An Inproc Server32 is then registered, allowing the data collected to begin to move from infected computer to the trojanners server/home pc.
Code:
Connections
Server: deadverb.freehostia.com
Service: INTERNET_SERVICE_FTP
Successful: 1
Api-Function: InternetConnectA
This Trojan then connects to a free host.
Code:
Outgoing Connections
FTP Data
User Name v1sp3t
Password 2629342
Passive Mode 1
Remote Data Port 53860
Login Successful 1
Plain Communication Data
And passes the proper information to the free FTP server. Username and password is needed for this trojan to finish transfering the collected data from the infected computer to the trojanners server/home pc.
Here we show that its making a TCP connection from the trojanners server IP on which port and what protocol; FTP.
We will now delete the collected data from this particular trojanner.
Quote:
226 Transfer complete.
CWD /
250 CWD command successful.
RMD Mu Online
250 RMD command successful
DELE MIHAJLOVI_260809_1936.html
250 DELE command successful.
DELE PC-25_260809_2106.html
250 DELE command successful.
DELE SLOTPC_260809_2055.html
250 DELE command successful.
DELE LENOVO-4903350B_270809_0331.html
250 DELE command successful.
DELE LENOVO-4903350B_270809_0332.html
250 DELE command successful.
DELE MERC-AD53B44336_260809_1704.html
250 DELE command successful.
DELE MERC-AD53B44336_260809_1730.html
250 DELE command successful.
DELE FILIPPIN_260809_1909.html
250 DELE command successful.
DELE OWNER-PC_260809_2019.html
250 DELE command successful.
DELE DEVON-PC_260809_2121.html
250 DELE command successful.
DELE PC2_041019_1713.html
250 DELE command successful.
DELE PETER_030907_1817.html
250 DELE command successful.
PASV
227 Entering Passive Mode (66,40,52,62,196,139).
LIST -al
150 Opening ASCII mode data connection for file list
226 Transfer complete.
Quote:
F[Only registered and activated users can see links. ]
Report generated: 27.8.2009 at 4.17.37 (GMT 1)
Filename: program.exe
File size: 1171 KB
MD5 Hash: 2da2c50aa242b02a4c57874a7084e585
SHA1 Hash: 9EA954F432262D24D35864D304710AB15AE17905
Self-Extract Archive: Nothing found
Binder Detector: Nothing found
Detection rate: 13 on 22