Report - CrySyS Lab
Report - CrySyS Lab
Report - CrySyS Lab
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
The ~24kb size module from index3.hta contains 4 distinct MZ headers. We name them atl_1 to atl_4<br />
in the hash list. The 24k long file is compiled on 2005-04-04.<br />
Submodule atl_1<br />
refers to \atlsrv.exe \altnet32.exe \atlsrv.exe sdmnet32.dll srvshell.dll sdmnet.dll srvshell32.dll<br />
It contains debug information that gives hint on the code goal:<br />
i:\119prj\Bv\REPLACE Kasp\3 otdel\1.2m UnderKasper\installer\Release\installer.pdb<br />
The module communicates with other modules through the registry, under the key<br />
Software\Microsoft\Internet Explorer\MainFileSRC<br />
This module saves an interesting email address “” into the registry.<br />
The module also uses a mutex named “{118-32-FOOTBOLL-15}” and it is also able to set<br />
SOFTWARE\Microsoft\Windows\CurrentVersion\Run for its goals.<br />
It modifies “\AUTOEXE.BAT” (no typo) in some cases to:<br />
:LOOP<br />
DEL "%s"'<br />
IF EXIST "%s" GOTO LOOP<br />
DEL "%s"<br />
Module atl_2<br />
Figure 48 – .bat file created by submodule atl_1<br />
This module uses mutexes “{132-79-FOOTBOLL-18}” , “{118-32-FOOTBOLL-15}” and {167-53-<br />
BADFOOD-14}, as well as DLLs sdmnet32.dll sdmnet.dll srvshell.dll or srvshell32.dll<br />
It has some relation to explorer.exe, and it calls the _NetBiosDisconnectNt export of another module.<br />
Basically this module is a middle layer between atl_1 and atl_3.<br />
Module atl_3<br />
Compile time: 2005-04-04<br />
This module is UPX compressed (ver 1.92 – released in 2004). When uncompressed, this module is<br />
28kb long, therefore, it is the biggest “main” module among the four submodules.<br />
It provides functionality to other modules, the defined export functions are as follows, where the<br />
most important export function is probably NetBiosDisconnectNt:<br />
_NetBiosConnectNt@8<br />
_NetBiosDisconnectNt@8<br />
_NtDR@0<br />
46