEX

Creates semaphore

shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1}

Creates event

Global\crypt32LogoffEvent

Creates event

DINPUTWINMM

Creates event

Global\userenv: User Profile setup eventE1}

Creates mutex

ExplorerIsShellMutex

Creates event

Global\ScmCreatedEvent

Creates semaphore

shell.{210A4BA0-3AEA-1069-A2D9-08002B30309D}

Creates semaphore

shell.{090851A5-EB96-11D2-8BE4-00C04FA31A66}

Creates event

_fCanRegisterWithShellService

Creates semaphore

shell.{7CB834F0-527B-11D2-9D1F-0000F805CA57}

Creates mutex

Shell.CMruPidlList

Creates event

ShellReadyEvent

Creates event

Local\HotPlug_TaskBarIcon_Event

Creates event

HPlugEjectEvent

Forcepoint has made an effort to determine if your submission is malicious however, Forcepoint cannot guarantee the accuracy of the result