RubyRAT
Released 16 years, 11 months ago. December 2007
Copyright © MegaSecurity
By xT-Dart-Tx
Informations
Author | xT-Dart-Tx |
Family | RubyRAT |
Category | Remote Access |
Version | RubyRAT |
Released Date | Dec 2007, 16 years, 11 months ago. |
Language | Visual Basic |
Additional Information
Server
Dropped Files:
c:\WINDOWS\system32\drivers\services.exe Size: 7,168 bytes
c:\WINDOWS\system32\drivers\winlogon.exe Size: 50,755 bytes
Added to Registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Services"
Data: C:\WINDOWS\System32\drivers\services.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Winlogon"
Data: C:\WINDOWS\System32\drivers\winlogon.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Services"
Data: C:\WINDOWS\System32\drivers\services.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Winlogon"
Data: C:\WINDOWS\System32\drivers\winlogon.exe
Tested on Windows XP
December 27, 2007
If you recognize any personal information on this page and wish to have it removed or redacted, please contact us at jplesueur@phrozen.io. We are committed to protecting your privacy in accordance with GDPR regulations.