Shadow Phyre (b)
(Backdoor.Win32.ShadowPhyre.b)

by Cheitan, Mayhem and Phr33k

more versions


Server:
dropped file:
C:\WINDOWS\SYSTEM\WinZip.exe 

size: 228 KB

port: 55555 TCP 

startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run 

MegaSecurity