Shalan 1.06
Released 18 years, 11 months ago. December 2005
Copyright © MegaSecurity
By Red Move
Informations
Author | Red Move |
Family | Shalan |
Category | Information Stealer |
Version | Shalan 1.06 |
Released Date | Dec 2005, 18 years, 11 months ago. |
Language | Visual Basic, compressed with UPX |
Additional Information
Server:
dropped file:
c:\WINDOWS\system32\Mscng.exe
size: 13,362 bytes
startup:
HKEY_CLASSES_ROOT\exefile\shell\open\command "(Default)"
old data: "%1" %*
new data: Mscng.exe opext "%1" %*
tested on Windows XP
January 23, 2006
Author Information / Description
Shalan is a pass sender that can send Yahoo Messenger & ICQ passwords to you.
--------
Features
--------
+ Both email and cgi logger notificatDon.
+ Fake message at double click on server.
+ Run file at double click on server.
+ Able to change icon.
+ Binder.
+ Firewall bypassing.
+ Undetectable by anti viruses.
+ Not shown in msconfig.
+ Diabolic startup
+ Server size is about 13.5 KB
Version 1.06 - December/22/2005
* Mail Sending bug fixed.
Red Move
If you recognize any personal information on this page and wish to have it removed or redacted, please contact us at jplesueur@phrozen.io. We are committed to protecting your privacy in accordance with GDPR regulations.