Seastar 1.101
(Trojan.Win32.Patcher.i for Client)
(Backdoor.Win32.Bifrose.la for Server)

by hh

Released in June 2008

Made in China

 





Server
Dropped Files:
c:\WINDOWS\LastGood\system32\setup.exe
Size: 72,391 bytes 

c:\WINDOWS\system32\plugin1.dat
Size: 51,733 bytes 

c:\WINDOWS\system32\dllcache\setup.exe
Size: 23,040 bytes 



Added to Registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "startkey"
Data: C:\WINDOWS\system32\setup.exe 



Tested on Windows XP
June 19, 2008

MegaSecurity