Security Incidents mailing list archives
New IRC Worm?
From: Mister Coffee <live4java () stormcenter net>
Date: Tue, 25 May 2004 11:31:11 -0700
Good day, I'm an admin on a small IRC network and take a personal interest in dealing with all the various worms that seem to cruise by. Recently, we've seen a spate of connections where a "user" signs in, jumps into a channel and spews "http://<client IP>/<random>.exe" then channel hops. Usually repeated several times before it either disconnects or is killed by an oper. Relatively typical bot behavior. I was able to download the virus to a *NIX box for posterity. Strings output caught the somewhat odd "tate()dextromethorphan" in the body. Evidently this is a drug found in cough medicine and subject to abuse? In any case, I was curious to know if anyone else had seen this. File size is 45568 and I can make it available if someone wants to examine it. I suspect an ago/gao/phat/etc/bot variant but figured I'd ask before deconstructing. TIA Cheers, L4J
Current thread:
- New IRC Worm? Mister Coffee (May 25)
- Re: New IRC Worm? Gadi Evron (May 26)