Forums: Sexy.exe - Forums

Jump to content

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Sexy.exe whats it?

#16 Guest_sk3tch_*

  • Group: Guests

Posted 16 March 2005 - 07:24 AM

I find a ton of these...is there interest in the forum if I post the botnet's IRC server address/port and the malware? You guys can go from there....
0

#17 User is offline   Chris 

  • Specialist
  • Icon
  • Group: Specialist
  • Posts: 1,202
  • Joined: 31-August 03

Posted 16 March 2005 - 10:38 AM

They will be good for practice, the only one thing is that FBI hostname freaks me out, im sure its fake but it still scares me lol :ph34r:

EDIT: Sat there using a SOCKS proxy atm, see if I can get a password then type $remove, should be funny!

I have enclosed an nmap log in case my idea dont work, seems they are using the BNCs to hide their IP, does anyone want to tell them it shuld be on a different server with no ties to them whatsoever or shall I?

EDIT EDIT:

They are changing the server, maybe we have pissed them off, new one is at:

WARNING THIS IS A VIRUS! POSTED FOR RESEARCH ONLY

hxxp://www.freewebtown.com/sexygirl1/sexy.exe

Not detected by AVG, can't see what its packed with (if its packed, maybe its not). I will have to fire up my test box tommorow to find data).

WARNING THIS IS A VIRUS! POSTED FOR RESEARCH ONLY

Will tell you the new server / channel / password asap



The zip file attached is the log not the virus.

http://65.110.55.15%20:10000/ webmin

Attached File(s)

  • Attached File  log.zip (1.58K)
    Number of downloads: 21

0

#18 Guest_sk3tch_*

  • Group: Guests

Posted 16 March 2005 - 11:48 AM

chris105, on Mar 16 2005, 06:38 PM, said:

They will be good for practice, the only one thing is that FBI hostname freaks me out, im sure its fake but it still scares me lol  :ph34r:


Yup...it has done it's purpose then. I am about 99% certain it is fake since *many* of them feature such things. FBI, CIA, Microsoft, everything. I've even seen ones where they say "this is a honeypot, there is no hacker on this server"...pretty funny. Anything to keep prying eyes away from their precious bots. B)
0

#19 User is offline   ash^ 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 72
  • Joined: 02-October 04

Posted 16 March 2005 - 02:06 PM

chris105, on Mar 16 2005, 06:38 PM, said:

EDIT: Sat there using a SOCKS proxy atm, see if I can get a password then type $remove, should be funny!


Problem:
the bot has probs got a hostauth set so only the bot owner can login to the bots and do commands

the chans modes are +u so you not be able to see other bots in the channels.

sexy.exe
Is a self extracting file so right click and choose extract to /sexy ( if you have winrar )


:ph34r:
0

#20 Guest_sk3tch_*

  • Group: Guests

Posted 16 March 2005 - 02:36 PM

Nice find chris105!

Tons of fun stuff in that archive -

Kaspersky Anti-Virus On-Demand Scanner for Linux. Version 5.0.5/RELEASE build #13, compiled Nov 29 2004, 16:50:29
Copyright (C) Kaspersky Lab, 1997-2004.
There are 115061 records loaded, the latest update 16-03-2005
Config file: /etc/kav/5.0/kav4unix.conf
sexy.exe Archive CAB
sexy.exe/090-ntpass.xpn Packed UPX
sexy.exe/090-ntpass.xpn OK
sexy.exe/090-ntpass.xpn OK
sexy.exe/calcu.exe Packed UPX
sexy.exe/calcu.exe OK
sexy.exe/calcu.exe OK
sexy.exe/config.ini OK
sexy.exe/cs INFECTED Net-Worm.Win32.Randon
sexy.exe/demo.xt OK
sexy.exe/dir32.exe Packed Cexe
sexy.exe/dir32.exe Archive MS Expand
sexy.exe/dir32.exe/dir32.exe OK
sexy.exe/dir32.exe OK
sexy.exe/dir32.exe OK
sexy.exe/dirote.exe Packed UPX
sexy.exe/dirote.exe OK
sexy.exe/dirote.exe OK
sexy.exe/dorod.exe Packed Cexe
sexy.exe/dorod.exe Archive MS Expand
sexy.exe/dorod.exe/dorod.exe INFECTED Backdoor.Win32.HacDef.084
sexy.exe/dorod.ini OK
sexy.exe/easy_user.dic OK
sexy.exe/emoti.bat INFECTED Trojan.BAT.Passer.a
sexy.exe/kltye.exe Packed UPX
sexy.exe/kltye.exe OK
sexy.exe/kltye.exe OK
sexy.exe/kolder.exe Packed UPX
sexy.exe/kolder.exe OK
sexy.exe/kolder.exe OK
sexy.exe/language.ini OK
sexy.exe/niamx INFECTED Net-Worm.Win32.Randon
sexy.exe/nt_pass.dic OK
sexy.exe/nt_user.dic OK
sexy.exe/os.finger OK
sexy.exe/port.ini OK
sexy.exe/redroses INFECTED Net-Worm.Win32.Randon
sexy.exe/riqa OK
sexy.exe/roudSTID.EXE Packed UPX
sexy.exe/roudSTID.EXE OK
sexy.exe/roudSTID.EXE OK
sexy.exe/rpc.ini OK
sexy.exe/van32.exe Packed FSG
sexy.exe/van32.exe OK
sexy.exe/van32.exe OK
sexy.exe/X-ScanCfg.ini OK

