CyberSpy 1.3 (b)
Copyright © MegaSecurity
By Ghirai
Informations
From | Visual Basic |
Author | Ghirai |
Family | CyberSpy |
Category | Remote Access |
Version | CyberSpy 1.3 (b) |
Additional Information
Server:
dropped file:
C:\WINDOWS\SYSTEM\~Cab001.exe
size: 48 and 49 KB
port: 38742 TCP
startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Regcheck"
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices "Regcheck"
c:\windows\win.ini, "load"
If you recognize any personal information on this page and wish to have it removed or redacted, please contact us at jplesueur@phrozen.io. We are committed to protecting your privacy in accordance with GDPR regulations.