Details
Robot
FileName
Malware Family DarkComet
Date Added 2015-11-07 20:01:56
MD5 9974e1929554268d7b28e301a74de800
Sha256 1d634822de0c4912b48e39ebc3faadd37bdc4c81ae5ebc5e4ed23ef364a9162d
Robot Robots lovingly delivered by robohash.org
Advertising
Config Data
FTPSIZE
SID Guest16
SH6 1
SH9 1
DIRATTRIB 0
FTPPORT
CHIDEF 1
GENCODE XUPnkFzKEb6b
SH10 1
SH8 1
MSGICON 0
CHANGEDATE 0
CHIDED 1
FTPROOT
MSGTITLE Welcome
PERS 1
OFFLINEK 1
MSGCORE 57656C636F6D6520746F204461726B436F6D6574205241542E0D0A496620796F75207365652074686973206D6573736167652C206974206D65616E73207468652073747562207375636365737366756C6C792072756E7320616E6420796F752077696C6C206170656172200D0A696E20746865206D61737465722075736572206C6973742E0D0A
FTPUPLOADK
KEYNAME svchost
PERSINST 1
EDTPATH svchost\svchost.exe
MELT 1
COMBOPATH 2
FILEATTRIB 0
FAKEMSG 1
NETDATA extacy1985.no-ip.org:1604
MUTEX DC_MUTEX-RKXBVM3
SH1 1
FWB 0
SH7 1
FTPPASS
FTPHOST
PWD 6822097808
FTPUSER
SH4 1
SH5 1
EDTDATE 16/04/2007
SH3 1
INSTALL 1
Virustotal

51 out of 53 AV Engines identified the sample as Malicious.

Virustotal Report