Answers to your tech questions
Computer forums for help with removing malicious software (malware) and improving computer security

Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)

      
 
Reply to this topicStart new topic
> Linux, FreeBSD and Mac (!) bot
AplusWebMaster
post Feb 28 2008, 05:46 AM
Post #1


AplusWebMaster
*****

Group: Authentic Member
Posts: 3,667
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: WinXP



FYI...

- http://isc.sans.org/diary.html?storyid=4042
Last Updated: 2008-02-28 09:31:30 UTC - "Yesterday I received samples of an IRC bot. This in itself would be nothing interesting except the fact that the archive contained binaries for FreeBSD and Mac (Darwin, ppc). After initial analysis I found out that it's nothing special – just a port of a well known IRC bot called EnergyMech. The most interesting thing was that the attacker compiled it for FreeBSD and Mac. This probably didn't require any extra effort though since it compiles out of the box on FreeBSD and Linux anyway. The bot did all the standard stuff: had couple of "owners" defined; comments in Portuguese and connected to Undernet, the IRC network that a lot of attackers like. I decided, for the fun of it, to run the sample through VirusTotal, just to see what results AV programs will have. It was .. erm.. interesting, as you will see below. There were in total 3 files:
$ md5sum linux freebsd darwin
fbab7e9bf1780fd2bc99e44d46535be5 linux
17eb3a901811ea86f7d71394cde36202 freebsd
a93b41466e330fc3cf8e6602e5cd03c2 darwin
The FreeBSD version of the bot was detected by 23 out of 32 AV programs (decent) and the Linux one by 24 out of 32 AV programs (even better). This was clearly signature detection since almost all AV programs detected the FreeBSD version as something for Linux (Linux/RST.B ) – my guess is that they trigger on some text in the binary. Finally, the Darwin version was a bit of a shock – 0 detections in total (!). Since it was a Mach-O executable for PPC, my guess is that AV programs didn't know how to parse the file format and just thought of it as data."

ph34r.gif

This post has been edited by AplusWebMaster: Feb 28 2008, 11:45 AM
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

Collapse

> Similar Topics

    Topic Title Replies Topic Starter Views Last Action
No New Posts  
1 PaPa-Smurf 74 30th September 2008 - 08:51 PM
Last post by: Ztruker
No New Posts
1 AplusWebMaster 93 27th August 2008 - 04:27 AM
Last post by: AplusWebMaster
No New Posts  
4 Roberts 1,981 1st July 2008 - 04:05 PM
Last post by: wizzy2k5
No New Posts  
2 theburn7 693 20th February 2008 - 07:13 PM
Last post by: LDDI
No New Posts  
12 notesetter 2,397 19th February 2008 - 07:06 PM
Last post by: LDDI

RSS Time is now: 12th October 2008 - 09:14 AM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy