| Packed MD5 | 10980f4df2060b86a72eb5e533102980 |
| Priority | 2 |
| First | 06/18/2009 |
| Last | 11/01/2009 |
| Count | |
| History | |
| Unpacked MD5 | 1fd3385a95d48a550702029ef44a7f5b |
| AV Hits | 39 |
| AV Count | 32 |
| CC Servers | |
| DNS Lookups | US:gg.arrancar.org |
| Failed Connects | US:209.85.51.152:555 US:66.90.73.229:555 74.55.100.8:555 |
| AV Name | AhnLab-V3:Autorun.32256.D, AntiVir:TRCrypt.ULPM.Gen, Authentium:Backdoor2.DSTK, Avast:_Neeris-B, AVG:IRCBackDoor.SdBot4.GYM, BitDefender:Peed.Gen, CAT-QuickHeal:Agent.IRC, ClamAV:Crypt-106, DrWeb:IRC.Sdbot.4538, eSafe:AutoRun.tet, eTrust-Vet:IRCBot.EH, Ewido:MISSED, FileAdvisor:MISSED, Fortinet:IRCBot.B, F-Prot:Backdoor2.DSTK, F-Secure:SdBot.CNG, Ikarus:AutoRun, Kaspersky:AutoRun.tet, McAfee:Sdbot.worm, Microsoft:Neeris.AN, NOD32v2:MISSED, Norman:Smalltroj.IVKD, Panda:Autorun.AOL, Prevx1:MISSED, Rising:IRCbot.wyd, Sophos:SdBot-DKI, Sunbelt:AutoRun.tet, Symantec:Sdbot, TheHacker:AutoRun.tet, VBA32:AutoRun.Agent.DO, VirusBuster:RBot.AEKD, Webwasher-Gateway:MISSED |
| WinXP Files | SVCHOST.EXE |
| WinXP Processes | CMD.EXE, csrsc.exe, CSRSS.EXE, dwwin.exe, EXPLORER.EXE, LSASS.EXE, MSMSGS.EXE, SERVICES.EXE, SPOOLSV.EXE, SVCHOST.EXE, WINLOGON.EXE |
| WinXP Registries | |
| WinXP Ports | 22303, 4361, 4362, 4363, 4364, 4365, 4366, 4368, 4369, 4370, 4371, 4372, 4373, 4374, 4375, 4376, 4377, 4378, 4379, 4380, 4381, 4382, 4383, 4384, 4385, 4386, 4387, 4388, 4389, 4390, 4391, 4392, 4393, 4394, 4395, 4396, 4397, 4398, 4399, 4400, 4401, 4402, 4403, 4404, 4405, 4406, 4407, 4408, 4409, 4410, 4411, 4412, 4413, 4414, 4415, 4416, 4417, 4418, 4419, 4420, 4421, 4422, 69, 22195, 4054, 4055, 4056, 4057, 4058, 4059, 4060, 4061, 4062, 4063, 4064, 4065, 4066, 4067, 4068, 4069, 4070, 4071, 4072, 4073, 4074, 4075, 4076, 4077, 4078, 4079, 4080, 4081, 4082, 4083, 4084, 4085, 4086, 4087, 4088, 4089, 4090, 4091, 1869, 1870, 1871, 1872, 1873, 1874, 1875, 1876, 1877, 1878, 1879, 1880, 1881, 1882, 1883, 1884, 1885, 1886, 1887, 1888, 1889, 1890, 1891, 1892, 1893, 1894, 1895, 1896, 1897, 1898, 1899, 1900, 1901, 1902, 1903, 1904, 1905, 1906, 1907, 1908, 1909, 1910, 1911, 1912, 1913, 1914, 1915, 1916, 1917, 1918, 1919, 1920, 1921, 1922, 1923, 1924, 1925, 1926, 1927, 1928, 1929, 1930, 1931, 1932, 1933, 1934, 1935, 1936, 1937, 1938, 20912, 20781, 2146, 2147, 2148, 2149, 2150, 2151, 2152, 2153, 2154, 2155, 2156, 2157, 2158, 2159, 2160, 2161, 2162, 2163, 2164, 2165, 2166, 2167, 2168, 2169, 2170, 2171, 2172, 2173, 2174, 2175, 2176, 2177, 2178, 2179, 2180, 2181, 2182, 2183 |
| Win-2Kf Files | |
| Win-2Kf Processes | drwtsn32.exe, explorer.exe |
| Win-2Kf Registries | HKEY_USERS@...InternetSettings\\5.0 |
| Win-2Kf Ports | |
| Create Events | |
| Create Files | |
| Create RegKeys | |
| Open RegKeys | |
| Service Starts | |
| Service Deletes | |
| Service Creates | |
| Cluster | |
| Cluster Confidence | |
| Packer ID1 | none |
| Packer ID2 | none |
| Embedded DNS | |
| String Count | 556 |
| String Link | text |
| String MD5 | 79ac919a7a223a4d7bd5e82ca31f6256 |
| Timerange | 365 Days |
| Unpack Status | unknown (unpacked : 0 : Unpacking Provided Binary. (Code,Data) = (63.43%, 12.99%)) |
| Countries | 2 |
| Unpacked Link | |
| Callgraph | |
| API Resolution | |
| Comment | none |