Soheil-PS
Copyright © MegaSecurity
By Soheil
 
                Informations
| From | The Middle East | 
| Author | Soheil | 
| Family | Soheil-PS | 
| Category | Information Stealer | 
| Version | Soheil-PS | 
| Language | Visual Basic | 
Additional Information
Server:
dropped files:
c:\WINDOWS\system\shell32.dll    Size: 114 bytes 
c:\WINDOWS\system\svchost.exe    Size: 49,664 bytes 
startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell"
old data: Explorer.exe 
new data: Explorer.exe C:\WINDOWS\system\svchost.exe 
tested on Windows XP
August 23, 2006If you recognize any personal information on this page and wish to have it removed or redacted, please contact us at jplesueur@phrozen.io. We are committed to protecting your privacy in accordance with GDPR regulations.