FireFly 2.3
(Backdoor.Win32.Delf.agq for Client)
(Backdoor.Win32.Delf.iia)

by wsdgs

Written in Delphi

Released in September 2005

Made in China

more versions


Server:
dropped files:
c:\Program Files\FireFly\Info.ini        Size: 64 bytes 
c:\Program Files\FireFly\WinDeBug.exe    Size: 16,412 bytes 

port: 1266 TCP

added to registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_FIREFLY
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FireFly
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FIREFLY
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FireFly


tested on Windows 2000
October 04, 2005

MegaSecurity