Details
Robot
FileName
Malware Family DarkComet
Date Added 2015-11-07 20:01:53
MD5 9a2bcc303d4c38dd7da96563d7eb3414
Sha256 54ab1d00d65a48957b71210d37eaab495ae6fe1adc5939b517454414fe095c4c
Robot Robots lovingly delivered by robohash.org
Advertising
Config Data
FTPSIZE
SID Guest16
SH6 1
SH9 1
DIRATTRIB 2
FTPPORT
CHIDEF 1
GENCODE Q7q.WR+FgQ//
SH10 1
SH8 1
MSGICON 0
CHANGEDATE 0
CHIDED 1
FTPROOT
MSGTITLE Welcome
PERS 1
OFFLINEK
MSGCORE 57656C636F6D6520746F204461726B436F6D6574205241542E0D0A496620796F75207365652074686973206D6573736167652C206974206D65616E73207468652073747562207375636365737366756C6C792072756E7320616E6420796F752077696C6C206170656172200D0A696E20746865206D61737465722075736572206C6973742E0D0A
FTPUPLOADK
KEYNAME MicroUpdate
PERSINST 1
EDTPATH MSDCSC\msdcsc.exe
MELT 1
COMBOPATH 2
FILEATTRIB 2
FAKEMSG 1
NETDATA fishermanhax.no-ip.org:6530
MUTEX DC_MUTEX-PWNCG1V
SH1 1
FWB 1
SH7 1
FTPPASS
FTPHOST
PWD 6822097808
FTPUSER
SH4 1
SH5 1
EDTDATE 16/04/2007
SH3 1
INSTALL 1
Virustotal

47 out of 51 AV Engines identified the sample as Malicious.

Virustotal Report