FireFly 1.5
(Backdoor.Win32.Delf.aaa for Client)
(Backdoor.Win32.Delf.zn)

by wsdgs

Written in Delphi, compressed with UPX

Released in April 2005

Made in China

more versions


Server:
dropped files:
c:\WINNT\system32\Intenat.exe    Size: 13,355 bytes 
c:\WINNT\system32\Notepad.txt    Size: 13,355 bytes 
c:\WINNT\system32\Serpent.Exe    Size: 256,000 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "system"
data: Serpent.Exe 

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideo
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo



tested on Windows 2000
April 18, 2005

MegaSecurity