Packed MD5 ca47a36342c23f5c291ae4fc6d4f6416 
Priority
First 05/29/2008 
Last 08/30/2008 
Count
History 5 hits: 02-16 to 08-30 
Unpacked MD5 c3a58f69c6070a943cce79e251f46542  
AV Hits 26 
AV Count 32 
CC Servers  
DNS Lookups RU:moscow-advokat.ru 
Failed Connects RU:194.6.222.11:6667 
AV Name AhnLab-V3:Korgo.11391.B, AntiVir:Korgo.F.var, Authentium:Korgo.AA, Avast:_Korgo-UPX, AVG:Padobot.AB, BitDefender:Korgo.Z, CAT-QuickHeal:Korgo.Z, ClamAV:MISSED, DrWeb:Lsabot, eSafe:Korgo.r, eTrust-Vet:Korgo.Z, Ewido:Padobot, FileAdvisor:MISSED, Fortinet:Korgo.Z!worm, F-Prot:Korgo.AA, F-Secure:MISSED, Ikarus:Padobot.Z, Kaspersky:Padobot.gen, McAfee:Korgo.z, Microsoft:Korgo.AG, NOD32v2:MISSED, Norman:Horst.gen33, Panda:Korgo.W.worm, Prevx1:MISSED, Rising:MISSED, Sophos:Korgo-Gen, Sunbelt:Padobot.gen, Symantec:Korgo.R, TheHacker:Korgo(2).gen.pack, VBA32:Padobot.gen, VirusBuster:Korgo.Z, Webwasher-Gateway:MISSED  
WinXP Files ftpupd.exe, xvednt.exe, byhaopdl.exe  
WinXP Processes CMD.EXE, CSRSS.EXE, EXPLORER.EXE, LSASS.EXE, MSMSGS.EXE, SERVICES.EXE, SPOOLSV.EXE, SVCHOST.EXE, WINLOGON.EXE, xvednt.exe, byhaopdl.exe  
WinXP Registries HKEY_LOCAL_MACHINE@...Microsoft\Wireless, HKEY_LOCAL_MACHINE@...Microsoft\\Wireless  
WinXP Ports 113, 3067, 5315, 5371  
Win-2Kf Files  
Win-2Kf Processes  
Win-2Kf Registries  
Win-2Kf Ports  
Create Events  
Create Files  
Create RegKeys .exe,System Update,SOFTWARE\Microsoft\Windows\CurrentVersion\Run,ID,Client 
Open RegKeys System Update,SOFTWARE\Microsoft\Windows\CurrentVersion\Run,Software\Microsoft\Wireless,ID,Client 
Service Starts  
Service Deletes  
Service Creates  
Cluster  
Cluster Confidence  
Packer ID1 PolyEnE 
Packer ID2  
Embedded DNS qis.md.us.dal.net, ced.dal.net, viking.dal.net, vancouver.dal.net, ozbytes.dal.net, broadway.ny.us.dal.net, coins.dal.net, lulea.se.eu.undernet.org, diemen.nl.eu.undernet.org, gaspode.zanet.org.za, lia.zanet.net, london.uk.eu.undernet.org, washington.dc.us.undernet.org, los-angeles.ca.us.undernet.org, brussels.be.eu.undernet.org, caen.fr.eu.undernet.org, flanders.be.eu.undernet.org, graz.at.eu.undernet.org  
String Count 89 
String Link text
String MD5 6a15c8f62aa9e992f15a0fa72363fe77 
Timerange 365 Days 
Unpack Status good (unpacked : 0 : Unpacking Provided Binary. (Code,Data) = (73.62%, 13.27%)) 
Countries
Unpacked Link c3a58f69c6 [0
Callgraph ASM:Graph 
API Resolution 100% 
Comment none