Home > ParetoLogic Blogs > Malware Diaries > YouTube typo delivers IRC Bot
Reply
 
Thread Tools Display Modes
  #1  
Old 06-25-2009, 12:22 AM
Michael Michael is offline
Administrator
Join Date: May 2007
Posts: 313
Default YouTube typo delivers IRC Bot

UPDATE:

The file is compressed with professional software (Armadillo) making the unpacking process almost impossible.

peid

Once executed, the file uses some in-memory protection by running these two processes.

process

--------

Fresh from our HoneyPot we discovered a malware site using a typo in its domain name.

The site youtorube.com will push a fake video codec, on what appears to be a YouTube page (in Italian).

youtorube2

The domain is registered to:

you2

Pretty soon after running the fake codec, I observed IRC traffic with the same IP address:

youtorube3

This lets me know that I am part of an IRC channel:

youtorube4

The IRC server's IP (87.98.184.231) has some interesting connections, including a "p0nwed.de" domain. Hmm... ;-)

youtorube5

I attempted to connect to that IRC channel manually, however the channel requires a key... In other words, I am not welcome.

youtorube6

Further analysis of the malware binary may reveal the channel's key hard-coded.

The file itself is detected as:

youtorube7

Our Heuristic engine already detected it as:

zheng

However, at that point I have aggregated enough data to determine that this 'codec' actually turns your machine into a Bot, which is not a good thing.

Jerome Segura

Malware ID: f028c315649b7319e8ef2cc22dc67690.zip
Reply With Quote
Reply

« Previous Thread | Next Thread »

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump


Terms of Use