GrayPigeon (a)
(Backdoor.Win32.Hupigon.a)

by ?

Compressed with ASPack

Released in August 2002

Made in China

more versions


Win98:
Server:
dropped files:
c:\WINDOWS\Notepod.exe 
c:\WINDOWS\SYSTEM\kernel32.exe 

size: 291.469 bytes
 
port: 8080 TCP

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "LoadWindowsFile" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices "LoadWindowsFile" 
HKEY_CLASSES_ROOT\exefile\shell\open\command "(Default)" 
HKEY_CLASSES_ROOT\txtfile\shell\open\command "(Default)"



Win2000:
servers:
c:\WINNT\Notepod.exe 
c:\WINNT\system32\Kernel32.exe

size: 291.469 bytes  

port: 8080 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices "LoadWindowsFile" 
HKEY_CLASSES_ROOT\exefile\shell\open\command "(Default)" 
HKEY_CLASSES_ROOT\txtfile\shell\open\command "(Default)" 
 
MegaSecurity