| Packed MD5 | 29a3030e160f25ace323c58fcb55dbbf |
| Priority | 1 |
| First | 01/04/2010 |
| Last | 01/16/2010 |
| Count | |
| History | |
| Unpacked MD5 | 1d04d6dc84e8567d1d9d991e78294986 |
| AV Hits | 41 |
| AV Count | 32 |
| CC Servers | |
| DNS Lookups | TW:m.DRD3H.COM |
| Failed Connects | TW:122.117.146.70:6668 |
| AV Name | AhnLab-V3:IRCBot.206336.K, AntiVir:TRDownloader.Gen, Authentium:Trojan5.JEJ, Avast:_Trojan-gen, AVG:RBot.AI, BitDefender:Bot.91681, CAT-QuickHeal:Rbot.aus, ClamAV:PUA.Packed.ASPack212, DrWeb:HLLW.MyBot.5, eSafe:HEURCrypted, eTrust-Vet:Rbot.JNW, Ewido:MISSED, FileAdvisor:MISSED, Fortinet:RBot.AUS!tr.bdr, F-Prot:Trojan5.JEJ, F-Secure:Bot.91681, Ikarus:Bot, Kaspersky:Packed.Black.d, McAfee:Sdbot.worm!bn, Microsoft:Rbot.gen, NOD32v2:MISSED, Norman:DLoader.NNTE, Panda:TrjCI.A, Prevx1:MISSED, Rising:Mybot.bar, Sophos:MalGeneric-A, Sunbelt:Generic!BT, Symantec:Spybot.Worm, TheHacker:BackdoorRbot.aus, VBA32:OScope.Backdoor.Sdbot.Cgen, VirusBuster:Rbot.AKKE, Webwasher-Gateway:MISSED |
| WinXP Files | |
| WinXP Processes | Cilevb.com, CMD.EXE, CSRSS.EXE, EXPLORER.EXE, LSASS.EXE, MSMSGS.EXE, SERVICES.EXE, SPOOLSV.EXE, SVCHOST.EXE, WINLOGON.EXE |
| WinXP Registries | HKEY_CLASSES_ROOT@...HKEY_CLASSES_ROOT\.key, HKEY_LOCAL_MACHINE@...Classes\.key, HKEY_LOCAL_MACHINE@...CurrentVersion\RunServices, HKEY_USERS@...Microsoft\OLE, HKEY_CLASSES_ROOT@...HKEY_CLASSES_ROOT\\.key, HKEY_LOCAL_MACHINE@...Classes\\.key, HKEY_LOCAL_MACHINE@...CurrentVersion\\RunServices, HKEY_USERS@...Microsoft\\OLE |
| WinXP Ports | 1034, 1034, 2421, 2422, 2423, 2424, 2425, 2426, 2427, 2428, 2429, 2430, 2431, 2432, 2433, 2434, 2435, 2436, 2437, 2438, 2439, 2440, 2441, 2442, 2443, 2444, 2445, 2446, 2447, 2448, 2449, 2450, 2451, 2452, 2453, 40299, 3728, 1035, 1094, 1095, 1096, 1097, 1098, 1099, 1100, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1111, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 1130, 1131, 1132, 42222 |
| Win-2Kf Files | |
| Win-2Kf Processes | Cilevb.com |
| Win-2Kf Registries | HKEY_CLASSES_ROOT@...HKEY_CLASSES_ROOT\\.key, HKEY_LOCAL_MACHINE@...Classes\\.key, HKEY_LOCAL_MACHINE@...CurrentVersion\\RunServices, HKEY_USERS@...InternetSettings\\5.0, HKEY_USERS@...InternetSettings\\Connections, HKEY_USERS@...Microsoft\\OLE |
| Win-2Kf Ports | 1048, 2347, 2348, 2349, 2350, 2351, 2352, 2353, 2354, 2355, 2356, 2357, 2358, 2359, 2360, 2361, 2362, 2363, 2364, 2365, 2366, 2367, 2368, 2369, 2370, 2371, 2372, 2373, 2374, 2375, 2376, 2377, 2378, 2379, 33186, 3868, 3869, 3728, 1027, 1030, 1031, 1032, 1033, 1034, 1035, 1036, 1037, 1038, 1039, 1040, 1041, 1042, 1043, 1044, 1045, 1046, 1047, 1049, 1050, 1051, 1052, 1053, 1054, 1055, 1056, 1057, 1058, 1059, 1060, 1061, 1062, 1063, 1064, 1065, 1066, 1067, 19049 |
| Create Events | |
| Create Files | |
| Create RegKeys | Software\Microsoft\OLE,SYSTEM\CurrentControlSet\Control\Lsa |
| Open RegKeys | |
| Service Starts | |
| Service Deletes | |
| Service Creates | |
| Cluster | |
| Cluster Confidence | |
| Packer ID1 | ASPack |
| Packer ID2 | |
| Embedded DNS | m.DRD3H.COM, m.DRD3H.COM, Cilevb.com, Cilevb.com, clone.ac, clone.pm, enz.ps, box.mv, enz.de, clone.ni, enz.cy, enz.ac, enz.pm, enz.gh, box.net, box.cm, dcc.gt, enz.se, enz.pr, enz.pt, box.ps, box.ni, enz.al, enz.id, vuln.st |
| String Count | 3292 |
| String Link | text |
| String MD5 | 9c5543bd275663d243224bc2f0c1e28c |
| Timerange | 365 Days |
| Unpack Status | unknown () |
| Countries | 3 |
| Unpacked Link | |
| Callgraph | |
| API Resolution | |
| Comment | none |