0

#21 User is offline   tibbar 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 1,423
  • Joined: 14-October 03

Posted 16 March 2005 - 03:42 PM

it's still alive:

:234051:. *** Looking up your hostname...
.:234110:. *** Found your hostname
[%] ?Connected?
.:234110:. (%) ?Connected to CASH.NICK.FBI.GOV?
.:234110:. (%) Welcome to the FBI IRC Network Hax0r!tibret@serifos.eecs.harvard.edu
.:234110:. (%) Your host is CASH.NICK.FBI.GOV, running version Unreal3.2.2
.:234110:. (%) This server was created Sun Dec 19 2004 at 11:35:47 EST
.:234110:. (%) CASH.NICK.FBI.GOV Unreal3.2.2 iowghraAsORTVSxNCWqBzvdHtGp lvhopsmntikrRcaqOALQbSeKVfMGCuzNT
.:234110:. (%) CMDS=KNOCK,MAP,DCCALLOW,USERIP SAFELIST HCN MAXCHANNELS=10 CHANLIMIT=#:10 MAXLIST=b:60,e:60 NICKLEN=30 CHANNELLEN=32 TOPICLEN=307 KICKLEN=307 AWAYLEN=307 MAXTARGETS=20 WALLCHOPS are supported by this server
.:234110:. (%) WATCH=128 SILENCE=15 MODES=12 CHANTYPES=# PREFIX=(ohv)@%+ CHANMODES=beqa,kfL,l,psmntirRcOAQKVGCuzNSMT NETWORK=FBI CASEMAPPING=ascii EXTBAN=~,cqnr ELIST=MNUCT STATUSMSG=@%+ EXCEPTS are supported by this server
.:234110:. There are 1 users and 478 invisible on 1 servers
.:234110:. 2 operator(s) online
.:234110:. 14 channels formed
.:234110:. I have 479 clients and 0 servers
.:234110:. Current Local Users: 479 Max: 952
.:234110:. Current Global Users: 479 Max: 952
.:234110:. [%] - CASH.NICK.FBI.GOV Message of the Day -
.:234110:. - 3/11/2004 9:35


There are two channels i can see:

%] Now talking in [#rx-mp]
[%] Topic is '.advscan dcom135 100 3 999 217.83.x.x -r'
(pwd 6677)

and:

[%] Now talking in [#rx-talal]
[%] Topic is '$advscan lsass_445 100 5 0 -b -r'
[%] Set by [TaLaL`] on Wednesday, March 16th, 2005 at 9:24pm

I'm guessing TaLal` is the other op on the botnet

Hehe: .:235247:. Closing Link: TaLaL`[serifos.eecs.harvard.edu] (User has been permanently banned from FBI (no reason))
If you want to read more about my security research, visit Tibbar.org
0

#22 User is offline   ash^ 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 72
  • Joined: 02-October 04

Posted 17 March 2005 - 12:14 AM

Ive just connected to the server again tried having a play around the default chan modes are +mnstu so i dont think any of us are going to get very far.
0

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting