This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Careful with Christmas.exe - IRCBot variant

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Geez. Will it ever stop… 'guess not:

- http://www.f-secure.com/weblog/archives/ar…6.html#00001057
December 23, 2006
"We've just received a sample of something that's called CHRISTMAS.EXE. When run, this IRCBot variant will try to download various malicious executables from web servers at waiguadown.008.net and user.free.77169.net. As a decoy, it shows this Christmas-themed image… Obviously, a gift that keeps on giving. To be avoided."

(Screenshot at URL above.)

- http://isc.sans.org/diary.php?storyid=1968
Last Updated: 2006-12-23 21:11:30 UTC

:ph34r:
FYI…

More Christmas-themed malware
- http://www.f-secure.com/weblog/index.html#00001058
December 24, 2006
"Unfortunately there seems to be more Christmas-related malware floating around. Now there's a backdoor called Christmas_Puzzle.exe. This one uses a rootkit to hide it's presence on a system. We detect it as Trojan-Spy.Win32.Ardamax.e. As a decoy, this one shows a Christmas-themed jigsaw puzzle game on screen. And then there's a Powerpoint file called Christmas+Blessing-4.ppt. This one uses MS06-012 or a related vulnerability to drop and execute two embedded programs. As a decoy, the exploit has been embedded in an innocent Christmas-themed PPT slideshow that has been making rounds previously…"

(Screenshot at URL above.)

- http://isc.sans.org/diary.php?storyid=1970
Last Updated: 2006-12-24 08:21:00 UTC
"…Reliance on anti-virus software should -not- be too high. The powerpoint file above was detected badly at the time we got our copy of it…"

:ph34r: