LESEAL Backdoor (a)
(Backdoor.Win32.Sealer.a)

by LESEAL

Written in Delphi, compressed with UPX

Released in May 2004

Made in Russia




dropped file:
c:\WINDOWS\system32\winupd.exe
size: 168.448 bytes 

port: 1764 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "winupd"
data: c:\Windows\System32\winupd.exe 


tested on Windows XP
December 25, 2004

MegaSecurity