|
File type: PE
Memory resident: Yes
Size of malware: 112,640 Bytes
Ports used: Random
Initial samples received on: Nov 8, 2005
Compression type: PECompact
Vulnerability used: (MS04-011) Security Update for Microsoft Windows (835732), (MS03-039) Buffer Overrun In RPCSS Service Could Allow Code Execution, (MS02-061) Elevation of Privilege in SQL Server Web Tasks (Q316333)
Payload 1:
Steals information
Payload 2:
Terminates processes
Payload 3:
Compromises system security
|