.: BirdSPY (b) :.
- From: Taiwan
- Coded by: Chiu a.k.a Birdman
- Version: BirdSPY (b)
- Coded in: Visual C++, compressed with ASPack
- Family: BirdSPY
- Category: Remote Access
Server: dropped files: c:\WINDOWS\Ndapi32K.dll c:\WINDOWS\winstart.bat c:\WINDOWS\�.bat c:\WINDOWS\SYSTEM\WinSock.exe Size: 27.648 bytes c:\WINDOWS\Winbife.scr Size: 27.648 bytes port: 50829 TCP startup: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "MS-Screen" HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
URL's and mails were automatically redacted (filtered) for reader's safety. However the filter is not perfect and can't find all harmful elements. If you find something dangerous including file link, website, mail address, profanity... contact me immediately at firstname.lastname@example.org, thank you in advance.