Trojan INV4S10N
(Backdoor.Win32.Agent.ctt)

by Hacker Share

Released in November 2007

Made in Brazil




Server:
Dropped File:
c:\WINDOWS\system32\cftmon.exe
Size: 394,752 bytes 

Port: 1234 TCP

Startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "cftmon"
Data: C:\WINDOWS\system32\cftmon.exe 



Tested on Windows XP
December 04, 2007
MegaSecurity