Scriptkid Backdoor

Released 18 years, 1 month ago. August 2006

Copyright © MegaSecurity

By _1nf3ct0r_


Informations
From Russia
Author _1nf3ct0r_
Family Scriptkid Backdoor
Category Remote Access
Version Scriptkid Backdoor
Released Date Aug 2006, 18 years, 1 month ago.
Language C, source included
Additional Information
Server:
dropped file:
c:\WINDOWS\system32\Isass.exe
size: 5,001 bytes 

port: 5745 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Userinit"
old data: C:\WINDOWS\system32\userinit.exe, 
new data: C:\WINDOWS\System32\userinit.exe,C:\WINDOWS\System32\Isass.exe 


tested on Windows XP
February 06, 2007

If you recognize any personal information on this page and wish to have it removed or redacted, please contact us at jplesueur@phrozen.io. We are committed to protecting your privacy in accordance with GDPR regulations.