Subsari 1.6 Beta 2

Released 17 years, 2 months ago. July 2007

Copyright © MegaSecurity

By KiPSOFT


Informations
From Turkey
Author KiPSOFT
Family Subsari
Category Remote Access
Version Subsari 1.6 Beta 2
Released Date Jul 2007, 17 years, 2 months ago.
Additional Information
Server
dropped file:
c:\WINDOWS\gar.exe                          Size: 2,083,056 bytes 
c:\WINDOWS\system32\drivers\oreans32.sys    Size: 33,824 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Gar"
data: C:\WINDOWS\gar.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\WinLicense
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_OREANS32\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\oreans32
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_OREANS32\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\oreans32



tested on windows XP
August 20, 2007

If you recognize any personal information on this page and wish to have it removed or redacted, please contact us at jplesueur@phrozen.io. We are committed to protecting your privacy in accordance with GDPR regulations.