Infection Channel: Downloaded from the Internet
This malware is believed to be the bot used by a hacking group that perpetrated attacks against Brazilian websites.
To get a one-glance comprehensive view of the behavior of this Backdoor, refer to the Threat Diagram shown below.

This backdoor may be downloaded by other malware/grayware/spyware from remote sites. It may be unknowingly downloaded by a user while visiting malicious websites.
It connects to Internet Relay Chat (IRC) servers. It executes commands from a remote malicious user, effectively compromising the affected system.
File size: 110,592 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 23 Jun 2011
Payload: Connects to URLs/IPs, Compromises system security, Drops files
Arrival Details
This backdoor may be downloaded by other malware/grayware/spyware from remote sites.
It may be unknowingly downloaded by a user while visiting malicious websites.
Installation
This backdoor drops the following copies of itself into the affected system:
- %System%\svchosth.exe or %System%\svchosta.exe or %System%\svchostzx.exe or %System%\svchoste.exe
(Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
Autostart Technique
This backdoor adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
svchostn.exe = ""%System%\{malware file name}" start4dalife"
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
svchostn.exe = ""%System%\{malware name}" start4alife""
Backdoor Routine
This backdoor opens the following ports:
It connects to any of the following Internet Relay Chat (IRC) servers:
- irc.{BLOCKED}.li
- irc.{BLOCKED}.net
It joins any of the following IRC channel(s):
It executes the following commands from a remote malicious user:
- attack - perform Denial of Service (DOS) attack to target site/IP
- stop - stop Denial of Service (DOS) attack
- stopall - stop Denial of Service (DOS) attack and terminate itself
- update - update copy of itself
- info - gather and send the following information to the server:
- IP Address
- Machine Name
- Domain
- Username
- Operating System
- Working Set
- Common Language Runtime (CLR) Version
- status - display status of current attack being performed by the bot
- getkl - gather and send keystroked informtion to the server
NOTES:
It saves the downloaded updated copy of itself as:
It connects to the following URL(s) to get the affected system's external IP address:
It uses any of the following IRC nick(s):
It uses any of the following IRC password(s):
Connect with us on
| | | |