.: DeadCow :.
- Coded by: ?
- Version: DeadCow
- Coded in: Delphi,compressed with ASPack
- Family: DeadCow
- Category: Remote Access
Server: dropped file: C:\WINDOWS\Vbrun600.exe size: 158,208 bytes port: 1987 TCP startup: HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Microsoft Visual Basic Runtime following url's can be found in the binary: --/URL REDACTED BY SUB7CREW.ORG FOR YOUR SAFETY\-- --/URL REDACTED BY SUB7CREW.ORG FOR YOUR SAFETY\-- probably related to Backdoor.Win32.Feri
URL's and mails were automatically redacted (filtered) for reader's safety. However the filter is not perfect and can't find all harmful elements. If you find something dangerous including file link, website, mail address, profanity... contact me immediately at firstname.lastname@example.org, thank you in advance.