RubyRAT

Released 16 years, 11 months ago. December 2007

Copyright © MegaSecurity

By xT-Dart-Tx


RubyRAT
Informations
Author xT-Dart-Tx
Family RubyRAT
Category Remote Access
Version RubyRAT
Released Date Dec 2007, 16 years, 11 months ago.
Language Visual Basic
Additional Information
Server
Dropped Files:
c:\WINDOWS\system32\drivers\services.exe    Size: 7,168 bytes 
c:\WINDOWS\system32\drivers\winlogon.exe    Size: 50,755 bytes 



Added to Registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Services"
Data: C:\WINDOWS\System32\drivers\services.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Winlogon"
Data: C:\WINDOWS\System32\drivers\winlogon.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Services"
Data: C:\WINDOWS\System32\drivers\services.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Winlogon"
Data: C:\WINDOWS\System32\drivers\winlogon.exe 


Tested on Windows XP
December 27, 2007

If you recognize any personal information on this page and wish to have it removed or redacted, please contact us at jplesueur@phrozen.io. We are committed to protecting your privacy in accordance with GDPR regulations.