Uploader
(Backdoor.Win32.Delf.rb)

by (v)aster

Written in Delphi, compressed with UPX

Released in July 2004


Server:
dropped file:
c:\WINDOWS\SYSTEM\WLNLOGON.EXE

size: 9.216 bytes 

port: 1337 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "WindowsAutoLogon"
data: C:\WINDOWS\SYSTEM\WLNLOGON.EXE 

MegaSecurity