ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

Parasitic IRCBot in the wild

highMalwareimportance 42
Full article371 words · extracted from securelist.com · click to collapse

Malware descriptions

Malware descriptions

10 May 2006

minute read

Statistics show that the contemporary malware landscape is, in the main, somehow connected with Trojans: Backdoors, Trojan-Downloaders, Trojan-Droppers, etc.

Although we are still seeing the same kind of viruses as we were seeing 10 years ago, written by cyber hooligans, every now and then we find old style methods being incorporated into more serious malware.

Almost a year ago we wrote about Tenga, a classic file infector with worm and trojan-downloader functionality.

Recently we added detection for something similar: Virus.Win32.Virut.4960. While its name doesn’t sound very interesting, or pretty for that matter, this is quite an interesting sample.

Like Tenga, Virut.4960 is a classic appending virus. This file infector infects .exe and .scr files by attaching its (encrypted) code.

The interesting part is that the encrypted code contains IRCBot functionality. When an infected sample is executed it tries to connect to a certain IRC server.

The IRCBot functionality is very limited, and simply downloads a file of the attacker’s choice. However, even such restricted functionality is enough to introduce more malware onto the victim system.

Using this kind of attack has some clear advantages; most significantly, that only virus scanners will be capable of detecting it. So malware which uses such strategies will be able to bypass, for example, anti-spyware solutions, which don’t have an antivirus engine, and therefore can’t detect and disinfect virus infected files.

Although the use of file infecting techniques still isn’t particularly common, it’s an interesting trend, which will continue evolving – because dedicated antispyware solutions will be unable to combat such threats.

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/parasitic-ircbot-in-the-wild/30164/