This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

"Nugache" Worm/Bot using P2P control channel

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.websensesecuritylabs.com/alerts…php?AlertID=478
5/1/2006
"Websense® Security Labs ™ has received several reports of a new worm, "Nugache", which is spreading on AOL/MSN Instant Messenger networks and as an e-mail attachment by exploiting several workstation vulnerabilities. The worm opens a back door on TCP port 8, and installs a bot to wait for commands from the attacker. The command & control channel that is used is unique, as the bot appears to connect to infected peers instead of a static list. A peer-to-peer command & control channel makes it more difficult to block commands issued to the bot. The traffic over this channel also uses obfuscation in an attempt to bypass intrusion detection systems."

>>> http://securityresponse.symantec.com/[removed]


:ph34r:
Additional info:

- http://www.sarc.com/avcenter/venc/data/[removed]
Last Updated on: May 02, 2006
"…# Attempts to connect to a predetermined IRC server, open a back door, and wait for commands from an attacker. The back door allows the attacker to do the following:
* Perform a denial of service attack
* Access an FTP server
* Run as Web server
# Spreads thorough AOL Instant Messenger, AOL mail and Windows Messenger…
* Attachment:
One of following:
* attachment
* documents
* backup
* forwarded
* details
>>> The attachment has an .scr or .scp .scq .scr extension.
# The worm spreads to unpatched computers by exploiting the following vulnerabilities:
* The Microsoft ASN.1 Library Multiple Stack-Based Buffer Overflow Vulnerabilities (as described in Microsoft Security Bulletin MS04-007)
* The Microsoft Windows LSASS Buffer Overrun Vulnerabilities (as described in Microsoft Security Bulletin MS04-011)
# Attempts to repack itself before spreading…"

:ph34r:
FYI…

- http://www.securityfocus.com/news/11390
2006-05-02
"…The techniques represent the latest improvements for bots–the tools of choice for many online criminals aiming to turn compromised computers into cash. Typically, the programs allow a bot master to control a large network of infected systems–or bot net–by sending commands through an Internet relay chat (IRC) system, the still extant precursors to the major IM networks. This latest variant of bot software shows that–threatened by investigators' ability to tap into command-and-control networks built on top of Internet relay chat–bot masters are looking to peer-to-peer communications, encryption and other technologies to hide their tracks…"

:(