Sysmon
(Backdoor.Win32.Sysmon)

by François Piette
Modified by Bomber_guy_uk

Invisible Telnet Server


Server:
c:\windows\system\sysmon.exe 

size: 474 KB

port: 23 TCP

startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run 

MegaSecurity