PitFall Suprise Attack
(Backdoor.Win32.Comando)

by IntrudeR

Released in May 2001

Made in Brazil

more versions




Server:
dropped files:
c:\WINDOWS\SYSTEM\POWERPSA.EXE
size: 154.112 bytes 

port: 11991 TCP

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "LoadPowerPSA"
data: C:\WINDOWS\SYSTEM\POWERPSA.EXE 

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "LoadPowerPSA"
data: C:\WINDOWS\SYSTEM\POWERPSA.EXE 

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices "LoadPowerPSA"
data: C:\WINDOWS\SYSTEM\POWERPSA.EXE 

Server does kill some Anti-Virus Programs (AVP)

tested on Windows 98
November 08, 2004

MegaSecurity