General

  • Target

    605afc84a56e97c82cc08b2dd944a543a0fe4e692190584500c2d3f2f7a28e57

  • Size

    348KB

  • MD5

    bbdef653a5bc03166478e4fa4cc7dacc

  • SHA1

    0dc2190ab8c3e6c764f3dd422547f2c50da3ceb7

  • SHA256

    605afc84a56e97c82cc08b2dd944a543a0fe4e692190584500c2d3f2f7a28e57

  • SHA512

    2108397e6ff1fea06107565de45e9dd0137788735b08baa0fea0805c1822c0ad5315ae2513639f33187f15108f0d5bbf53f60e2db57d5fd5aab1e2c84a14c928

  • SSDEEP

    6144:pmcD66R15JGmrpQsK3RD2u270jupCJsCxCXI5Ag:scD666Z2zkPaCx1

Score
10/10

Malware Config

Extracted

Family

cybergate

Version

2.6

Botnet

ÖÍíÉ

C2

altamimi000.no-ip.info:288

Mutex

***MUTEX***

Attributes
  • enable_keylogger

    true

  • enable_message_box

    false

  • ftp_directory

    ./logs/

  • ftp_interval

    30

  • injected_process

    svchost.exe

  • install_file

    windows.exe

  • install_flag

    true

  • keylogger_enable_ftp

    false

  • message_box_caption

    texto da mensagem

  • message_box_title

    título da mensagem

  • password

    abcd1234

Signatures

  • Cybergate family
  • Detects binaries and memory artifacts referencing sandbox product IDs 1 IoCs
  • UPX dump on OEP (original entry point) 1 IoCs
  • UPX packed file 1 IoCs

    Detects executables packed with UPX/modified UPX open source packer.

  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • 605afc84a56e97c82cc08b2dd944a543a0fe4e692190584500c2d3f2f7a28e57
    .exe windows:4 windows x86 arch:x86


    Headers

    Sections