| Packed MD5 | 9928a1e6601cf00d0b7826d13fb556f0 |
| Priority | 2 |
| First | 01/17/2008 |
| Last | 07/02/2008 |
| Count | 22 |
| History | 22 hits: 10-06 to 07-02 |
| Unpacked MD5 | 28c8dadabf9911b53b8e186a6eaaa4cc |
| AV Hits | 31 |
| AV Count | 32 |
| CC Servers | 222.51.25.90:18067 222.51.25.91:18067 121.254.173.70:18067 |
| DNS Lookups | CN:bniu.househot.com CN:ypgw.wallloan.com EU:www.filefrog.net KR:bniu.househot.com |
| Failed Connects | CN:222.51.25.90:18067 |
| AV Name | AhnLab-V3:WargBot.9609, AntiVir:IrcBot.9609, Authentium:Ircbot.TU, Avast:_Ircbot-ACE, AVG:Generic3.GBC, BitDefender:VanBot.A, CAT-QuickHeal:IRCBot.st, ClamAV:IRCBot-689, DrWeb:HLLW.Nert, eSafe:IRCBot.jl, eTrust-Vet:Cuebot.J, Ewido:IRCBot.st, FileAdvisor:MISSED, Fortinet:Graweg.B!tr.bdr, F-Prot:Ircbot.TU, F-Secure:VanBot.a, Ikarus:IRCBot.st, Kaspersky:VanBot.a, McAfee:IRC-Mocbot!MS06-040, Microsoft:Mocbot.A!CME-482, NOD32v2:IRCBot.OO, Norman:Ircbot.BVM, Panda:Oscarbot.KD.worm!CME-482, Prevx1:MISSED, Rising:Mocbot.b, Sophos:Cuebot-L, Sunbelt:IRC.Mocbot, Symantec:Wargbot, TheHacker:Exploit.MS06-040.b, VBA32:IRCBot.st, VirusBuster:IRCBot.AAH, Webwasher-Gateway:IrcBot.9609 |
| WinXP Files | |
| WinXP Processes | |
| WinXP Registries | |
| WinXP Ports | |
| Win-2Kf Files | |
| Win-2Kf Processes | wgareg.exe |
| Win-2Kf Registries | HKEY_LOCAL_MACHINE@...Microsoft\securitycenter, HKEY_LOCAL_MACHINE@...Microsoft\windowsfirewall, HKEY_LOCAL_MACHINE@...windowsfirewall\domainprofile, HKEY_LOCAL_MACHINE@...windowsfirewall\standardprofile, HKEY_LOCAL_MACHINE@...Microsoft\\securitycenter, HKEY_LOCAL_MACHINE@...Microsoft\\windowsfirewall, HKEY_LOCAL_MACHINE@...windowsfirewall\\domainprofile, HKEY_LOCAL_MACHINE@...windowsfirewall\\standardprofile, HKEY_LOCAL_MACHINE@...Microsoft\\DownloadManager, HKEY_USERS@...InternetSettings\\5.0, HKEY_USERS@...InternetSettings\\Connections |
| Win-2Kf Ports | 1028, 2693, 2694, 2695, 2696, 2697, 2698, 2699, 2700, 2701, 2702, 2703, 2704, 2705, 2706, 2707, 2708, 2709, 2710, 2711, 2712, 2713, 2714, 2715, 2716, 2717, 2718, 2719, 2720, 2721, 2722, 2723, 2724, 2725, 2726, 2727, 2728, 2729, 2730, 2731, 2732, 2733, 2734, 2735, 2736, 2737, 2738, 2739, 2740, 2741, 2742, 2743, 2744, 2745, 2746, 2747, 2748, 2749, 2750, 2751, 2752, 2753, 2754, 2755, 2756, 1031, 1736, 1737, 1738, 1739, 1740, 1741, 1742, 1743, 1744, 1745, 1746, 1747, 1748, 1749, 1750, 1751, 1752, 1753, 1754, 1755, 1756, 1757, 1758, 1759, 1760, 1761, 1762, 1763, 1764, 1765, 1766, 1767, 1768, 1769, 1770, 1771, 1772, 1773, 1774, 1775, 1776, 1777, 1778, 1779, 1780, 1781, 1782, 1783, 1784, 1785, 1786, 1787, 1788, 1789, 1790, 1791, 1792, 1793, 1794, 1795, 1796, 1797, 1798, 1799, 1029, 1285, 1286, 1287, 1288, 1289, 1290, 1291, 1292, 1293, 1294, 1295, 1296, 1297, 1298, 1299, 1300, 1301, 1302, 1303, 1304, 1305, 1306, 1307, 1308, 1309, 1310, 1311, 1312, 1313, 1314, 1315, 1316, 1317, 1318, 1319, 1320, 1321, 1322, 1323, 1324, 1325, 1326, 1327, 1328, 1329, 1330, 1331, 1332, 1333, 1334, 1335, 1336, 1337, 1338, 1339, 1340, 1341, 1342, 1343, 1344, 1345, 1346, 1347, 1348, 1349, 1350, 1351, 1352, 1353, 1354, 1355, 1356, 1357, 1358, 1359, 1360, 1361, 1362, 1363, 1364, 1365, 1366, 1367, 1368, 1369, 1370, 1371, 1372, 1373, 1374, 1375, 1376, 1377, 1378, 1379, 1380, 1381, 1382, 1383, 1384, 1385, 1386, 1387, 1388, 1389, 1390, 1391, 1392, 1393, 1394, 1395, 1396, 1397, 1398, 1399, 1400, 1401, 1402, 1403, 1404, 1405, 1406, 1407, 1408, 1409, 1410, 1411, 1412, 1221, 1222, 1223, 1224, 1225, 1226, 1227, 1228, 1229, 1230, 1231, 1232, 1233, 1234, 1235, 1236, 1237, 1238, 1239, 1240, 1241, 1242, 1243, 1244, 1245, 1246, 1247, 1248, 1249, 1250, 1251, 1252, 1253, 1254, 1255, 1256, 1257, 1258, 1259, 1260, 1261, 1262, 1263, 1264, 1265, 1266, 1267, 1268, 1269, 1270, 1271, 1272, 1273, 1274, 1275, 1276, 1277, 1278, 1279, 1280, 1281, 1282, 1283, 1284 |
| Create Events | |
| Create Files | |
| Create RegKeys | |
| Open RegKeys | |
| Service Starts | |
| Service Deletes | |
| Service Creates | |
| Cluster | |
| Cluster Confidence | |
| Packer ID1 | none |
| Packer ID2 | none |
| Embedded DNS | ypgw.wallloan.com |
| String Count | 104 |
| String Link | text |
| String MD5 | 11292a7589719e49a71f2008cd43d90c |
| Timerange | 365 Days |
| Unpack Status | good (unpacked : 0 : Unpacking Provided Binary. (Code,Data) = (65.33%, 16.45%)) |
| Countries | 1 |
| Unpacked Link | 28c8dadabf [0] |
| Callgraph | ASM:Graph |
| API Resolution | 99% |
| Comment | none |