Details
Robot
FileName
Malware Family CyberGate
Date Added 2015-11-07 14:29:19
MD5 a27844120d3669d69899eca0d78a2c4b
Sha256 77137279d86e98945aa11f7a7edd58c0a7171c2d91f7ecdad6ad43c04a2178fc
Robot Robots lovingly delivered by robohash.org
Advertising
Config Data
FTPPassword +
CampaignID bruna ferreira
Password 123
USBSpread FALSE
FTPDirectory ./logs/
FTPAddress ftp.server.com
InstallDir install
Persistance TRUE
InstallMessageTitle ttulo da mensagem
KeyloggerBackspace TRUE
HideFile TRUE
Mutex ***MUTEX***
Domain hilt000.no-ip.org,
FTPPort 21
REGKeyHKCU HKCU
MessageBoxIcon 16
Port 2000,
CyberGateVersion
StartupPolicies Policies
REGKeyHKLM HKLM
FTPUserName ftp_user
ChangeCreationDate TRUE
MeltFile TRUE
InstallFileName server.exe
KeyloggerEnableFTP FALSE
FTPInterval 30
InstallMessageBox texto da mensagem
InstallFlag TRUE
ActiveXStartup {08B0E5JF-4FCB-11CF-AAA5-00401C6XX500}
EnableMessageBox FALSE
ActivateKeylogger TRUE
MessageBoxButton 0
Virustotal

47 out of 50 AV Engines identified the sample as Malicious.

Virustotal Report