by Nexzus
Released in October 2000
This is a uploader trojan that's meant to upload a bigger trojan.
It also server as an IRC worm. Want to have unlimited Victims?
Sent this to your victim and the bigger trojan will be uploded
onto his comp.
Also the next time he goes to irc, Ashley will auto attempt to spread
herself to other users on the irc. When someone else on irc accepts it
and execute it, It'll also download that bigger trojan from the URL you
specified and it'll also attempt to spread itself on irc.
Therefore you will get more and more victims. Sure some may say few ppl on irc
accepts anonamous files anymore. But there are always guilleble users out there.
It may spread slower but it'll still spread.
Even if it doesn't, just treat this as a uploader trojan.
Version 1.0.0c and version 1.0.0.d of ashley also attempts to spread itself
through outlook e-mail.
Therefor if you use version c or d of it, you will get much more victims.
HOWEVER both Versions has never been tested before and might not work.
But do test it cos at the most only the e-mail part won't work,
the irc and uploader part should work.
If you do test it, please send some feed backs to me.
Any comments or bugs(I'm sure there's plenty of them) or suggestion,
sent mail to [email protected]
#############
#What's new #
#############
-Optional Error msg and Configurable msg.
-Destroy Victim's Netstat upoon d/l of the trojan from the web. [For paronoid ppl]
-Mass Server Command First you enter the url of the txt file u want the server to
check for command. Eg: http://geocities.com/nexzus/test.txt.
Now u up load the a.txt file into that geocities add.
Everytime ashley starts up it'll get the command from the test.txt file on geocities.
As for wat are the commands . In test.txt it contains only one digit to represent that commands:
"1" To Stop all Trojan Activites
"2" To redownload the trojan from the website.
"3" Icq notify you everytime the victim is online.
This is useful incase your other trojan icq notification does not work.
Some sort of a backup icq notification.
"9" to destroy the victim comp [ please dun abuse]
So for eg u want the victim to icq notify u everytime he's online.
go in a.txt file just type:
3
in a.txt.That's it.. Now save a.txt and upload it to geocities etc..]
-Banner Clicking This option is for banner displaying.
You enter the full path of the banner cgi's url and whenever the user is online,
he'll retrive the banner 50 times.
Take note.. it only RETRIVIE the banner , not CLICKING them..
So for those ads that requires clicking this won't work.. BUT there are ads that pay
u just for each time a banner is display. eg allclicks.com etc..... basically this is
also for webmasters who are using banner exchange stuff.
-Added a updater.exe. Antivirus is detecting this rather quick.
So i will release a undetected servers every 2 weeks or so.
It can only be d/l via the updater.Check for updates every 2 weeks.
When running the updater, it will open your web browser and bring u to our sponsers page.
This allow us to make some $ and to server u better. So plz do support us.
############
# Servers #
############
There are 3 different Servers this time:
-ashley1.1.0a Is just the basic one without any worm capability
-ashley1.1.0b uploads the trojan from the web and also spread itself via mirc and outlook.
-ashley1.1.0c is the same as version b but base on different algorithm.
*note ashley1.1.0b outlook spreading was base on senna spy worm algorithm
As usualy version a is working perfectly and version b and c has not been tested fully.
Try them and let me know.
That's all. Any mails sent them to [email protected]
############
#Shoutouts:#
############
Wildphir3
MaskDemon -This guy help me design some fo the graphics.. visit him at www.morbus.co.uk
All the beta testers
Eveyone at Innervoid
& of cos Ashley *grinz
Nexzus
MegaSecurity