Research Article

Osiris: A Malware Behavior Capturing System Implemented at Virtual Machine Monitor Layer

Table 2

Some detailed analysis results for backdoor/Win32.Hupigon.hypj.

BehaviorBehavior parameter
Description from human analyst Osiris

Create file%Program Files%Common FilesMicrosoft Shared
MSInfoVirtualnat.exe;
C:Program FilesCommon FilesMicrosoft Shared
MSINFOVirtualnat.exe
Copy file×Source path: C:Program FilesCommon Files
Microsoft SharedMSINFOVirtualnat.exe
Target path: C:Program Files_Virtualnat.exe
Search fileklif.sysC:WINDOWSsystem32drivers/klif.sys
Set registry keyHKEY_LOCAL_MACHINESYSTEMCurrentControlSet
ServicesVirtualnatDescription
HKEY_LOCAL_MACHINESYSTEM
CurrentControlSetServicesVirtualnat
Create processiexeplore.exeC:program filesinternet explorerIEXPLORE.EXE
Create processcalc.exeC:WINDOWSsystem32calc.exe
Inject processiexeplore.exeiexeplore.exe
Inject processcalc.execalc.exe
Create service×Image path: C:Program FilesCommon Files
Microsoft SharedMSINFOVirtualnat.exe
Description: Virtual Network Control Service
Connect remote portTCP; port number: 80; IP address: 60.190.92.75TCP; port number: 80
Open URL×http://www.5ai8.net/ip.txt
Create window×TApplication