Spy Uploader 1.0
(Trojan-Downloader.Win32.Agent.ll)

by PersiaCracker

Written in Assembler, compressed with FSG

Released in September 2005

Made in the Middle East

 


Server:
dropped file:
c:\WINDOWS\system32\comctl.exe
size: 5,033 bytes 

port: 551 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Mscomctl"
data: C:\WINDOWS\System32\comctl.exe 
	
	
	
tested on Windows XP
March 12, 2006	

MegaSecurity