1023Telnet Batch
(TrojanDropper.Win32.StealthBat)

by heroin

Released in July 2003


 		-add Localgroup Telnetclients
 		-add User IWAM_USER Password:her0in
 		-add User IWAM_USER to Groups: Administrators
		-Start Telnet Service on Port 1023
 		-DisableLog, Autostart every Systemstart


	telnet xxx.xxx.xxx.xxx 1023
	Login: IWAM_USER
	Password: her0in




Ready Compiled to an executable and Packed with UPX

1023Telnet.d.exe = german operating system
1023Telnet.e.exe = english operating system

-heroin



size: 3.584 bytes

port: 1023 TCP

added to registry:
HKEY_USERS\.DEFAULT\Console\C:_WINNT_system32_tlntsess.exe
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TLNTSVR\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TlntSvr\Enum
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TLNTSVR\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\Enum

MegaSecurity