Home Malware Programs Remote Administration Tools Little Witch

Little Witch

Posted: March 28, 2006

Little Witch is a large RAT virus family. Many versions appeared from May 2001 to January 2004. The pest is written in Delphi applicationming language. The author is an Argentinian hacker called Axlito. A RAT works by a simple principle: the attacker infects the PC via the e-mail or File and Print Sharing. A "server" allows him to connect via a "client" on his own machine. Once inside the computer, the virus opens a default TCP port and awaits hacker commands. This RAT also has the ability to log keystrokes. The collected information is stored in the PC and later sent to the intruder. He can study this log in order to find some valuable information, such as bank account numbers, passwords, etc.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 backdoor.littlewitch.61.o.exe
    2 leeme.txt
    3 lwclient.exe
    4 lwclient5.1.exe
    5 lwclient5.2.exe
    6 lwclient5.3.exe
    7 lwserver.exe
    8 lwserver_base.exe
    9 lwserver_full.exe
    10 lwserver_full5.1.exe
    11 lwserver_full5.2.exe
    12 lwserver_full5.3.exe
    13 miniserver.exe
    14 miniserver10.exe
    15 miniserver12.exe
    16 miniserver17.exe
    17 miniserver18.exe
    18 miniserver2.exe
    19 miniserver20.exe
    20 miniserver22.exe
    21 miniserver3.exe
    22 miniserver4.exe
    23 miniserver6.exe
    24 miniserver7.exe
    25 news.txt
    26 novedades.html
    27 remover2.0.exe
Loading...