Shipo 1.5
(Backdoor.Win32.Delf.ee)

by ?

Written in Delphi, compressed with ASPack

Released in May 2005

Made in China


Server:
dropped file:
c:\WINNT\system32\SysService.exe
size: 177,664 bytes 

port: 2444 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "SysService"
data: C:\WINNT\system32\SysService.exe 

tested on Windows 2000
May 27, 2005

MegaSecurity