Punisher

Released 17 years, 10 months ago. June 2007

Copyright © MegaSecurity

By E.M.I.N.E.M


Punisher
Informations
From Romania
Author E.M.I.N.E.M
Family Punisher
Category Remote Access
Version Punisher
Released Date Jun 2007, 17 years, 10 months ago.
Language Visual Basic
Additional Information
Server
dropped file:
c:\WINDOWS\system32\Svchost32.exe
size: 301,841 bytes 

port: 13699, 8888, 1234 TCP

added to registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr"
data: 01, 00, 00, 00 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Server"

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NOD32krn
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NOD32krn
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet001\Services\NOD32krn
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet002\Services\NOD32krn



tested on Windows XP
June 24, 2007

If you recognize any personal information on this page and wish to have it removed or redacted, please contact us at jplesueur@phrozen.io. We are committed to protecting your privacy in accordance with GDPR regulations.