Ashley 1.0.1
(Backdoor.Win32.Ashley.100)
(Backdoor.Win32.Ashley.100.b)
(Backdoor.Win32.Ashley.100.d)
(Backdoor.Win32.Ashley.101.a)
(Backdoor.Win32.Ashley.101.c)

by Nexzus

Written in Visual Basic, servers compressed with UPX

Released in October 2000

more versions


This is a uploader trojan that's meant to upload a bigger trojan.
It also server as an IRC worm. Want to have unlimited Victims?
Sent this to your victim and the bigger trojan will be uploded onto his comp.
Also the next time he goes to irc, Ashley will auto attempt to spread
herself to other users on the irc.
When someone else on irc accepts it and execute it, It'll also download
that bigger trojan from the URL you specified and it'll also attempt to
spread itself on irc. 
Therefore you will get more and more victims.
Sure some may say few ppl on irc accepts anonamous 
files anymore. But there are always guilleble users out there.
It may spread slower but it'll still spread.
Even if it doesn't, just treat this as a uploader trojan. 
Version 1.0.0c and version 1.0.0.d of ashley also attempts to spread itself
through outlook e-mail.
Therefor if you use version c or d of it, you will  get much more victims.
HOWEVER both Versions has never been tested before and might not work.
But do test it cos at the most only the e-mail part won't work,
the irc and uploader part should work.
If you do test it, please send some feed backs to me.

The four versions of Ashley:

-Version 1.0.1a is an uploader trojan and irc worm.[14kb]
-Version 1.0.1b is just an uploader trojan and will NOT attempt to spread itself via irc.
 [12.5kb yaya I know it's a  bit big]       
-Version 1.0.1c is an uploader cum irc worm and Outlook worm. 
 [15.5kb Never tested before]
-Version 1.0.1d similar to version c except for different method/ algorithm of spreadin
 through outlook.[15kb ]
-Version 1.0.0c outlook spreading was created based on Senna Spy Worm Algorithm
 and MIGHT be detected by Av.        
 
 Nexzus                                                                            


Server:
C:\WINDOWS\ALL USERS\START MENU\PROGRAMS\STARTUP\EXPLORER.EXE

startup:
C:\WINDOWS\ALL USERS\START MENU\PROGRAMS\STARTUP

MegaSecurity