God Message


Name: God Message
Aliases: BackDoor-AB.gen (?),
Ports: 80, 121, 7777 (ports can be changed)
Files: Godmessage.zip - 23,247 bytes Godmessage3.zip - 20,683 bytesGodmessage4.zip - 12,974 bytes Onz.exe - Lcoder.exe - 5,264 bytes Gmv.vbs- Lcoder.hex - Xxencode.com - Short.com - Hex2script.exe - 12,800 bytesEa.hta -
Created: Oct 1999
Requires:
Actions: Remote Access / ActiveX trojan / Downloading trojan / Worm / Mailtrojan / IRC trojan / Virus / Network trojan
By just viewing a HTML file or reading a mail a trojan can bedownloaded to the users computer. As of now it installs The Thing 1.6server. Spreads through MS Outlook, shared drives and IRC.
Versions: 3, rev4, 4 rev 2,
Registers: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\
Notes: Works on Windows 95, 98, ME, NT and 2000, together with MS InternetExplorer 5, MS Outlook and mIRC. Password =
Country:
Program: Written in Visual Basic Script (VBS).

© Copyright von Braun Consultants. This information may include technical inaccuracies or typographical errors. If you have any questions or further information about the actual trojan above, please contact Joakim von Braun at <joakim.von.braun@risab.se>