Hellojan 1.0 Public Edition
(Not detected by KAV on April 08, 2008)

by hellojand

Released in March 2008

Made in Turkey

 


Client
Port: 52365 TCP


Server
Dropped Files:
c:\WINDOWS\system32\win0.exe          Size: 322,711 bytes 
c:\WINDOWS\system32\win1.exe          Size: 322,711 bytes 
c:\WINDOWS\system32\win2.exe          Size: 322,711 bytes 
c:\WINDOWS\system32\win3.exe          Size: 322,711 bytes 
c:\WINDOWS\system32\win4.exe          Size: 322,711 bytes 
c:\WINDOWS\system32\win5.exe          Size: 322,711 bytes 
c:\WINDOWS\system32\wspoolsv32.exe    Size: 322,711 bytes 

Startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Spoolsv Starter"
Data: c:\windows\system32\wspoolsv32.exe 

Server does open 945 ports



Tested on Windows XP
April 08, 2008

MegaSecurity