Packed MD5 9928a1e6601cf00d0b7826d13fb556f0 
Priority
First 01/17/2008 
Last 07/02/2008 
Count 22 
History 22 hits: 10-06 to 07-02 
Unpacked MD5 28c8dadabf9911b53b8e186a6eaaa4cc  
AV Hits 31 
AV Count 32 
CC Servers 222.51.25.90:18067 222.51.25.91:18067 121.254.173.70:18067 
DNS Lookups CN:bniu.househot.com CN:ypgw.wallloan.com EU:www.filefrog.net KR:bniu.househot.com 
Failed Connects CN:222.51.25.90:18067 
AV Name AhnLab-V3:WargBot.9609, AntiVir:IrcBot.9609, Authentium:Ircbot.TU, Avast:_Ircbot-ACE, AVG:Generic3.GBC, BitDefender:VanBot.A, CAT-QuickHeal:IRCBot.st, ClamAV:IRCBot-689, DrWeb:HLLW.Nert, eSafe:IRCBot.jl, eTrust-Vet:Cuebot.J, Ewido:IRCBot.st, FileAdvisor:MISSED, Fortinet:Graweg.B!tr.bdr, F-Prot:Ircbot.TU, F-Secure:VanBot.a, Ikarus:IRCBot.st, Kaspersky:VanBot.a, McAfee:IRC-Mocbot!MS06-040, Microsoft:Mocbot.A!CME-482, NOD32v2:IRCBot.OO, Norman:Ircbot.BVM, Panda:Oscarbot.KD.worm!CME-482, Prevx1:MISSED, Rising:Mocbot.b, Sophos:Cuebot-L, Sunbelt:IRC.Mocbot, Symantec:Wargbot, TheHacker:Exploit.MS06-040.b, VBA32:IRCBot.st, VirusBuster:IRCBot.AAH, Webwasher-Gateway:IrcBot.9609  
WinXP Files  
WinXP Processes  
WinXP Registries  
WinXP Ports  
Win-2Kf Files  
Win-2Kf Processes wgareg.exe  
Win-2Kf Registries HKEY_LOCAL_MACHINE@...Microsoft\securitycenter, HKEY_LOCAL_MACHINE@...Microsoft\windowsfirewall, HKEY_LOCAL_MACHINE@...windowsfirewall\domainprofile, HKEY_LOCAL_MACHINE@...windowsfirewall\standardprofile, HKEY_LOCAL_MACHINE@...Microsoft\\securitycenter, HKEY_LOCAL_MACHINE@...Microsoft\\windowsfirewall, HKEY_LOCAL_MACHINE@...windowsfirewall\\domainprofile, HKEY_LOCAL_MACHINE@...windowsfirewall\\standardprofile, HKEY_LOCAL_MACHINE@...Microsoft\\DownloadManager, HKEY_USERS@...InternetSettings\\5.0, HKEY_USERS@...InternetSettings\\Connections  
Win-2Kf Ports 1028, 2693, 2694, 2695, 2696, 2697, 2698, 2699, 2700, 2701, 2702, 2703, 2704, 2705, 2706, 2707, 2708, 2709, 2710, 2711, 2712, 2713, 2714, 2715, 2716, 2717, 2718, 2719, 2720, 2721, 2722, 2723, 2724, 2725, 2726, 2727, 2728, 2729, 2730, 2731, 2732, 2733, 2734, 2735, 2736, 2737, 2738, 2739, 2740, 2741, 2742, 2743, 2744, 2745, 2746, 2747, 2748, 2749, 2750, 2751, 2752, 2753, 2754, 2755, 2756, 1031, 1736, 1737, 1738, 1739, 1740, 1741, 1742, 1743, 1744, 1745, 1746, 1747, 1748, 1749, 1750, 1751, 1752, 1753, 1754, 1755, 1756, 1757, 1758, 1759, 1760, 1761, 1762, 1763, 1764, 1765, 1766, 1767, 1768, 1769, 1770, 1771, 1772, 1773, 1774, 1775, 1776, 1777, 1778, 1779, 1780, 1781, 1782, 1783, 1784, 1785, 1786, 1787, 1788, 1789, 1790, 1791, 1792, 1793, 1794, 1795, 1796, 1797, 1798, 1799, 1029, 1285, 1286, 1287, 1288, 1289, 1290, 1291, 1292, 1293, 1294, 1295, 1296, 1297, 1298, 1299, 1300, 1301, 1302, 1303, 1304, 1305, 1306, 1307, 1308, 1309, 1310, 1311, 1312, 1313, 1314, 1315, 1316, 1317, 1318, 1319, 1320, 1321, 1322, 1323, 1324, 1325, 1326, 1327, 1328, 1329, 1330, 1331, 1332, 1333, 1334, 1335, 1336, 1337, 1338, 1339, 1340, 1341, 1342, 1343, 1344, 1345, 1346, 1347, 1348, 1349, 1350, 1351, 1352, 1353, 1354, 1355, 1356, 1357, 1358, 1359, 1360, 1361, 1362, 1363, 1364, 1365, 1366, 1367, 1368, 1369, 1370, 1371, 1372, 1373, 1374, 1375, 1376, 1377, 1378, 1379, 1380, 1381, 1382, 1383, 1384, 1385, 1386, 1387, 1388, 1389, 1390, 1391, 1392, 1393, 1394, 1395, 1396, 1397, 1398, 1399, 1400, 1401, 1402, 1403, 1404, 1405, 1406, 1407, 1408, 1409, 1410, 1411, 1412, 1221, 1222, 1223, 1224, 1225, 1226, 1227, 1228, 1229, 1230, 1231, 1232, 1233, 1234, 1235, 1236, 1237, 1238, 1239, 1240, 1241, 1242, 1243, 1244, 1245, 1246, 1247, 1248, 1249, 1250, 1251, 1252, 1253, 1254, 1255, 1256, 1257, 1258, 1259, 1260, 1261, 1262, 1263, 1264, 1265, 1266, 1267, 1268, 1269, 1270, 1271, 1272, 1273, 1274, 1275, 1276, 1277, 1278, 1279, 1280, 1281, 1282, 1283, 1284  
Create Events  
Create Files  
Create RegKeys  
Open RegKeys  
Service Starts  
Service Deletes  
Service Creates  
Cluster  
Cluster Confidence  
Packer ID1 none 
Packer ID2 none 
Embedded DNS ypgw.wallloan.com  
String Count 104 
String Link text
String MD5 11292a7589719e49a71f2008cd43d90c 
Timerange 365 Days 
Unpack Status good (unpacked : 0 : Unpacking Provided Binary. (Code,Data) = (65.33%, 16.45%)) 
Countries
Unpacked Link 28c8dadabf [0
Callgraph ASM:Graph 
API Resolution 99% 
Comment none