B.R.E.A.C.H 4.5 beta
(Backdoor.Win32.Breach.45)

by -[FrEaK + HYBRiD]

Written in Delphi

Released in March 2000

more versions


Language:
Delphi 5 Enterprise
Build : 172

Functions:

Inline File Client
Swap Mouse Buttons
Mouse Trails
Key Trapper
File Search
Open CD-ROM
Delete File
Execute File
Send to URL
Port Change
Reboot
Remove Server
Logoff Windows
Powerdown
System Name / Time
Engage Chat
Wallpaper 
Show Image
Play Sound

BREACH is a Remote Administration Trojan for Windows 95/98 and NT
 ... it has been tested in all three environments and worked flawlessly.
 
[FrEaK + HYBRiD] 


Server:
dropped file:
c:\WINDOWS\windll.exe
size: 541.184 bytes
 
port: 420, 22845, 22847 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Windll.exe"
data: C:\WINDOWS\Windll.exe

tested on Windows 98 

MegaSecurity