MalwareConfig
Details
<table class="table table-striped table-bordered table-sm">
<tr>
<th>FileName</th>
<td><a href="/stats//">VirusShare_e121c5a3c4db555a826e0347ae0e436a</a></td>
</tr>
<tr>
<th>Malware Family</th>
<td><a href="/stats//">DarkComet</a></td>
</tr>
<tr>
<th>Date Added</th>
<td>2015-03-23 20:29:25</td>
</tr>
<tr>
<th>MD5</th>
<td>e121c5a3c4db555a826e0347ae0e436a</td>
</tr>
<tr>
<th>Sha256</th>
<td>d33d4d5560080302bbe56e577612c6fd8a45ec0986189b95ac8e2a3a850f6298</td>
</tr>
<tr>
<th>Robot</th>
<td>Robots lovingly delivered by <a href="https://robohash.org">robohash.org</a></td>
</tr>
</table>
</div>
</div>
</div>
</div>
</div>
</div>
<div class="row mt-5">
<div class="col">
<div class="card">
<div class="card-header">
Advertising
</div>
<div class="card-body">
<!-- ducktoolkit-leaderboard -->
<ins class="adsbygoogle"
style="display:inline-block;width:728px;height:90px"
data-ad-client="ca-pub-1435553701793282"
data-ad-slot="1601555780"></ins>
</div>
</div>
</div>
</div>
<div class="row mt-5">
<div class="col">
<div class="card">
<div class="card-header">
Config Data
</div>
<table class="table table-striped table-bordered table-sm">
<tr>
<th>Version</th>
<td>#KCMDDC5#</td>
</tr>
<tr>
<th>CampaignID</th>
<td>LogUser</td>
</tr>
<tr>
<th>FTPUserName</th>
<td></td>
</tr>
<tr>
<th>FTPRoot</th>
<td></td>
</tr>
<tr>
<th>FTPSize</th>
<td></td>
</tr>
<tr>
<th>FireWallBypass</th>
<td>1</td>
</tr>
<tr>
<th>Password</th>
<td></td>
</tr>
<tr>
<th>OfflineKeylogger</th>
<td>1</td>
</tr>
<tr>
<th>FTPHost</th>
<td></td>
</tr>
<tr>
<th>Mutex</th>
<td>DC_MUTEX-HMBXHW7</td>
</tr>
<tr>
<th>FTPPort</th>
<td></td>
</tr>
<tr>
<th>FTPPassword</th>
<td></td>
</tr>
<tr>
<th>Domains</th>
<td>25.189.190.89:888</td>
</tr>
<tr>
<th>Gencode</th>
<td>wFcKq8x+wb+%</td>
</tr>
<tr>
<th>FTPKeyLogs</th>
<td></td>
</tr>
</table>
</div>
</div>
</div>
<div class="row mt-5">
<div class="col">
<div class="card">
<div class="card-header">
Virustotal
</div>
<div class="card-body">
<p>46 out of 54 AV Engines identified the sample as Malicious.</p>
<p><a href="https://www.virustotal.com/file/d33d4d5560080302bbe56e577612c6fd8a45ec0986189b95ac8e2a3a850f6298/analysis/1405622133/">Virustotal Report</a></p>
</div>
</div>
</div>
</div>