FireFly 2.1
(Backdoor.Win32.Delf.aaa)
(Backdoor.Win32.Delf.adi)
(Backdoor.Win32.Delf.zn)
(Backdoor.Win32.Delf.aai)

by wsdgs

Written in Delphi, compressed with UPX

Released in April 2005

Made in China

more versions


Server:
dropped files:
c:\Program Files\FileFly\Intenat.exe    Size: 13,866 bytes 
c:\Program Files\FileFly\Notepad.txt    Size: 13,866 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "abc"
data: C:\Program Files\FileFly\Intenat.exe 




tested on Windows 2000
April 23, 2005

MegaSecurity