NetSphere


Name: NetSphere
Aliases: NSSX, Backdoor.NSSX, Backdoor.NetSphere,
Ports: 30100, 30101, 30102, 30103 (UDP), 30103, 30133 (can be changed)
Files: Netsphere.zip - 743,990 bytes Netsphere1.27a.zip - Netsphere1.28.zip - Netsphere129.zip - Netsphere1.30.zip - Netsphere131337.zip - Netsphere132.zip - Netspherefinal.zip - Ns1.31.337final.zip - Netsphereclient.exe - 1,068,032 bytes Netsphereclient.exe - Netsphereclient.exe - Netsphereserver.exe - 636,416 bytes Netsphereserver.exe - Netsphereserver.exe - Netsphere129.exe - Netsphere_v130.exe - 721,535 bytes Netsphere132.exe - 727,862 bytes Nets131337.exe - 759,297 bytes Khd2.dll - [41 kb]Icqmapi.dll - [57 kb]Nssx.exe - Epp32.exe -Iosubnet.sys -
Created: April 1999
Requires:
Actions: Remote Access / Keylogger / ICQ trojan
Registers: KEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\
HKEY_USERS\ [All individual users on the PC]\Software\Microsoft\Windows\CurrentVersion\Run\
Notes: Works on Windows 95, 98 and NT, together with ICQ. Version 1.33137 is to be the final release of this trojan. Added to the most common features are Kill CPU, add to ICQ , see the open ports on target, IP scan, view all hidden windows processes, etc.
Country: written in Canada
Program: Written in Delphi 4.

© Copyright von Braun Consultants. This information may include technical inaccuracies or typographical errors. If you have any questions or further information about the actual trojan above, please contact Joakim von Braun at <joakim.von.braun@risab.se>