Packed MD5 7f60162c2c0bd2cc7531e51328e98290 
Priority 31 
First 06/09/2009 
Last 11/02/2009 
Count  
History  
Unpacked MD5  
AV Hits 25 
AV Count 32 
CC Servers  
DNS Lookups :moscow-advokat.ru SE:vancouver.dal.net NO:london.uk.eu.undernet.org :los-angeles.ca.us.undernet.org SE:qis.md.us.dal.net SE:ozbytes.dal.net :washington.dc.us.undernet.org SE:ced.dal.net :caen.fr.eu.undernet.org SE:coins.dal.net :gaspode.zanet.org.za :lia.zanet.net AT:graz.at.eu.undernet.org FI:london.uk.eu.undernet.org NL:diemen.nl.eu.undernet.org :brussels.be.eu.undernet.org BE:london.uk.eu.undernet.org SE:broadway.ny.us.dal.net HR:london.uk.eu.undernet.org :lulea.se.eu.undernet.org :flanders.be.eu.undernet.org 
Failed Connects  
AV Name AhnLab-V3:Korgo.11391, AntiVir:Korgo.AF, Authentium:Korgo.S, Avast:_Korgo-S, AVG:MISSED, BitDefender:Korgo.T, CAT-QuickHeal:Korgo.S, ClamAV:Padobot.N, DrWeb:MISSED, eSafe:MISSED, eTrust-Vet:Korgo.S, Ewido:Padobot.n, FileAdvisor:MISSED, Fortinet:Korgo.S!worm, F-Prot:Korgo.S, F-Secure:MISSED, Ikarus:MISSED, Kaspersky:Padobot.n, McAfee:Korgo.s, Microsoft:SdBot, NOD32v2:Korgo.U, Norman:Korgo.AM, Panda:Korgo.T.worm, Prevx1:MISSED, Rising:MISSED, Sophos:Korgo-S, Sunbelt:IRCBot.n, Symantec:Korgo.S, TheHacker:Korgo.S, VBA32:Padobot.n, VirusBuster:Korgo.U, Webwasher-Gateway:Korgo.AF  
WinXP Files ftpupd.exe, ofpzock.exe, ekylqln.exe, zuievw.exe, brtfjv.exe, driiq.exe, ldpzcvfe.exe, xgsamw.exe, wlvxd.exe, zwoyv.exe, nefmwwx.exe, wkmuo.exe, qnnloi.exe, foedievq.exe, qxtkg.exe, uplmxbfh.exe, gpngcmf.exe, bztetu.exe, awwhxkg.exe, nhnnhiph.exe, idjpwr.exe, uvpgbq.exe, aicbr.exe, vvlgpdh.exe, kadqwfpv.exe, xpwzi.exe, llahy.exe, nclehi.exe, ximmrxje.exe, klfgnk.exe, ruqvq.exe, ljquigfg.exe, iclevlgf.exe, mkaxmh.exe, tzkbygj.exe, rrkofsz.exe, xqmsxcnk.exe, hwaingkp.exe, gczne.exe, qhuschtq.exe, iwjbegh.exe, qoprfr.exe, chzfwim.exe, eemzxpc.exe, ifofoqx.exe, tbxwn.exe, erovekf.exe, wmajzr.exe, lpaif.exe, bylzhrjf.exe, mbhwsq.exe, swewafx.exe, pkqin.exe, uyxdqfrd.exe, jrghb.exe, hakcwso.exe, zjwpw.exe, iqrwxvsh.exe, ssfsja.exe, hhiynnl.exe, agkxk.exe, qbilmxa.exe, aklppyp.exe, xwvcr.exe, uupaqofq.exe, oylbntk.exe, hzbnnzd.exe, ufhvcbvh.exe, vuyfu.exe, otfxyb.exe, csrasm.exe, brqmy.exe, cimnkh.exe, hblnpj.exe, dieostw.exe, qqcctlt.exe, qneldg.exe, yxpafree.exe, thkwezl.exe, smdcxlw.exe, nurbe.exe, sostzvqr.exe, csihvhly.exe, txwib.exe, zyluo.exe, ptmqaeg.exe, lkemxudt.exe, ciqvtap.exe, nvsmzgau.exe, yeiba.exe, exeist.exe, eajufng.exe  
WinXP Processes CMD.EXE, CSRSS.EXE, EXPLORER.EXE, LSASS.EXE, MSMSGS.EXE, ofpzock.exe, SERVICES.EXE, SPOOLSV.EXE, SVCHOST.EXE, WINLOGON.EXE, ekylqln.exe, zuievw.exe, brtfjv.exe, driiq.exe, ldpzcvfe.exe, xgsamw.exe, wlvxd.exe, zwoyv.exe, nefmwwx.exe, wkmuo.exe, qnnloi.exe, foedievq.exe, qxtkg.exe, uplmxbfh.exe, gpngcmf.exe, bztetu.exe, awwhxkg.exe, nhnnhiph.exe, idjpwr.exe, uvpgbq.exe, aicbr.exe, vvlgpdh.exe, kadqwfpv.exe, xpwzi.exe, llahy.exe, nclehi.exe, ximmrxje.exe, klfgnk.exe, ruqvq.exe, ljquigfg.exe, iclevlgf.exe, mkaxmh.exe, tzkbygj.exe, rrkofsz.exe, xqmsxcnk.exe, hwaingkp.exe, gczne.exe, qhuschtq.exe, iwjbegh.exe, qoprfr.exe, chzfwim.exe, eemzxpc.exe, ifofoqx.exe, tbxwn.exe, erovekf.exe, wmajzr.exe, lpaif.exe, bylzhrjf.exe, mbhwsq.exe, swewafx.exe, pkqin.exe, uyxdqfrd.exe, jrghb.exe, hakcwso.exe, zjwpw.exe, iqrwxvsh.exe, ssfsja.exe, hhiynnl.exe, agkxk.exe, ftpupd.exe, qbilmxa.exe, aklppyp.exe, xwvcr.exe, uupaqofq.exe, oylbntk.exe, hzbnnzd.exe, ufhvcbvh.exe, vuyfu.exe, otfxyb.exe, csrasm.exe, brqmy.exe, cimnkh.exe, hblnpj.exe, dieostw.exe, qqcctlt.exe, qneldg.exe, yxpafree.exe, thkwezl.exe, smdcxlw.exe, nurbe.exe, sostzvqr.exe, csihvhly.exe, txwib.exe, zyluo.exe, ptmqaeg.exe, lkemxudt.exe, ciqvtap.exe, nvsmzgau.exe, yeiba.exe, exeist.exe, eajufng.exe  
WinXP Registries HKEY_LOCAL_MACHINE@...Microsoft\Wireless, HKEY_LOCAL_MACHINE@...Microsoft\\Wireless  
WinXP Ports 113, 3067, 6183, 3986, 1679, 6051, 7906, 5771, 5482, 1922, 2999, 1901, 6345, 690, 4692, 2793, 5835, 6307, 779, 3362, 7811, 4161, 7592, 3544, 7444, 1431, 2832, 5767, 5480, 4332, 2833, 502, 6926, 4830, 4210, 2125, 5118, 4540, 4080, 4525, 7719, 5013, 1675, 4073, 3228, 6041, 1749, 4324, 6640, 730, 1031, 3937, 5430, 1054, 6092, 4671, 7113, 4933, 5082, 3560, 1044, 1152, 1871, 7891, 2750, 4995, 3851, 445, 5769, 1032, 1033, 1034, 1035, 1036, 1038, 1039, 1040, 1041, 1042, 1043, 1045, 1046, 1047, 1048, 1049, 1050, 1051, 1052, 1053, 1055, 1056, 1057, 1058, 1059, 1060, 1061, 1062, 1064, 1065, 1066, 1067, 1068, 1069, 1070, 1071, 1072, 1073, 1074, 1076, 1077, 1079, 1080, 1081, 1084, 1085, 1086, 1087, 1088, 1090, 1092, 1093, 1094, 1095, 1097, 1098, 1100, 7850, 6259, 2433, 549, 4016, 6132, 4217, 3631, 8050, 6244, 6355, 6251, 6393, 1957, 3679, 5327, 5134, 3497, 7477, 7919, 1476, 1407, 2804, 6481, 7690, 4383, 4407, 1301, 7945, 4979, 939, 369, 1772  
Win-2Kf Files  
Win-2Kf Processes  
Win-2Kf Registries  
Win-2Kf Ports  
Create Events  
Create Files  
Create RegKeys  
Open RegKeys  
Service Starts  
Service Deletes  
Service Creates  
Cluster  
Cluster Confidence  
Packer ID1 PolyEnE 
Packer ID2  
Embedded DNS qis.md.us.dal.net, ced.dal.net, viking.dal.net, vancouver.dal.net, ozbytes.dal.net, broadway.ny.us.dal.net, coins.dal.net, lulea.se.eu.undernet.org, diemen.nl.eu.undernet.org, gaspode.zanet.org.za, lia.zanet.net, london.uk.eu.undernet.org, washington.dc.us.undernet.org, los-angeles.ca.us.undernet.org, brussels.be.eu.undernet.org, caen.fr.eu.undernet.org, flanders.be.eu.undernet.org, graz.at.eu.undernet.org, moscow-advokat.ru  
String Count 93 
String Link text
String MD5 b3ff4983d397cadd298d04b0c63e704d 
Timerange 365 Days 
Unpack Status unknown (unpacked : 0 : Unpacking Provided Binary. (Code,Data) = (73.77%, 13.23%)) 
Countries 15 
Unpacked Link  
Callgraph  
API Resolution  
Comment none