Phoenix2 1.62
(Backdoor.Win32.Phoenix.162)

by C)DMP & Kaosł

Written in Microsoft Visual C++

Released in September 2001

Made in Italy

more versions


dropped file:
c:\WINDOWS\Msatrib.exe 
size: 204.800 bytes 

port: 7410 TCP

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Msatrib" 
data: C:\WINDOWS\Msatrib.exe 

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce "~IYSTPVI" 
data: C:\WINDOWS\Msatrib.exe /del:C:\WINDOWS\TEMP\~IYSTPVI.exe 


tested on Windows 98
December 17, 2004

MegaSecurity