« The Ukrainian connection
Fake Porntube Malware »

YouTube typo delivers IRC Bot

June 24th, 2009

UPDATE:

The file is compressed with professional software (Armadillo) making the unpacking process almost impossible.

peid

Once executed, the file uses some in-memory protection by running these two processes.

process

——–

Fresh from our HoneyPot we discovered a malware site using a typo in its domain name.

The site youtorube.com will push a fake video codec, on what appears to be a YouTube page (in Italian).

youtorube2

The domain is registered to:

you2

Pretty soon after running the fake codec, I observed IRC traffic with the same IP address:

youtorube3

This lets me know that I am part of an IRC channel:

youtorube4

The IRC server’s IP (87.98.184.231) has some interesting connections, including a “p0nwed.de” domain. Hmm… ;-)

youtorube5

I attempted to connect to that IRC channel manually, however the channel requires a key… In other words, I am not welcome.

youtorube6

Further analysis of the malware binary may reveal the channel’s key hard-coded.

The file itself is detected as:

youtorube7

Our Heuristic engine already detected it as:

zheng

However, at that point I have aggregated enough data to determine that this ‘codec’ actually turns your machine into a Bot, which is not a good thing.

Jerome Segura

Malware ID: f028c315649b7319e8ef2cc22dc67690.zip

    This entry was posted on Wednesday, June 24th, 2009 at 3:22 pm and is filed under Research. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • Infected with Koobface?
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (32)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (14)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (103)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.