HGZ 2004 Build 20040829
(Backdoor.GrayBird.x for client)
(TrojanSpy.Win32.Delf.df for server)

by HGZ

aka GrayPigeon

Written in Delphi

Released in August 2004

Made in China

more versions


Client:
port: 8000 TCP


Server:
dropped files:
c:\WINNT\system32\G_Server.DLL  size: 26.624 bytes 
c:\WINNT\system32\G_Server.exe  size: 273.220 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_GRAYPIGEONSERVER\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\GrayPigeonServer\Enum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\GrayPigeonServer\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_GRAYPIGEONSERVER\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GrayPigeonServer\Enum
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GrayPigeonServer\Security
	
tested on Windows 2000	

MegaSecurity