Home Malware Programs Remote Administration Tools Derek 2.0a

Derek 2.0a

Posted: March 28, 2006

The Hacker infects his victim's PC via the e-mail or File and Print Sharing with a "server" application. This application opens a default port and awaits commands from the attacker. The intruder communicates with the "server" via a "client" application on his PC. This RAT application can be classified as very dangerous, because it has "password capture" ability. It means that all keystrokes, done on the infected machine are stored in a log file, which is later sent to the intruder. He can study this log in order to find passwords and bank account numbers. This pest originated in December 2000.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 derek2.0.a_server.exe
Loading...