| Name: | God Message |
| Aliases: | BackDoor-AB.gen (?), |
| Ports: | 80, 121, 7777 (ports can be changed) |
| Files: | Godmessage.zip - 23,247 bytes Godmessage3.zip - 20,683 bytesGodmessage4.zip - 12,974 bytes Onz.exe - Lcoder.exe - 5,264 bytes Gmv.vbs- Lcoder.hex - Xxencode.com - Short.com - Hex2script.exe - 12,800 bytesEa.hta - |
| Created: | Oct 1999 |
| Requires: | |
| Actions: | Remote Access / ActiveX trojan / Downloading trojan / Worm / Mailtrojan / IRC trojan / Virus / Network trojan |
| By just viewing a HTML file or reading a mail a trojan can bedownloaded to the users computer. As of now it installs The Thing 1.6server. Spreads through MS Outlook, shared drives and IRC. | |
| Versions: | 3, rev4, 4 rev 2, |
| Registers: | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ |
| Notes: | Works on Windows 95, 98, ME, NT and 2000, together with MS InternetExplorer 5, MS Outlook and mIRC. Password = |
| Country: | |
| Program: | Written in Visual Basic Script (VBS). |