FireFly 2.2 HackBase
(Backdoor.Win32.Delf.aaa for Client)
(Backdoor.Win32.Delf.zn for Server)
(Trojan.Win32.Agent.cu)

by wsdgs

Written in Delphi, compressed with UPX

Released in May 2005

Made in China

more versions


Server:
dropped files:
c:\Program Files\FireFly\FireFly.Dat    Size: 43 bytes 
c:\Program Files\FireFly\Intenat.exe    Size: 12,932 bytes 
c:\Program Files\FireFly\Notepad.txt    Size: 12,932 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "system"
data: C:\Program Files\FireFly\Intenat.exe 




tested on Windows XP
June 01, 2005

MegaSecurity