Details
Robot
FileName VirusShare_46b05d6d239f87c8f81ebec22fc50ae4
Malware Family CyberGate
Date Added 2015-03-23 20:29:25
MD5 46b05d6d239f87c8f81ebec22fc50ae4
Sha256 5426f20a0d6b2a085d617962558d94b5046e830e9bd6befc458329c1234be89a
Robot Robots lovingly delivered by robohash.org
Advertising
Config Data
RegKeyHKLM
FTPInterval 30
InstallFileName server.exe
CampaignID vtima
Domain moof1.no-ip.org,
InstallMessageTitle ttulodamensagem
KeyLoggerEnableFTP FALSE
ActiveXStartup {08B0E5JF-4FCB-11CF-AAA5-00401C6XX500}
FTPUserName ftp_user
Persistance FALSE
GoogleChromePasswords NoLongerStored
Password abcd1234
Port 81,
USBSpread TRUE
Mutex ***MUTEX***
P2PSpread
InstallMessageBox textodamensagem
MessageBoxIcon 16
ActivateKeylogger TRUE
StartupPolicies Policies
FTPAddress ftp.server.com
KeyloggerBackspace TRUE
ChangeCreationDate FALSE
InstallFlag TRUE
FTPPort 21
CyberGateVersion
InstallDir install
FTPPassword +
MessageBoxButton 0
MeltFile FALSE
RegKeyHKCU
FTPDirectory ./logs/
HideFile FALSE
EnableMessageBox FALSE
Virustotal

50 out of 55 AV Engines identified the sample as Malicious.

Virustotal Report