FireFly 2.3Beta2
(Backdoor.Win32.Delf.aiz)
(Backdoor.Win32.Delf.any)
(Backdoor.Win32.Delf.aja)
(Backdoor.Win32.Delf.aaa)

by wsdgs

Written in Delphi

Released in November 2005

Made in China

more versions


Server:
dropped files:
c:\Program Files\FireFly\FireFlyInfo.ini    Size: 100 bytes 
c:\Program Files\FireFly\Serpent.Exe        Size: 267,289 bytes 
c:\Program Files\FireFly\WinDeBug.exe       Size: 15,456 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_FIREFLY\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FireFly
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FIREFLY\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FireFly


tested on Windows 2000
November 22, 2005

MegaSecurity