| Packed MD5 | 37cd59759e61e931ffd337f999b696af |
| Priority | 1 |
| First | 08/01/2008 |
| Last | 08/12/2008 |
| Count | 4 |
| History | 4 hits: 08-01 to 08-12 |
| Unpacked MD5 | |
| AV Hits | 15 |
| AV Count | 32 |
| CC Servers | 67.149.121.39:12351 64.202.117.102:13001 190.174.67.119:13001 |
| DNS Lookups | US:chat-shqip.org US:w3bs.chat-shqip.org |
| Failed Connects | US:24.192.170.232:12351 US:24.192.170.232:13001 US:67.149.121.39:12351 US:67.149.121.39:13001 |
| AV Name | AhnLab-V3:MISSED, AntiVir:Virut.AX, Authentium:MISSED, Avast:_Agent-AABV, AVG:PSW.Generic6.QSP, BitDefender:Generic.343948, CAT-QuickHeal:MISSED, ClamAV:MISSED, DrWeb:MISSED, eSafe:MISSED, eTrust-Vet:MISSED, Ewido:MISSED, FileAdvisor:MISSED, Fortinet:MISSED, F-Prot:MISSED, F-Secure:Suspicious_Malware!Gemini, Ikarus:Virut.av, Kaspersky:MISSED, McAfee:MISSED, Microsoft:Wootbot.EG, NOD32v2:MISSED, Norman:MISSED, Panda:MISSED, Prevx1:MISSED, Rising:MISSED, Sophos:SusUnkPacker, Sunbelt:MISSED, Symantec:Virut.W, TheHacker:MISSED, VBA32:MISSED, VirusBuster:MISSED, Webwasher-Gateway:Virut.AX |
| WinXP Files | iexplorer.exe, c.bat |
| WinXP Processes | CMD.EXE, CSRSS.EXE, EXPLORER.EXE, iexplorer.exe, LSASS.EXE, MSMSGS.EXE, SERVICES.EXE, SPOOLSV.EXE, SVCHOST.EXE, WINLOGON.EXE |
| WinXP Registries | HKEY_LOCAL_MACHINE@...CurrentVersion\RunServices, HKEY_USERS@...CurrentVersion\RunOnce, HKEY_LOCAL_MACHINE@...CurrentVersion\\RunServices, HKEY_USERS@...CurrentVersion\\RunOnce |
| WinXP Ports | 1041, 12045, 18317, 1037, 1053, 1201, 14548, 1469, 1519, 1562, 1680, 1730, 1761, 1874, 1934, 1941, 1943, 2225, 2320, 2365, 2370, 2405, 2478, 2482, 2488, 2495, 2540, 2935, 3139, 3219, 3220, 3228, 3346, 3347, 3348, 3349, 3350, 3351, 3352, 3353, 3354, 3355, 3356, 3357, 3358, 3359, 3360, 3361, 3362, 3363, 3364, 3365, 3366, 3367, 3368, 3369, 3370, 3371, 3372, 3373, 3374, 3375, 3376, 3377, 3378, 3379, 3380, 3381, 3382, 3383, 3384, 3385, 3386, 3387, 3388, 3389, 3390, 3391, 3392, 3393, 3394, 3395, 3396, 3397, 3398, 3399, 3400, 3401, 3551, 3589, 3610, 3675, 3824, 3838, 3924, 3958, 4057, 4093, 4372, 4452, 4478, 4577, 4581, 1039, 8195, 1034, 1073, 1325, 1343, 2389, 2415, 2442, 2530, 2739, 2747, 2895, 2904, 3245, 3246, 3247, 3248, 3249, 3250, 3251, 3252, 3253, 3254, 3255, 3256, 3257, 3258, 3259, 3260, 3261, 3262, 3263, 3264, 3265, 3266, 3267, 3268, 3269, 3270, 3271, 3272, 3273, 3274, 3275, 3276, 3277, 3278, 3279, 3280, 3281, 3282, 3283, 3284, 3285, 3286, 3287, 3288, 3289, 3290, 3291, 3292, 3293, 3294, 3295, 3296, 3297, 3298, 3299, 3301, 3302, 3303, 3304, 3305, 3306, 3307, 3308, 3309, 3310, 3311, 3312, 3313, 3314, 3685, 4627, 7683 |
| Win-2Kf Files | |
| Win-2Kf Processes | |
| Win-2Kf Registries | |
| Win-2Kf Ports | |
| Create Events | |
| Create Files | |
| Create RegKeys | |
| Open RegKeys | |
| Service Starts | |
| Service Deletes | |
| Service Creates | |
| Cluster | |
| Cluster Confidence | |
| Packer ID1 | none |
| Packer ID2 | none |
| Embedded DNS | |
| String Count | |
| String Link | text |
| String MD5 | |
| Timerange | 365 Days |
| Unpack Status | unknown () |
| Countries | 1 |
| Unpacked Link | none[none] |
| Callgraph | none:none |
| API Resolution | |
| Comment | none |