Details
Robot
FileName
Malware Family DarkComet
Date Added 2015-11-07 20:06:05
MD5 9910183e1fdd81e17feb4fb7830897c0
Sha256 131be0e018114356487703b0fd224c47f89c0fc4db45a2f8c4931ff600923998
Robot Robots lovingly delivered by robohash.org
Advertising
Config Data
FTPSIZE 10
SID Guest16
SH6 1
SH9 1
DIRATTRIB 7
FTPPORT 21
CHIDEF 1
GENCODE qad=Bu+VDHBE
SH10 1
SH8 1
MSGICON 64
CHANGEDATE 0
CHIDED 1
FTPROOT /darkcomet
MSGTITLE Microsoft Windows Update
PERS 1
OFFLINEK 1
MSGCORE 596F757220636F6D707574657220686173206265656E20757064617465642E
FTPUPLOADK
KEYNAME updater
PERSINST 1
EDTPATH udupdt\update.exe
MELT 1
COMBOPATH 2
FILEATTRIB 7
FAKEMSG 1
NETDATA serveftm.serveftp.com:85
MUTEX DC_MUTEX-F54S21D
SH1 1
FWB 1
SH7 1
FTPPASS lkjuh787yhg40***
FTPHOST shops.walnmar.com
PWD Ppghytu&*&^^[]09\\\]][]
FTPUSER admin@walnmar.com
SH4 1
SH5 1
EDTDATE 16/04/2007
SH3 1
INSTALL 1
Virustotal

48 out of 51 AV Engines identified the sample as Malicious.

Virustotal Report