| Packed MD5 | e3faefa56a524b1dfdba7a1f6896a7cb |
| Priority | 1 |
| First | 12/31/2009 |
| Last | 01/16/2010 |
| Count | |
| History | |
| Unpacked MD5 | 1d04d6dc84e8567d1d9d991e78294986 |
| AV Hits | 40 |
| AV Count | 32 |
| CC Servers | |
| DNS Lookups | TW:m.DRD3H.COM |
| Failed Connects | TW:122.117.146.70:6668 |
| AV Name | AhnLab-V3:IRCBot.206336.K, AntiVir:TRDownloader.Gen, Authentium:Heuristic-210!Eldorado, Avast:MISSED, AVG:RBot.AI, BitDefender:Bot.91681, CAT-QuickHeal:Rbot.aus, ClamAV:Mybot-7905, DrWeb:HLLW.MyBot.5, eSafe:HEURCrypted, eTrust-Vet:Rbot.JNW, Ewido:MISSED, FileAdvisor:MISSED, Fortinet:RBot.AUS!tr.bdr, F-Prot:Heuristic-210!Eldorado, F-Secure:Rbot.aus, Ikarus:Rbot, Kaspersky:Rbot.aus, McAfee:Sdbot.worm, Microsoft:Rbot.gen, NOD32v2:MISSED, Norman:DLoader.NNTE, Panda:MISSED, Prevx1:MISSED, Rising:Mybot.bar, Sophos:MalGeneric-A, Sunbelt:Rbot, Symantec:Spybot.Worm, TheHacker:BackdoorRbot.aus, VBA32:OScope.Backdoor.Sdbot.Cgen, VirusBuster:Rbot.AKKE, Webwasher-Gateway:MISSED |
| WinXP Files | |
| WinXP Processes | Cilevb.com, CMD.EXE, CSRSS.EXE, defrag.exe, DfrgFat.exe, EXPLORER.EXE, LSASS.EXE, MSMSGS.EXE, SERVICES.EXE, SPOOLSV.EXE, SVCHOST.EXE, WINLOGON.EXE |
| WinXP Registries | HKEY_CLASSES_ROOT@...HKEY_CLASSES_ROOT\.key, HKEY_LOCAL_MACHINE@...Classes\.key, HKEY_LOCAL_MACHINE@...CurrentVersion\RunServices, HKEY_USERS@...Microsoft\OLE, HKEY_CLASSES_ROOT@...HKEY_CLASSES_ROOT\\.key, HKEY_LOCAL_MACHINE@...Classes\\.key, HKEY_LOCAL_MACHINE@...CurrentVersion\\RunServices, HKEY_USERS@...Microsoft\\OLE |
| WinXP Ports | 1038, 1038, 1099, 1100, 1101, 1102, 1103, 1104, 1105, 1106, 1107, 1108, 1109, 1110, 1111, 1112, 1113, 1114, 1115, 1116, 1117, 1118, 1119, 1120, 1121, 1122, 1123, 1124, 1125, 1126, 1127, 1128, 1129, 39252, 3728, 1034, 2754, 2755, 2756, 2757, 2758, 2759, 2760, 2761, 2762, 2763, 2764, 2765, 2766, 2767, 2768, 2769, 2770, 2771, 2772, 2773, 2774, 2775, 2776, 2777, 2778, 2779, 2780, 2781, 2782, 2783, 2784, 2785, 2786, 2787, 2788, 2789, 38933 |
| Win-2Kf Files | |
| Win-2Kf Processes | Cilevb.com |
| Win-2Kf Registries | HKEY_CLASSES_ROOT@...HKEY_CLASSES_ROOT\\.key, HKEY_LOCAL_MACHINE@...Classes\\.key, HKEY_LOCAL_MACHINE@...CurrentVersion\\RunServices, HKEY_USERS@...InternetSettings\\5.0, HKEY_USERS@...InternetSettings\\Connections, HKEY_USERS@...Microsoft\\OLE |
| Win-2Kf Ports | 1042, 3105, 3106, 3107, 3108, 3109, 3110, 3111, 3112, 3113, 3114, 3115, 3116, 3117, 3118, 3119, 3120, 3121, 3122, 3123, 3124, 3125, 3126, 3127, 3128, 3129, 3130, 3131, 3132, 3133, 3134, 3135, 3136, 54653, 3728 |
| Create Events | |
| Create Files | |
| Create RegKeys | Software\Microsoft\OLE,SYSTEM\CurrentControlSet\Control\Lsa |
| Open RegKeys | |
| Service Starts | |
| Service Deletes | |
| Service Creates | |
| Cluster | |
| Cluster Confidence | |
| Packer ID1 | ASPack |
| Packer ID2 | |
| Embedded DNS | m.DRD3H.COM, m.DRD3H.COM, Cilevb.com, Cilevb.com, clone.ac, clone.pm, enz.ps, box.mv, enz.de, clone.ni, enz.cy, enz.ac, enz.pm, enz.gh, box.net, box.cm, dcc.gt, enz.se, enz.pr, enz.pt, box.ps, box.ni, enz.al, enz.id, vuln.st |
| String Count | 3292 |
| String Link | text |
| String MD5 | 9c5543bd275663d243224bc2f0c1e28c |
| Timerange | 365 Days |
| Unpack Status | unknown (unpacked : 0 : Unpacking Provided Binary. (Code,Data) = (49.98%, 23.55%)) |
| Countries | 4 |
| Unpacked Link | |
| Callgraph | |
| API Resolution | |
| Comment | none |