Doing

Released 20 years, 11 months ago. July 2004

Copyright © MegaSecurity

By jocanor


Doing
Informations
Author jocanor
Family Doing
Category Remote Access
Version Doing
Released Date Jul 2004, 20 years, 11 months ago.
Language Visual Basic, Server is compressed with UPX
Additional Information
Server:
dropped files:
c:\WINDOWS\DIjpg.dll       Size: 413,756 bytes 
c:\WINDOWS\MSWINSCK.OCX    Size: 108,336 bytes 
c:\WINDOWS\win32api.exe    Size: 53,248 bytes 

port: 7744, 5454 TCP

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "win32api.exe"
data: C:\windows\win32api.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "win32api.exe"
data: C:\windows\win32api.exe 



tested on Windows XP
May 30, 2005


If you recognize any personal information on this page and wish to have it removed or redacted, please contact us at jplesueur@phrozen.io. We are committed to protecting your privacy in accordance with GDPR regulations.