Dark Machine Troyan Beta
(Trojan-Dropper.Win32.VB.rr)
(Backdoor.Win32.ServU-based)

by Zauron

Written in Visual Basic

Released in September 2007




Server:
Dropped Files:
c:\WINDOWS\KEY.OLD               Size: 71 bytes 
c:\WINDOWS\System32.dll          Size: 1,017,344 bytes 
c:\WINDOWS\System32.exe          Size: 24,861 bytes 
c:\WINDOWS\System32ini.dll       Size: 900 bytes 
c:\WINDOWS\system32\Batch.bat    Size: 163 bytes 

Startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "System32"
Data: C:\WINDOWS\System32.exe 


Tested on Windows XP
October 08, 2007

MegaSecurity