System33r Socks5 (klorin) 1.0
(Not detected by AVP on October 15, 2004)
(Constructor.Win32.SS.11.b for editor)

by System33r (k0nsl)

Released in October 2004

more versions


System33r Socks5 (klorin) v1.0 by System33r ([email protected])

System33r Socks5 is a socks5 server with a 'trojan'-like behaviour (extremely stable)

Main Features:
- SubSeven CGI Notification
- Installation (Copies to SystemDirectory, and adds Registry entries)
- DeleteSelf (melt)
- Identd
- It's horribly stable

System33r


Server:
dropped file:
c:\WINDOWS\system32\test.exe
size: 4.113 bytes
 
port: 113 TCP

startup:
KEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows Script Host"
data: C:\WINDOWS\System32\test.exe 

tested on Windows XP

MegaSecurity