Black Curse

Released 19 years, 6 months ago. March 2005

Copyright © MegaSecurity

By Lin


Informations
From China
Author Lin
Family Black Curse
Category Remote Access
Version Black Curse
Released Date Mar 2005, 19 years, 6 months ago.
Language Delphi
Additional Information
Server:
dropped files:
c:\WINNT\system32\EXPL0RER.EXE   Size: 35,423 bytes 
c:\WINNT\system32\SP00LSV.EXE    Size: 35,423 bytes 

port: 25555, 800 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "EXPLORER"
data: EXPL0RER.EXE 

based on source of
DarkMoon
tested on Windows 2000
May 31, 2005

If you recognize any personal information on this page and wish to have it removed or redacted, please contact us at jplesueur@phrozen.io. We are committed to protecting your privacy in accordance with GDPR regulations.