Home / malwarePDF  

Backdoor:W32/IRCBot.BNS


First posted on 18 July 2007.
Source: SecurityHome

Aliases :

Backdoor:W32/IRCBot.BNS is also known as Backdoor.win32.Rbot.cmx.

Explanation :

IRCBot represents a large family of backdoors - remote access tools used by hackers.

These tools allow for the control of a victim's computer remotely by sending specific commands via IRC channels. Also, these backdoors can steal data and spread to computers vulnerable to exploits.

The backdoor's file is a PE executable about 1.3 megabytes long, packed with Themida file compressor.

When the backdoor's file is started, it copies itself as a file named winupdate.exe to the Windows System folder and then creates the following startup key value in the Registry:


When the backdoor is active, it connects to an IRC server, joins a certain channel, and acts as a bot there.

The following IRC server and ports is used by the backdoor:


The backdoor joins the following password-protected IRC channel:


A hacker can send commands to the bots to control infected computers. Several tasks can be performed, including the following:


When spreading, the bot can exploit the following vulnerabilities:

Last update 18 July 2007

 

TOP

Malware :

Family: