Content

IRC-Itlebot

Type
Trojan
SubType
Internet Relay Chat
Discovery Date
08/06/2005
Length
44,834 bytes (dropper) 14,876 bytes
Minimum DAT
4552 (08/08/2005)
Updated DAT
4562 (08/18/2005)
Minimum Engine
5.1.00
Description Added
08/06/2005
Description Modified
08/06/2005 2:55 PM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

This IRC Bot trojan was mass-spammed on August 6, 2005 attached to a message as follows:

From: noreply@ukcards.com
Subject: Transaction Receipt (UKCards)
Body:

Please note: All charges to your statement
will appear in the name "UKCARDS LIMITED".

Order Information
Amount: =A3399.95
Currency: GBP
Merchant Name: HUNTINGDON MAIL ORDER
Description: iPod Music Player 40GB

Customer Service
Telephone: 0845 6060 234
Email: N/A

Delivery Address
47 Silver Street, London, NW1 5TR

You can download your purchase agreement here, please keep this
safe as it is your only means to cancel the order before the expected
delivery date.

Attachment: iPod Purchase Agreement.zip (containing ipod purchase agreement.scr )
MD5 of ZIP file: 4f1e3192e564d74418f2ee82b97d70ae
MD5 of SCR file: aaa4744f2d6d8a51613b883e3bf0d814

The purpose of this trojan is to connect to a remote IRC server and wait for instructions to download and execute another file.

Symptoms

When run, a trojan dropper, creates a file begonia.exe in the WINDOWS SYSTEM directory and creates a registry run key to load itself at system startup, such as:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
    Run "Litebot" = C:\WINDOWS\System32\begonia.exe

The trojan attempts to connect to the IRC server sluts.skene.net or irc.skene.net on TCP port 6667.

Method of Infection

This trojan may be proactively detected as New Malware.n with the released DAT files when scanning with program heuristics enable via server and on-demand scanners.  The IRC traffic related with this threat is blocked by default Access Protection rules with the VirusScan 8.0i product.

This trojan was seeded via a mass-spamming.  Unlike viruses, trojans do not self-replicate.

Removal

Detection is included in our BETA DAT files and will also be included in the next scheduled DAT release. In addition to the DAT version requirements for detection, the specified engine version (or greater) must also be used.

Additional Windows ME/XP removal considerations

Variants

Variants

    N/A

All Information

Overview -

This is a trojan detection. Unlike viruses, trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.

Aliases

  • LiteBot

Characteristics

Characteristics -

This IRC Bot trojan was mass-spammed on August 6, 2005 attached to a message as follows:

From: noreply@ukcards.com
Subject: Transaction Receipt (UKCards)
Body:

Please note: All charges to your statement
will appear in the name "UKCARDS LIMITED".

Order Information
Amount: =A3399.95
Currency: GBP
Merchant Name: HUNTINGDON MAIL ORDER
Description: iPod Music Player 40GB

Customer Service
Telephone: 0845 6060 234
Email: N/A

Delivery Address
47 Silver Street, London, NW1 5TR

You can download your purchase agreement here, please keep this
safe as it is your only means to cancel the order before the expected
delivery date.

Attachment: iPod Purchase Agreement.zip (containing ipod purchase agreement.scr )
MD5 of ZIP file: 4f1e3192e564d74418f2ee82b97d70ae
MD5 of SCR file: aaa4744f2d6d8a51613b883e3bf0d814

The purpose of this trojan is to connect to a remote IRC server and wait for instructions to download and execute another file.

Symptoms

Symptoms -

When run, a trojan dropper, creates a file begonia.exe in the WINDOWS SYSTEM directory and creates a registry run key to load itself at system startup, such as:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
    Run "Litebot" = C:\WINDOWS\System32\begonia.exe

The trojan attempts to connect to the IRC server sluts.skene.net or irc.skene.net on TCP port 6667.

Method of Infection

Method of Infection -

This trojan may be proactively detected as New Malware.n with the released DAT files when scanning with program heuristics enable via server and on-demand scanners.  The IRC traffic related with this threat is blocked by default Access Protection rules with the VirusScan 8.0i product.

This trojan was seeded via a mass-spamming.  Unlike viruses, trojans do not self-replicate.

Removal -

Removal -

Detection is included in our BETA DAT files and will also be included in the next scheduled DAT release. In addition to the DAT version requirements for detection, the specified engine version (or greater) must also be used.

Additional Windows ME/XP removal considerations

Variants

Variants -

    N/A