| Packed MD5 | 50f889782df4367a344a6527c653e3ee |
| Priority | 1 |
| First | 08/26/2008 |
| Last | 08/30/2008 |
| Count | 6 |
| History | 6 hits: 08-26 to 08-30 |
| Unpacked MD5 | |
| AV Hits | 31 |
| AV Count | 32 |
| CC Servers | 69.42.216.108:9890 |
| DNS Lookups | :f.unicat.org |
| Failed Connects | 69.42.216.108:9890 |
| AV Name | AhnLab-V3:Kolabc.552960, AntiVir:WootBot.GB, Authentium:Backdoor2.BHQS, Avast:_Crypt-AYQ, AVG:Themida, BitDefender:DeepScan_Generic.Malware.KIFWX!Bg.1A084C1E, CAT-QuickHeal:SdBot.gen, ClamAV:PUA.Packed.Themida, DrWeb:MISSED, eSafe:MISSED, eTrust-Vet:ForBot.VM, Ewido:MISSED, FileAdvisor:MISSED, Fortinet:SDBot.GAV!worm, F-Prot:Backdoor2.BHQS, F-Secure:Wootbot.gb, Ikarus:Kolabc.vq, Kaspersky:Wootbot.gb, McAfee:Sdbot.worm, Microsoft:Wootbot.DP, NOD32v2:MISSED, Norman:SDBot.gen8, Panda:MISSED, Prevx1:MISSED, Rising:Wootbot.gep, Sophos:MalBehav-285, Sunbelt:Wootbot.gb, Symantec:Spybot.Worm, TheHacker:BackdoorWootbot.gb, VBA32:Wootbot.gb, VirusBuster:Agobot.WPTQ, Webwasher-Gateway:WootBot.GB |
| WinXP Files | igxdfdfds.com |
| WinXP Processes | CMD.EXE, CSRSS.EXE, EXPLORER.EXE, igxdfdfds.com, LSASS.EXE, MSMSGS.EXE, SERVICES.EXE, SPOOLSV.EXE, SVCHOST.EXE, WINLOGON.EXE |
| WinXP Registries | HKEY_LOCAL_MACHINE@...CurrentVersion\\RunServices, HKEY_USERS@...CurrentVersion\\RunOnce |
| WinXP Ports | 1034, 14437, 2448, 2449, 2450, 2451, 2452, 2453, 2454, 2455, 2456, 2457, 2458, 2459, 2460, 2461, 2462, 2463, 2464, 2465, 2466, 2467, 2468, 2469, 2470, 2471, 2472, 2473, 2474, 2475, 2476, 2477, 2478, 2479, 2480, 2481, 2482, 2483, 2484, 1037, 17788, 2808, 2809, 2810, 2811, 2812, 2813, 2814, 2815, 2816, 2817, 1036, 21607, 4329, 4330, 4331, 4332, 4333, 4334, 4335, 4336, 4337, 4338, 4339, 4340, 4341, 4342, 4343, 4344, 4345, 4346, 4347, 4348, 4349, 4350, 4351, 4352, 4353, 4354, 4355, 4356, 4357, 4358, 4359, 4360, 4361, 4362, 4363, 4364, 4365, 18770, 4719, 4720, 4721, 4722, 4723, 4724, 4725, 4726, 4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4736, 4737, 4738, 4739, 4740, 4741, 4742, 4743, 4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4754, 4755, 4756, 4757, 4758, 4759, 4760, 4761, 4762, 4763, 4764, 4765, 4766, 4767, 4768, 4769, 4770, 4771, 4772, 4773, 4774, 4775, 4776, 4777, 4778, 12983, 2952, 2953, 2954, 2955, 2956, 2957, 2958, 2959, 2960, 2961, 2962, 2963, 2964, 2965, 2966, 2967, 2968, 2969, 2970, 2971, 2972, 2973, 2974, 2975, 2976, 2977, 2978, 2979, 2980, 2981, 2982, 2984, 2985, 2986, 2987, 2988, 2989, 2990 |
| Win-2Kf Files | |
| Win-2Kf Processes | |
| Win-2Kf Registries | |
| Win-2Kf Ports | |
| Create Events | |
| Create Files | |
| Create RegKeys | |
| Open RegKeys | |
| Service Starts | |
| Service Deletes | |
| Service Creates | |
| Cluster | |
| Cluster Confidence | |
| Packer ID1 | none |
| Packer ID2 | none |
| Embedded DNS | |
| String Count | |
| String Link | text |
| String MD5 | |
| Timerange | 365 Days |
| Unpack Status | unknown () |
| Countries | 1 |
| Unpacked Link | none[none] |
| Callgraph | none:none |
| API Resolution | |
| Comment | none |