Details
Robot
FileName
Malware Family DarkComet
Date Added 2015-11-07 20:03:36
MD5 ac2a9b55fd4814bdb535af768e0d5efe
Sha256 41237788c521348695345377f02e0efb2773cafbac806efc23abb8e9ed353033
Robot Robots lovingly delivered by robohash.org
Advertising
Config Data
FTPSIZE 10
SID Guest16
SH6 1
SH9 1
DIRATTRIB 2
FTPPORT 21
CHIDEF 1
GENCODE YUtQ6fT37Aqx
SH10 1
SH8 1
MSGICON 64
CHANGEDATE 0
CHIDED 1
FTPROOT /darkcomet
MSGTITLE Microsoft Windows Update
PERS 1
OFFLINEK 1
MSGCORE 596F757220636F6D707574657220686173206265656E20757064617465642E
FTPUPLOADK
KEYNAME WinUpdater
PERSINST 1
EDTPATH MSDCSC\msdcsc.exe
MELT 0
COMBOPATH 0
FILEATTRIB 2
FAKEMSG 1
NETDATA |tracktor11.ddns.net:51773
MUTEX DC_MUTEX-WTVP7Z9
SH1 1
FWB 0
SH7 1
FTPPASS lkjuh787yhg40***
FTPHOST shops.walnmar.com
PWD Ppghytu&*&^^[]09\\\]][]
FTPUSER admin@walnmar.com
SH4 1
SH5 1
EDTDATE 16/04/2007
SH3 1
INSTALL 1
Virustotal

47 out of 56 AV Engines identified the sample as Malicious.

Virustotal Report