A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #4420  by EP_X0FF
 Wed Jan 12, 2011 5:47 pm
markusg wrote:Cycle Calculator for Women 4.3.exe
http://www.virustotal.com/file-scan/rep ... 1294851668
Dot net container working as muldrop (spawns IE copy with injected CyberGate v1.07.5 RAT dll inside), additionally drops this

http://www.virustotal.com/file-scan/rep ... 1294854077 (see attach)
Attachments
pass: malware
(2.02 KiB) Downloaded 56 times
 #21048  by EX!
 Thu Oct 03, 2013 4:41 pm
Hello!

I think it's Cybergate, but is very similar to XtremeRat, what do you think?


Bye!

VT :
https://www.virustotal.com/es-ar/file/a ... 380807573/

hXXp://fabpasadena.com/includes/js/calendar/Certificaciones%20Calificacion%20Tributaria%20y%20para%20Fiscales.zip
http://urlquery.net/report.php?id=6273753


VT: Dump
https://www.virustotal.com/es-ar/file/1 ... /analysis/

00C82310 ASCII "Portions Copyrig"
00C82320 ASCII "ht (c) 1999,2003"
00C82330 ASCII " Avenger by NhT",0
00C82AAB MOV EDX,DumpedXT.00C82B00 UNICODE "x.html"
00C82B00 UNICODE "x.html",0
00C831E4 UNICODE "CyberGat"
00C831F4 UNICODE "e",0
Attachments
pass=infected
(1.56 MiB) Downloaded 63 times
 #21053  by patriq
 Thu Oct 03, 2013 6:26 pm
This is a "commercial" RAT that is available to the public.
http://www.cyber-software.org/site/

As described on its website the key features include:

- AES 256 bit keys traffic encryption
- Local settings files RC4 encryption for extra security on Administration System
- 2 different types of server (Remote Host Console and stealth server)
- Multi port use with uPnP support
- Unicode support
- option kind of server to load from URL or Client Console allowing to reduce server size to the loader only (47kb’s)
- Startup methods option to create new server
- Password protection method to create new server
- Customizable installation folder and file name to create new server
- Ftp logs support
- Email notification on server startup
- Tagger notification (webhost solution) on server startup
- Automatic DNS updater with multi DNS addresses support
- Multi profiles builder
- UAC (Vista, 7 and 8) bypass on server
- Windows * ready application
- Offline and Online Keylogger with Unicode support
- Password recovery tool (Chrome, Safari, IE, FF, Filezilla, Windows Live Messenger, No-IP, IDM and many more …)
- Interactive real time chat feature
- File manager
- Services manager
- Windows manager
- Processes manager
- Clipboard manager
- Socks 4/5 and Http Proxy
- Mass features
- Installed programs manager
- Remote desktop (with capture)
- Remote webcam view (with capture)
- Audio stream with save option
- Remote download and execute
- Shell command
- Message boxes control
- Control desktop items (taskbar, icon, start menu)
- Active ports list
- Server control (update, disconnect, restart)
- Remote open HTTP URL
- Send file and execute
- CD Open and Close
- Reverse Mouse Option
- Remote Power Options (Shutdown, Restart, etc …)
- Remote Mouse Lock
- Remote Keyboard Lock
- Remote Icons Hide/show
- Remote Start Hide/show
- Group support (connections can be organized in groups)
- Several function that can be performed from group panel
- URL visiter (with hidden feature)
- VBscript console
- Multi-user keylogger/file search
- Connection log incorporated in the client GUI
- Add Notes for your connections if you want
- Multiple tabs in the client making your life easier (connections tab, group panel tab, client tasks tab, etc …)
- GeoIP server tracking for accurate remote computer localization tracking
- Thumbnails view on file manager allowing display all images of a remote folder
- Auto detection of Windows OS bit system (x32/x64)
- Run remote files as admin
- and many more …
 #21081  by EX!
 Fri Oct 04, 2013 9:52 pm
hmm...seems that the sample is xtreme rat.
 #21087  by EP_X0FF
 Sun Oct 06, 2013 5:27 am
EX! wrote:Hello!

I think it's Cybergate, but is very similar to XtremeRat, what do you think?


Bye!

VT :
https://www.virustotal.com/es-ar/file/a ... 380807573/

hXXp://fabpasadena.com/includes/js/calendar/Certificaciones%20Calificacion%20Tributaria%20y%20para%20Fiscales.zip
http://urlquery.net/report.php?id=6273753


VT: Dump
https://www.virustotal.com/es-ar/file/1 ... /analysis/

00C82310 ASCII "Portions Copyrig"
00C82320 ASCII "ht (c) 1999,2003"
00C82330 ASCII " Avenger by NhT",0
00C82AAB MOV EDX,DumpedXT.00C82B00 UNICODE "x.html"
00C82B00 UNICODE "x.html",0
00C831E4 UNICODE "CyberGat"
00C831F4 UNICODE "e",0
If you look at memory region dump you attached you will find PE inside packed with UPX containing in resource section "CYBERGATE" item. When you load unpacked exe from this dump into debugger you will notice it create process svchost.exe in suspended state for self-injection. In binary clearly visible numerous:

CYBERGATEBINDER
CyberGateKeylogger
CYBERGATEUPDATESETTINGS
SOFTWARE\CyberGate\
CYBERGATE