Suckz Trojanh
(Backdoor.Win32.Agent.ctu)

by log_22

Released in November 2007

Made in Brazil




Server
Dropped File:
c:\WINDOWS\system32\win32.exe
Size: 555,559 bytes 

Port: 3961, 3962 TCP

Startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "win32"
Data: C:\WINDOWS\System32\win32.exe 


Tested on Windows XP
November 25, 2007

MegaSecurity