Back Attack 1.8
(Backdoor.Win32.BackAttack.18)

by CurrenTChaoSGroup

Written in Delphi, compressed with UPX

Released in August 2003

Made in Romania

more versions


Server:
dropped files:
c:\WINDOWS\Clear.exe size: 334.848 bytes 
c:\WINDOWS\MaT.scr 
c:\WINDOWS\LICENSE.TXT 

port: 80, 11131 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "RegVn3.3" 

MegaSecurity