Home Malware Programs Remote Administration Tools Earthquake 1.5

Earthquake 1.5

Posted: March 28, 2006

This is a Remote Administration Tool , used by hackers for gaining
access to distant PCs. A RAT application works by a simple but effective
principle: the hacker infects the machine with a "server" application via
the e-mail or File and Print Sharing computer and can control it, using a
"client" on his PC. The functions of a RAT can vary, depending on the needs of the attacker. This RAT was designed to create a "backdoor" in the security, so that the intruder can connect to the infected PC and stay completely unnoticed. This Chinese RAT application was created in December 2002. The virus is written in Delphi applicationming language and compressed with ASPack. The interface of the application is also written in Cinese.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 [system
    2 client.exe
    3 server.exe
    4 sysservice.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionunsysservice
Loading...