Y3K rat 1.3
(Backdoor.Win32.Y3KRat.13)
(Backdoor.Win32.Y3KRat.13.a)
(Backdoor.Win32.Y3KRat.13.b)
(TrojanDropper.Win32.Joiner.n)

by -/Chucky-\- and [Firelarm]

Compressed with UPX

Released in August 2000

more versions







Client:
port: 5858, 5881, 5885, 5886, 5887 TCP



Server:
C:\WINDOWS\Advapi32.exe 

size: 296 KB

port: 5882, 5888, 5889 TCP

startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Advapi32" 

MegaSecurity