Sigs by Matt Jonkman 2003543 through 2003565
View all related Signatures here
This is a windows backdoor, very full features. PrinceAli? is the author. Recent version available at http://www.nuclearwintercrew.com
Sample PCAPs available below.
Versions 1.2 and 1.3+ changed significantly. There's what appears to be some somple XORd network communication in 1.3+. The current sigs work well with the respective versions, but future releases may not be detected if the encryption proto is changed.
-- MattJonkman - 12 Apr 2007