CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[WsIRT#195] IRC Bot Shell @AS8342

 
Post new topic   Reply to topic       All -> FavForums -> WsIRT Reports [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Sat Dec 01, 2007 1:38 am    Post subject: [WsIRT#195] IRC Bot Shell @AS8342
Reply with quote

Attack Alert
 
 Full Report: CastleCops Link/IRC_Bot_Shell_attack195.html
 
 Changed status to .


IP Converted: 195.161.119.84

dword = 3282138964
hex1 = 0xc3a17754
hex2 = 0xc3.0xa1.0x77.0x54
oct = 0303.0241.0167.0124

Attackers are attempting to inject this script into vulnerable remote web servers. Once it is successfully installed illegally onto a web server, it attempts an fsockopen connection to one of the following destinations on port 8080:

sunnyplaces.weedns.com
mymusicplace.weedns.com
dns4.bpa.nu
dns3.bpa.nu
dns2.bpa.nu
dns1.bpa.nu
snes.dnip.ne
snes.opendns.be
nses1.dd.blueline.be
xamyx.dnip.net

At which point it randomly generates a user and a nick for what appears to be an IRC-like connection. A real sample is shown once it has logged in:

"MODE cafkassps -x i"
"JOIN ##p md5hash"
"NICK cafkassps"

One of its responses include:
"NOTICE :VERSION mIRC 6.26 BY Khaled Mardam-Bay"

This script is setup for the attacker to read in commands such as:

ls, cmd, pwd, chown, chmod, get, rm, cd, touch, cat, symlink, uname, opme

et cetera.

The script attempts to be obfuscated. It is nefarious in nature and should be removed immediately. All evidence surrounding the installation of the script should be preserved and sent to law enforcement referencing this ticket.


View CIDR AS8342 Report: http://www.cidr-report.org/cgi-bin/as-report?as=8342

"8342 | RU | ripencc | 1997-06-11 | RTCOMM-AS RTComm.RU Autonomous System"<br />

Extended information for AS8342:
State/Province:
Country: ru
Responsible Domain: rtcomm.ru
Abuse Email: security@rtcomm.ru

Changed status to confirmed attack.
Quote:
http://hotraebywka.chat.ru/images/girl?

Back to top
View users profile Send private message Send email Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> WsIRT Reports All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer