Details
Robot
FileName VirusShare_052ef2fbeecaae004011253669bd43ae
Malware Family CyberGate
Date Added 2015-03-23 20:29:25
MD5 052ef2fbeecaae004011253669bd43ae
Sha256 2fda3accbfa2bd77654561f548ef0b21500f3040f0fc007535fe0f12d7826cbe
Robot Robots lovingly delivered by robohash.org
Advertising
Config Data
RegKeyHKLM HKLM
FTPInterval 30
InstallFileName svchost.exe
CampaignID deneme
Domain dannyhack.zapto.org,
InstallMessageTitle ttulodamensagem
KeyLoggerEnableFTP FALSE
ActiveXStartup {71HD16I7-O1O3-DFHV-8S77-IAFNL4Q8U718}
FTPUserName ftp_user
Persistance FALSE
GoogleChromePasswords NoLongerStored
Password 1111
Port 8080,
USBSpread FALSE
Mutex ***MUTEX***
P2PSpread
InstallMessageBox textodamensagem
MessageBoxIcon 16
ActivateKeylogger TRUE
StartupPolicies Policies
FTPAddress ftp.server.com
KeyloggerBackspace TRUE
ChangeCreationDate FALSE
InstallFlag TRUE
FTPPort 21
CyberGateVersion
InstallDir install
FTPPassword +
MessageBoxButton 0
MeltFile TRUE
RegKeyHKCU HKCU
FTPDirectory ./logs/
HideFile FALSE
EnableMessageBox FALSE
Virustotal

50 out of 54 AV Engines identified the sample as Malicious.

Virustotal Report