Sadahacher 1.0
(Backdoor.Win32.Ullysee.b for Server)
(Client is infected with Virus.Win32.Parite.b)

by Sada

Written in Visual Basic

Released in February 2004

Made in The Middle East


Server
dropped file:
c:\WINDOWS\system\system java.exe
size: 35,328 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices "windowssl2.0"
data: C:\Windows\System\system jav 



tested on Windows XP
April 30, 2007

MegaSecurity