IRAT Built 1001
(Trojan-Downloader.Win32.Delf.jdc for IRAT.DLL)
Trojan.Win32.Agent.bkpp for Server)

by HF

Written in Delphi

Released in October 2007

Made in China

more versions

 





Server:
Dropped Files:
c:\WINDOWS\system32\IRAT.DLL        Size: 58,981 bytes 
c:\WINDOWS\system32\IRAT.DLL.uns    Size: 8,192 bytes 

Added to Registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IRAT\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IRAT\Enum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IRAT\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IRAT\Security
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IRAT\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IRAT
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IRAT\Enum
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IRAT\Parameters
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IRAT\Security



Tested on Windows XP
October 09, 2007
MegaSecurity