Security Incidents mailing list archives

New IRC Worm?


From: Mister Coffee <live4java () stormcenter net>
Date: Tue, 25 May 2004 11:31:11 -0700

Good day,

I'm an admin on a small IRC network and take a personal interest in dealing with all the various worms that seem to 
cruise by.  Recently, we've seen a spate of connections where a "user" signs in, jumps into a channel and spews 
"http://<client IP>/<random>.exe" then channel hops.  Usually repeated several times before it either disconnects or is 
killed by an oper.

Relatively typical bot behavior.  I was able to download the virus to a *NIX box for posterity.  Strings output caught 
the somewhat odd "tate()dextromethorphan" in the body.  Evidently this is a drug found in cough medicine and subject to 
abuse?

In any case, I was curious to know if anyone else had seen this.  File size is 45568 and I can make it available if 
someone wants to examine it.  I suspect an ago/gao/phat/etc/bot variant but figured I'd ask before deconstructing.

TIA

Cheers,
L4J


Current thread: