| Packed MD5 | 013a5ba10e3fc8a039b045530381d957 |
| Priority | 3 |
| First | 01/04/2010 |
| Last | 01/17/2010 |
| Count | |
| History | |
| Unpacked MD5 | 1d04d6dc84e8567d1d9d991e78294986 |
| AV Hits | 40 |
| AV Count | 32 |
| CC Servers | |
| DNS Lookups | TW:m.DRD3H.COM |
| Failed Connects | TW:122.117.146.70:6668 |
| AV Name | AhnLab-V3:IRCBot.206336.K, AntiVir:TRDownloader.Gen, Authentium:Heuristic-210!Eldorado, Avast:MISSED, AVG:RBot.AI, BitDefender:Bot.91681, CAT-QuickHeal:Rbot.aus, ClamAV:Mybot-7905, DrWeb:HLLW.MyBot.5, eSafe:HEURCrypted, eTrust-Vet:Rbot.JNW, Ewido:MISSED, FileAdvisor:MISSED, Fortinet:RBot.AUS!tr.bdr, F-Prot:Heuristic-210!Eldorado, F-Secure:Rbot.aus, Ikarus:Rbot, Kaspersky:Rbot.aus, McAfee:Sdbot.worm, Microsoft:Rbot.gen, NOD32v2:MISSED, Norman:DLoader.NNTE, Panda:MISSED, Prevx1:MISSED, Rising:Mybot.bar, Sophos:MalGeneric-A, Sunbelt:SDBot, Symantec:Spybot.Worm, TheHacker:BackdoorRbot.aus, VBA32:OScope.Backdoor.Sdbot.Cgen, VirusBuster:Rbot.AKKE, Webwasher-Gateway:MISSED |
| WinXP Files | |
| WinXP Processes | Cilevb.com, CMD.EXE, CSRSS.EXE, EXPLORER.EXE, LSASS.EXE, MSMSGS.EXE, SERVICES.EXE, SPOOLSV.EXE, SVCHOST.EXE, WINLOGON.EXE |
| WinXP Registries | HKEY_CLASSES_ROOT@...HKEY_CLASSES_ROOT\.key, HKEY_LOCAL_MACHINE@...Classes\.key, HKEY_LOCAL_MACHINE@...CurrentVersion\RunServices, HKEY_USERS@...Microsoft\OLE, HKEY_CLASSES_ROOT@...HKEY_CLASSES_ROOT\\.key, HKEY_LOCAL_MACHINE@...Classes\\.key, HKEY_LOCAL_MACHINE@...CurrentVersion\\RunServices, HKEY_USERS@...Microsoft\\OLE |
| WinXP Ports | 1037, 1037, 42647, 4309, 4310, 4311, 4312, 4313, 4314, 4315, 4316, 4317, 4318, 4319, 4320, 4321, 4322, 4323, 4324, 4325, 4326, 4327, 4328, 4329, 4330, 4331, 4332, 4333, 4334, 4335, 4336, 4337, 4338, 4339, 4340, 4341, 4342, 4343, 4344, 4345, 4346, 4347, 3728, 1040, 2109, 2110, 2111, 2112, 2113, 2114, 2115, 2116, 2117, 2118, 2119, 2120, 2121, 2122, 2123, 2124, 2125, 2126, 2127, 2128, 2129, 2130, 2131, 2132, 2133, 2134, 2135, 2136, 2137, 42392, 1035, 39705, 4004, 4005, 4006, 4007, 4008, 4009, 4010, 4011, 4012, 4013, 4014, 4015, 4016, 4017, 4018, 4019, 4020, 4021, 4022, 4023, 4024, 4025, 4026, 4027, 4028, 4029, 4030, 4031, 4032 |
| Win-2Kf Files | |
| Win-2Kf Processes | Cilevb.com |
| Win-2Kf Registries | HKEY_CLASSES_ROOT@...HKEY_CLASSES_ROOT\\.key, HKEY_LOCAL_MACHINE@...Classes\\.key, HKEY_LOCAL_MACHINE@...CurrentVersion\\RunServices, HKEY_USERS@...InternetSettings\\5.0, HKEY_USERS@...InternetSettings\\Connections, HKEY_USERS@...Microsoft\\OLE |
| Win-2Kf Ports | 1044, 1938, 3207, 3208, 3209, 3210, 3211, 3212, 3213, 3214, 3215, 3216, 3217, 3218, 3219, 3220, 3221, 3222, 3223, 3224, 3225, 3226, 3227, 3228, 3229, 3230, 3231, 3232, 3233, 3234, 3235, 3236, 3237, 3728, 1030, 4489, 4490, 4491, 4492, 4493, 4494, 4495, 4496, 4497, 4498, 4499, 4500, 4501, 4502, 4503, 4504, 4505, 4506, 4507, 4508, 4509, 4510, 4511, 4512, 4513, 4514, 4515, 4516, 4517, 4518, 4519, 62472, 3403, 3404, 3405, 3406, 3407, 3408, 3409, 3410, 3411, 3412, 3413, 3414, 3415, 3416, 3417, 3418, 3419, 3420, 3421, 3422, 3423, 3424, 3425, 3426, 3427, 3428, 3429, 3430, 3431, 3432, 3433, 3434, 56811, 2947, 3467, 3468, 3469, 3470, 3471, 3472, 3473, 3474, 3475, 3476, 3477, 3478, 3479, 3480, 3481, 3482, 3483, 3484, 3485, 3486, 3487, 3488, 3489, 3490, 3491, 3492, 3493, 3494, 3495, 3496, 3497, 3498, 2378, 2379, 2380, 2381, 2382, 2383, 2384, 2385, 2386, 2387, 2388, 2389, 2390, 2391, 2392, 2393, 2394, 2395, 2396, 2397, 2398, 2399, 2400, 2401, 2402, 2403, 2404, 2405, 2406, 2407, 2408, 2409, 2410, 8233 |
| Create Events | |
| Create Files | |
| Create RegKeys | Software\Microsoft\OLE,SYSTEM\CurrentControlSet\Control\Lsa |
| Open RegKeys | |
| Service Starts | |
| Service Deletes | |
| Service Creates | |
| Cluster | |
| Cluster Confidence | |
| Packer ID1 | ASPack |
| Packer ID2 | |
| Embedded DNS | m.DRD3H.COM, m.DRD3H.COM, Cilevb.com, Cilevb.com, clone.ac, clone.pm, enz.ps, box.mv, enz.de, clone.ni, enz.cy, enz.ac, enz.pm, enz.gh, box.net, box.cm, dcc.gt, enz.se, enz.pr, enz.pt, box.ps, box.ni, enz.al, enz.id, vuln.st |
| String Count | 3292 |
| String Link | text |
| String MD5 | 9c5543bd275663d243224bc2f0c1e28c |
| Timerange | 365 Days |
| Unpack Status | unknown (unpacked : 0 : Unpacking Provided Binary. (Code,Data) = (49.98%, 23.55%)) |
| Countries | 7 |
| Unpacked Link | |
| Callgraph | |
| API Resolution | |
| Comment | none |