PA HAC 1.3 2004 alfa

Copyright © MegaSecurity

By PA HAC


Informations
From Poland
Author PA HAC
Family PA HAC
Category Remote Access
Version PA HAC 1.3 2004 alfa
Language Delphi
Additional Information
Server1:
dropped file:
c:\WINDOWS\SYSTEM\SystemTray.exe

size: 423.424 bytes
 
port: 1086, 1986, 1910, 8610, 1010 TCP 

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "LoadPowerProfile"
old data: Rundll32.exe powrprof.dll,LoadCurrentPwrScheme 
new data: C:\WINDOWS\SYSTEM\SystemTray.exe 



Server2:
dropped file:
c:\WINDOWS\SYSTEM\SystemTray.exe
 
size: 423.936 bytes
 
port: 1086, 1986, 1910, 8610, 1010 TCP 

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "LoadPowerProfile"
old data: Rundll32.exe powrprof.dll,LoadCurrentPwrScheme 
new data: C:\WINDOWS\SYSTEM\SystemTray.ex

If you recognize any personal information on this page and wish to have it removed or redacted, please contact us at jplesueur@phrozen.io. We are committed to protecting your privacy in accordance with GDPR regulations.