CyberRat 1.70
(Backdoor.Win32.Cyberat.170)

by ?

Written in Delphi

Released in November 2005

 


Server:
dropped files:
c:\WINDOWS\win32log.dat     Size: 263 bytes 
c:\WINDOWS\@@@\mydll.dll    Size: 233,472 bytes 
c:\WINDOWS\@@@\PID.dat      Size: 4 bytes 
c:\WINDOWS\@@@\WIN32.EXE    Size: 343,308 bytes 

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "@@@"
data: C:\WINDOWS\@@@\WIN32.EXE 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "@@@"
data: C:\WINDOWS\@@@\WIN32.EXE 



tested on Windows XP
January 27, 2006

MegaSecurity