Lizards Tail
(Backdoor.Win32.Lizard.11)
(Trojan.PSW.IDI for serveur_avec_jeu_mamba.exe)

by Marcel

Written in Delphi, source included

Released in February 2002

Made in France


Server1 (serveur_sans_le_jeu.exe, 184 KB):
c:\WINDOWS\HELP\hlp.exe 

size: 187.904 bytes 

port: 23, 81, 714, 8181, 23762 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "hlp.exe" 

added:
c:\WINDOWS\SYSTEM\dxdlg.exe 




Server2 (serveur_avec_jeu_mamba.exe, 271 KB):
c:\WINDOWS\HELP\hlp.exe 

size: 187.904 bytes 

port: 23, 81, 714, 8181, 23762 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "hlp.exe" 

added:
c:\WINDOWS\TEMP#01.EXE 
c:\WINDOWS\TEMP$01.EXE 

MegaSecurity