Ok, I've received the virus and it does indeed what was described above...
It's 4am here so I'm gone now, but I'll certainly take a look again tomorrow.
Anyway, since I was curious, here some facts:
- It is not recognized by current F-Secure antivirus
- The executable that stays running and connects to IRC servers etc is 'sysconf32.exe' (stored in c:\winnt\sysconf32.exe), this is also added to runservices so it starts on boot (well, on login).
- Has a nice file c:\ReAd_ThiS_ShiT.txt:
Code: Select all
Microsoft, you can lick my discusting ass
Bill Gates, suck my hairy balls
All AV companies, suck my huge cock
You can arrest all of us, but there will always be someone to shit on your software.
-------------------------------
Hey Gates, even if you gave all your millions,
you couldn't stop virus coders, especially me! You should better fix
your own software than use the money to stop us
So suck my big d*ck :)
-------------------------------
Greets to:mOfo,MorphinE,e-man,e[a]x,pcmaniac
all Bihnet.org,DTM,ACIdPheaK,Dominus
-------------------------------
greets from ACIdCooKie (old/skool)
see ya next time bro hehehe.. / 1997-2004
VirusKrew of Serbia
(boring :P)
- Creates a nice c:\irclog.txt where it stores stuff
- Has a .vbs script which does some stuff with (collecting) email addresses.
- The following servers are found in the binary:
Code: Select all
irc.afternet.org
irc.accessirc.net
irc.ablenet.org
irc.afterx.net
irc.amcool.net
irc.angeleyez.net
irc.animeirc.de
irc.aniverse.com
irc.arabmirc.net
irc.astrolink.org
irc.asylum-net.org
irc.aurosoniq.net
irc.awesomechat.net
irc.axenet.org
irc.bdsm-net.com
irc2.beyondirc.net
irc.blabber.net
irc.blitzed.org
irc.bolchat.org
irc.bongster.org
irc.brokenirc.net
irc.chat4all.org
irc.chatnet.org
irc.chatsociety.net
irc.chatspike.net
irc.chung.li
irc.coolchat.net
irc.crazednet.co.uk
irc.dal.net
irc.dark-storm.net
irc.d-t-net.de
irc.deviantart.com
irc.rizon.net
irc.tsk.ru
irc.saltek.net
irc.scoobynet.org
irc.serbiancafe.ws
irc.sexnet.org
irc.shadowfire.org
irc.syrolnet.org
irc.thundercity.net
irc.unionlatina.org
irc.unreal-irc.net
irc.webchatting.com
irc.webchat.org
irc.whatnet.org
irc.msinternals.net
irc.xtasy-chat.net
irc.zurna.net
irc.unerror.com
irc.quicknet.nl
irc.overdriveirc.net
irc.rezosup.org
irc.sorcery.net
irc.spacetronix.net
irc.spidernet.org
irc.staff-chat.net
irc.starchat.net
irc.starfusion.org
irc.starlink.org
irc.stormdancing.net
irc.tevhid.net
topircnet.com
irc.uaap.net
irc.underz.org
irc.virtualife.com.br
irc.voila.fr
irc.zirc.org
irc.tehnicom.net
(might have missed a few)
It seems that per-network it has coded some specific channels to join/herass, but I don't have time to analyze that atm ;)... I can say it has a HUGE channellist however (roughly 400) :/.
- Some interresting detail:
Code: Select all
C:\WIN98\Desktop\Lucifer\mymoon\mymoon.vbp
is found in the binary ;) [yes, it's VB]
- It downloads the ms winsock .ocx from several sites if needed
- It kills antivirus software
- It seems it can spread via mail too
- It acts as a HTTP server for a site with a lot of cracks/keygens/etc... I'm not sure about the port number in the http://ip:port/ thing... It doesn't look consistent, but I don't know how random it is.
- There are several sentences, with a quick look I think there are like 40 or 50
- The nick seems to be composed of a list of 142 names of which 2 are concated together (eg: frostMenon, butlerLesbos), it seems to use 1 name in ident (eg: Lesbos) and there could be a pattern in here.
Anyway, this was my analysis after ~20m, but I'm really tired now... I haven't even looked at traffic analysis or pretty much anything...
I'll look more into it tomorrow and most likely I'll have a rule (or rules, or whatever) ready to catch this nasty thing :)