Re: Worm1800.exe on UnderNet?

From: Alex Lambert (alambertat_private)
Date: Thu Jun 20 2002 - 13:30:31 PDT

  • Next message: Jean-Luc: "Re: Worm1800.exe on UnderNet?"

    This file is more than likely malicious. It's extremely common to see spoof
    nohack sites. The majority of "fixes" that I have seen are copies of the
    Litmus trojan.
    
    This apperas to be the same kiddiot "hook" (saying you're infected), and
    just a different piece of malware.
    
    Some interesting strings:
    
    .%windowsfonts%\fonts\bah\this\is\too\easy\hah\
    %appfolder%\PR.ini
    %appfolder%\MIRC3.INI
    %appfolder%\GATES.TXT
    %appfolder%\TEMP.SCR
    %appfolder%\mirc2.ini
    %appfolder%\WHVLXD.DAT
    %appfolder%\WHVLXD.EXE
    %appfolder%\infonet.mrc
    %appfolder%\moo.dll
    %appfolder%\scan.txt
    %appfolder%\cisco.ini
    %appfolder%\sysinfo.mrc
    %appfolder%\remote.ini
    %appfolder%\TEMP.exe
    %appfolder%\mirc.ini
    %appfolder%\infonet2.ini
    %appfolder%\temp2.exe
    %appfolder%\spam.mrc
    %appfolder%\temp.exe
    %appfolder%
    
    
    
    apl
    ----- Original Message -----
    From: "cw" <cwat_private>
    To: <incidentsat_private>
    Sent: Thursday, June 20, 2002 2:26 PM
    Subject: Worm1800.exe on UnderNet?
    
    
    Hi there folks,
    Twice in the past hour I have been messaged by two separate people on
    UnderNet.
    
    The message goes:
    :!Notice!: A Recent Port Scan on your Computer reveals that Port 1800
    is in open state. This usually means that you have been infected with
    an IRC Worm Virus. Please download the cleaner at:
    http://www.No-Hack.Us/Fixes/Worm1800.exe to remove the virus from
    your system. If you do not comply with this rule within 30 minutes,
    our client monitor will ban you from this network. -Thanks For
    Understanding. UNDERNet Exploit Team
    
    The nicks have both been Under-XXX (where XXX is a different set of
    numbers).
    
    For one, I know that port 1800 is not open however the file
    Worm1800.exe does not show up anything when scanned.
    
    Both of the users that messaged me were on pacbell.net adsl
    
    The domain no-hack.us was only registered 6 days ago.
    
    I don't have the spare time or computer to have a further look into
    what this file actually does, has anyone come across this yet and
    know what it does or is anyone willing to investigate?
    --
    O- cw, cwat_private on 20/06/2002
    "Part man, part monkey. Baby that's me"
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management
    and tracking system please see: http://aris.securityfocus.com
    
    
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Thu Jun 20 2002 - 14:11:20 PDT