Details
Robot
FileName VirusShare_4aa9fb5cbdf2941425218545c6aaf8bf
Malware Family CyberGate
Date Added 2015-03-23 20:29:25
MD5 4aa9fb5cbdf2941425218545c6aaf8bf
Sha256 51767503c3472794b82e9ff4096f5baf40f4e5be015b16763ce8bdfe447c5b6e
Robot Robots lovingly delivered by robohash.org
Advertising
Config Data
RegKeyHKLM win32
FTPInterval 30
InstallFileName server.exe
CampaignID teste22
Domain leozinhovix.no-ip.org,
InstallMessageTitle ttulodamensagem
KeyLoggerEnableFTP FALSE
ActiveXStartup {JW5W2S6H-6HR4-68A4-4K7I-8C0OT7EGMSU6}
FTPUserName ftp_user
Persistance TRUE
GoogleChromePasswords NoLongerStored
Password 8507
Port 2000,
USBSpread FALSE
Mutex ***MUTEX***
P2PSpread
InstallMessageBox textodamensagem
MessageBoxIcon 16
ActivateKeylogger TRUE
StartupPolicies Policies
FTPAddress ftp.server.com
KeyloggerBackspace TRUE
ChangeCreationDate TRUE
InstallFlag TRUE
FTPPort 21
CyberGateVersion
InstallDir install
FTPPassword +
MessageBoxButton 0
MeltFile TRUE
RegKeyHKCU win32
FTPDirectory ./logs/
HideFile TRUE
EnableMessageBox FALSE
Virustotal

49 out of 54 AV Engines identified the sample as Malicious.

Virustotal Report