DjiRAT
(Not detected by KAV on August 29, 2008)

by Hamtaro

Written in Visual Basic

Released in February 2007



Server:
dropped file:
c:\WINDOWS\system32\adobe loader.exe
size: 438,272 bytes 

port: 2886 TCP

added to registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "djiRAT-slave"



tested on Windows XP
August 26, 2007

MegaSecurity