Details
Robot
FileName VirusShare_67ca115819756a098b50577e6ba33a19
Malware Family CyberGate
Date Added 2015-03-23 20:29:25
MD5 67ca115819756a098b50577e6ba33a19
Sha256 f26bf97e6201269c830f9c7d0b9267f4c49313e44bccfced577eb504da77ec0a
Robot Robots lovingly delivered by robohash.org
Advertising
Config Data
RegKeyHKLM HKLM
FTPInterval 30
InstallFileName jax.exe
CampaignID vtima
Domain mosa7ee.no-ip.biz,mosa7ee.no-ip.biz,
InstallMessageTitle ttulodamensagem
KeyLoggerEnableFTP FALSE
ActiveXStartup {08B0E5JF-4FCB-11CF-AAA5-00401C6XX500}
FTPUserName ftp_user
Persistance TRUE
GoogleChromePasswords NoLongerStored
Password abcd1234
Port 81,82,
USBSpread FALSE
Mutex ***MUTEX***
P2PSpread
InstallMessageBox textodamensagem
MessageBoxIcon 16
ActivateKeylogger TRUE
StartupPolicies
FTPAddress ftp.server.com
KeyloggerBackspace TRUE
ChangeCreationDate TRUE
InstallFlag TRUE
FTPPort 21
CyberGateVersion
InstallDir install
FTPPassword +
MessageBoxButton 0
MeltFile FALSE
RegKeyHKCU HKCU
FTPDirectory ./logs/
HideFile TRUE
EnableMessageBox FALSE
Virustotal

49 out of 53 AV Engines identified the sample as Malicious.

Virustotal Report