| Packed MD5 | 74c6c141d83c291690bf3217f677e30d |
| Priority | 2 |
| First | 08/02/2008 |
| Last | 08/18/2008 |
| Count | 8 |
| History | 8 hits: 08-02 to 08-18 |
| Unpacked MD5 | |
| AV Hits | 29 |
| AV Count | 32 |
| CC Servers | 63.173.172.98:6667 |
| DNS Lookups | |
| Failed Connects | US:63.173.172.98:6667 |
| AV Name | AhnLab-V3:MISSED, AntiVir:TRCrypt.NSPI.Gen, Authentium:Threat-HLLIN-Slipper-based!Maximus, Avast:MISSED, AVG:RBot.KA, BitDefender:GenPack_Generic.Sdbot.943E3509, CAT-QuickHeal:Rbot.aus, ClamAV:PUA.Packed.NPack-3, DrWeb:MISSED, eSafe:MISSED, eTrust-Vet:MISSED, Ewido:MISSED, FileAdvisor:MISSED, Fortinet:RBot.AUS!tr.bdr, F-Prot:Threat-HLLIN-Slipper-based!Maximus, F-Secure:Rbot.aus, Ikarus:Packed.Klone.af, Kaspersky:Rbot.aus, McAfee:Sdbot.worm, Microsoft:Rbot.JA, NOD32v2:MISSED, Norman:Suspicious_N.gen, Panda:MISSED, Prevx1:MISSED, Rising:Rbot.GEN, Sophos:MalPacker, Sunbelt:Rbot, Symantec:Spybot.Worm, TheHacker:Behav-Heuristic-063, VBA32:Rbot.aus, VirusBuster:PackedNSPack, Webwasher-Gateway:Crypt.NSPI.Gen |
| WinXP Files | |
| WinXP Processes | CMD.EXE, CSRSS.EXE, EXPLORER.EXE, LSASS.EXE, MSMSGS.EXE, SERVICES.EXE, SPOOLSV.EXE, SVCHOST.EXE, Tilesys.com, WINLOGON.EXE |
| WinXP Registries | HKEY_CLASSES_ROOT@...HKEY_CLASSES_ROOT\\.key, HKEY_LOCAL_MACHINE@...Classes\\.key, HKEY_LOCAL_MACHINE@...CurrentVersion\\RunServices, HKEY_USERS@...Microsoft\\OLE |
| WinXP Ports | 1034, 3144, 3145, 3146, 3147, 3148, 3149, 3150, 3151, 3152, 3153, 3154, 3155, 3156, 3157, 3158, 3159, 3160, 3161, 3162, 3163, 3164, 3165, 3166, 3167, 3168, 3169, 3170, 3171, 3172, 3173, 3174, 3175, 3176, 3177, 3178, 3179, 3180, 3181, 3182, 3183, 3184, 3185, 3186, 3187, 3188, 3189, 3190, 3191, 3192, 3193, 3194, 3195, 3196, 3197, 3198, 35776, 3278, 3733, 3734, 3735, 3736, 3737, 3738, 3739, 3740, 3741, 3742, 3743, 3744, 3745, 3746, 3747, 3748, 3749, 3750, 3751, 3752, 3753, 3754, 3755, 3756, 3757, 3758, 3759, 3760, 3761, 3762, 3763, 3764, 3765, 38795 |
| Win-2Kf Files | |
| Win-2Kf Processes | Tilesys.com |
| Win-2Kf Registries | HKEY_CLASSES_ROOT@...HKEY_CLASSES_ROOT\\.key, HKEY_LOCAL_MACHINE@...Classes\\.key, HKEY_LOCAL_MACHINE@...CurrentVersion\\RunServices, HKEY_USERS@...InternetSettings\\5.0, HKEY_USERS@...InternetSettings\\Connections, HKEY_USERS@...Microsoft\\OLE |
| Win-2Kf Ports | 1034, 2488, 2489, 2490, 2491, 2492, 2493, 2494, 2495, 2496, 2497, 2498, 2499, 2500, 2501, 2502, 2503, 2504, 2505, 2506, 2507, 2508, 2509, 2510, 2511, 2512, 2513, 2514, 2515, 2516, 2517, 2518, 2519, 2520, 2521, 2522, 2523, 2524, 2525, 2526, 2527, 2528, 2529, 2530, 2531, 2532, 2533, 2534, 2535, 2536, 2537, 2538, 2539, 2540, 2541, 2542, 2543, 2544, 2545, 2546, 2547, 56805, 3278 |
| Create Events | |
| Create Files | |
| Create RegKeys | |
| Open RegKeys | |
| Service Starts | |
| Service Deletes | |
| Service Creates | |
| Cluster | |
| Cluster Confidence | |
| Packer ID1 | none |
| Packer ID2 | none |
| Embedded DNS | |
| String Count | |
| String Link | text |
| String MD5 | |
| Timerange | 365 Days |
| Unpack Status | unknown () |
| Countries | 2 |
| Unpacked Link | none[none] |
| Callgraph | none:none |
| API Resolution | |
| Comment | none |