Phoenix2 1.28
(Backdoor.Win32.Phoenix.128)

by C)DMP & Kaosł

Written in Microsoft Visual C++

Released in June 2001

Made in Italy

more versions


Server:
dropped files:
c:\WINDOWS\Msatrib.exe  size: 200.704 bytes 
c:\WINDOWS\TEMP\ .exe   size: 200.704 bytes
 
port: 7410 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Msatrib"
data: C:\WINDOWS\Msatrib.exe

tested on Windows 98
November 18, 2004 

MegaSecurity