Re: Suspicious JOe.exe

From: Tony Lambiris (methodicat_private)
Date: Fri Aug 03 2001 - 12:35:34 PDT

  • Next message: JKlemencat_private: "Code Red Infecting HP JetDirect - Not Exactly"

    I've youve got a spare machine kicking around, install NT on it, then
    tcpdump the LAN traffic and you should be able to snake the key that
    way.. it should work through VMware as well..
    
    On 08.03.01, OblivionOat_private wrote:
    > I ran a hex editor on a copy of Joe.exe that was sent to me and although i 
    > found most of the same information as the strings command, i was unable to 
    > find the request of invite. Upon entering the iRC network that joe.exe is 
    > connecting to i tried to enter channel "#penr0x". It is invite only, whcih 
    > leads me to believe that when the zombie connects to irc it sends a request 
    > to a bot or botnetwork with a specific phrase, ordering the botnet to invite 
    > it to #penr0x.... My question is where would this phrase/nick be located in 
    > the file? i cant seem to find it although it seems to me that it should be in 
    > plain text...
    > 
    >  ~ Chris
    



    This archive was generated by hypermail 2b30 : Fri Aug 03 2001 - 12:49:57 PDT