El control remoto mas antiguo del mudo
(Backdoor.Win32.Delf.kh)

by ?

Original Filename: Amistad.exe

Written in Delphi


Server:
dropped file:
c:\WINDOWS\inf\SVCHOST.exe
size: 106,496 bytes 

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows "RUN"

attempts to connect to an IRC Server

tested on Windows XP
August 05, 2005

MegaSecurity