Phoenix2 1.46
(Backdoor.Win32.Phoenix.144)
(Backdoor.Win32.Phoenix.146)

by C)DMP & Kaosł

Written in Microsoft Visual C++

Released in July 2001

more versions

Made in Italy


Server:
dropped files:
c:\WINDOWS\Msatrib.exe        size: 204.800 bytes 
c:\WINDOWS\TEMP\~OEQYFZG.exe  size: 204.800 bytes 

Port: 7410 TCP

added to registry:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Msatrib"
data: C:\WINDOWS\Msatrib.exe 

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce "~OEQYFZG"
data: C:\WINDOWS\Msatrib.exe /del:C:\WINDOWS\TEMP\~OEQYFZG.exe 

tested on Windows 98
November 18, 2004

MegaSecurity