FireFly 1.0
(Backdoor.Win32.Delf.aaa)
(Backdoor.Win32.Delf.acc)
(Backdoor.Win32.Delf.abh)
(Trojan-Downloader.Win32.Agent.lk)

by ?

Written in Delphi, compressed with UPX

Released in March 2005

Made in China

more versions


Server:
dropped files:
c:\WINNT\system32\Intenat.exe    Size: 13,340 bytes 
c:\WINNT\system32\Notepad.txt    Size: 13,340 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "abc"
data: Intenat.exe 


tested on Windows XP
April 02, 2005

MegaSecurity