Threat Database Keyloggers Keylogger.Ardamax

Keylogger.Ardamax

By CagedTech in Keyloggers

Threat Scorecard

Ranking: 7,556
Threat Level: 80 % (High)
Infected Computers: 10,238
First Seen: July 24, 2009
Last Seen: March 23, 2024
OS(es) Affected: Windows

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Fortinet W32/Gbot.YRA!tr.bdr
AntiVir SPR/Tool.Ardamax.556
Kaspersky Backdoor.Win32.Gbot.yra
McAfee Artemis!647F311B4718
AVG Ardamax.BUD
BitDefender MemScan:Trojan.Generic.8306227
Avast Win32:Ardamax-PU [PUP]
McAfee Artemis!3DEBCBACE7A0
AVG Ardamax.BWQ
DrWeb Trojan.KeyLogger.18881
McAfee Artemis!D7BB86DA5866
DrWeb Trojan.KeyLogger.19070
DrWeb Trojan.KeyLogger.16596
Avast Win32:Ardamax-QG [PUP]
AntiVir SPR/Tool.Monitor.Gen

File System Details

Keylogger.Ardamax may create the following file(s):
# File Name MD5 Detections
1. CSJ.exe 29a6ac921bfd693769a7f7e255dc2e77 37
2. setup_akl64 (password=ardamax).exe e33b737b368c02ef9b7c908c9472dfef 14
3. DFC.exe b37aad7a36fbbb2d2054e082d590a76c 11
4. AKV.exe b8fa30233794772b8b76b4b1d91c7321 8
5. LYA.exe 3cd29c0df98a7aeb69a9692843ca3edb 7
6. AKV.exe 51507d91d43683b9c4b8fafeb4d888f8 5
7. CSJ.exe 16a7080bdbdd3c66f6edef08c5bea843 5
8. ETK.exe 56dce36cac37d632bf722e9804e4965e 4
9. BCR.exe b910f5d24e399a13f6aae20535ac05b4 4
10. setup_akl64 (password=ardamax).exe e3d267c02ec24bd475e394551cca6ad0 4
11. MAI.exe e40fa583acd317b71575596bd8bc10b8 3
12. MSQ.exe f22340c8c0caad1136de9bec84c82281 3
13. ELU.exe 785197d7f66a482b64c5ae297016d24e 3
14. POL.exe 8459b0ba642d016c60571a3ad31e6ec8 3
15. setup_akl (password=ardamax).exe 725f36560115d2a096df3e499d6ba449 3
16. TND.exe a6c12264242dba831b32523a07688d4a 2
17. QHI.exe d5918580ed2951ab6b1a5a94719757ff 2
18. FYB.exe 14f067c0291ce6a4a4c4735ba7f4712d 2
19. WDI.exe ed53cef3e425639f180392ccf031f9ce 2
20. NGK.exe 0aaffc12ef1b416b9276bdc3fdec9dff 2
21. HWF.exe 647f311b471810298c1d0b3b43966d8c 2
22. UIB.exe 47d45da7bc718cef809ecec470987248 1
23. YHF.exe ff5d248fc602b8d6fb11a7aa8cf27391 1
24. YEY.exe 53522c8c3b01191caae1e1e2692c42de 1
25. YHH.exe 7f9e58f1df8721ed17066d08a769c73a 1
26. JTF.exe ce6e2998fc31ef25e3771cd7be4f4e75 1
More files

Registry Details

Keylogger.Ardamax may create the following registry entry or registry entries:
File name without path
setup (password=ardamax).exe
Regexp file mask
%APPDATA%\support\svchost.exe

Directories

Keylogger.Ardamax may create the following directory or directories:

%ALLUSERSPROFILE%\auk
%ALLUSERSPROFILE%\cve
%WINDIR%\Syswow64\sys32
%WINDIR%\system32\sys32

Related Posts

Trending

Most Viewed

Loading...