MoonPie 1.35 beta 1
Copyright © MegaSecurity
By Simon Moon
Informations
From | Germany |
Author | Simon Moon |
Family | MoonPie |
Category | Remote Access |
Version | MoonPie 1.35 beta 1 |
Language | Delphi |
Additional Information
Server:
dropped files:
C:\WINDOWS\system\WinSys.exe
C:\WINDOWS\system\systray.exe.jkl
c:\WINDOWS\Start Menu\Programma's\Opstarten\WinSys.exe
size: 257 KB
port: 25982, 25686, 27160 TCP
startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "WinSys"
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices "SystemTray"
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices "WinSys"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "SystemTray"
c:\WINDOWS\Start Menu\Programma's\Opstarten
Added:
HKEY_CLASSES_ROOT\jklfile\shell\open\command
If you recognize any personal information on this page and wish to have it removed or redacted, please contact us at jplesueur@phrozen.io. We are committed to protecting your privacy in accordance with GDPR regulations.