PiaoYes v2
(Backdoor.Win32.Delf.fr)

by ?

Written in Delphi


Made in China

more versions


installer


installer


Client.exe:
dropped file:
c:\WINDOWS\SYSTEM\client.exe 

size: 171.008 bytes 

port: 2485, 8888, 21009 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "piaoyes" 

registry added:
HKEY_LOCAL_MACHINE\Software\piaoyes 

Tries to connect to specified IRC server and joins a channel to listen for commands

MegaSecurity