CN Polyserver 1.0
(Backdoor.Delf.mw)

by matiteman, modified by ?

Written in Delphi

Released in april 2004

more versions




Server:
port: 21, 12000 TCP

dropped files:
c:\WINDOWS\icmd.exe              size: 19.456 bytes 
c:\WINDOWS\iexplore.exe          size: 254.978 bytes 
c:\WINDOWS\internetexplorer.exe  size: 25.600 bytes 
c:\WINDOWS\mtm.txt               size: 350 bytes 
c:\WINDOWS\socks4.exe            size: 11.264 bytes

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "clock" 
data: C:\WINDOWS\iexplore.exe

MegaSecurity