Holzpferd 2.2
(Backdoor.Win32.Fenster.20 for Client)
(Backdoor.Win32.Fenster.22 for Server)

by Wolff

Written in Delphi

Released in June 2001

Made in Germany

more versions


Client:
port: 49683 TCP


Server:
dropped file:
c:\WINDOWS\SYSTEM\RundlI32.Exe 

size: 196.608 bytes 

port: 49682 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Rundll32" 

MegaSecurity