F-Secure Virus Descriptions : NewsFlood
|
|
|
| NAME: | NewsFlood |
| ALIAS: | Win32/NewsFlood.7168.A, Trojan.Win32.NewsFlood |
Newsflood is a trojan with the purpose of posting vast amount of
messages to certain usenet groups.
It is 7 kilobytes in size (28 uncompressed).
When executed it starts to post messages in an endless loop using
'news.hispeed.ch' as newsserver. It has functionality for
supplying username and password combination on the server but
that feature is not used. It is also capable of encoding itself
in uuencode format that might be used to send the trojan along
with the other messages. Fortunately this is also disabled. When
communicating with the news server all the events are logged to a
logfile called 'Starorbita.txt' in the same directory where the
trojan is located.
The targeted newsgroups:
'news.admin.net-abuse.usenet'
'alt.binaries.nospam.teenfem.nonude'
'alt.2600'
'alt.binaries.pictures.erotica.male'
'alt.religion.scientology'
'alt.comp.virus'
'alt.hackers.malicious'
'alt.religion.christian'
'alt.politics.bush'
'alt.binaries.pictures.asparagus'
Each message is posted to two randomly chosen groups (sometimes
to the same group twice).
The random meassages are created from the following components:
Sender adresses in the form 'jdavis@aol.com (Jack Davis)' using
First names:
'Neil Jack Frank Randy Keith Rick Timothy Mark Charlie Mike
Gordon Joe Habib George Albert Herbert Roosevelt David
Carl Nicholas Peter Shaniqua'
Last names:
'Black Rogers White Colt Smith Elm Bell Ash Walton Davis
Carter Wilson Andrews Chung Elliott Harvey Brown Williams
Todd Sawyer Jones Axelrod'
Domains:
'scientology.org'
'elsitio.com'
'EnlargeYourPenisToday.Com'
'netexplora.com'
'google.com'
'my-deja.com'
'yahoo.com'
'hotmail.com'
'aol.com'
'fed.rr.com'
'mailman.lanl.gov'
'nuddie.com'
'baldpussy.org'
'hairless.net'
'fuck-a-preteen.com'
'postmans0.tripod.com'
'fenvhs.org'
'pteens.net'
'nohairboys.com'
'nohairgirls.com'
'preteen-paradise.net'
'buddingtittys.com'
'tenyearolds.net'
'allvirgins.com'
'little-virgins.com'
Organization field:
'Martiza Internet Services'
'Disorganized'
'Amigo Org.'
'Wakkina Software'
'Executive Orifice of the President'
'The Christian Coalition'
'little or none at all'
'FBI-CIA-NSA-DOJ-MI5-AOL-TimeWarner, Inc.'
'Lbh unir gbb zhpu shpxvat serr gvzr'
'wHipcreme'
'Iggerbay Enispay'
' '
Subject line is constructed from:
'12-15 yo. girls on nuddie webcam'
'13 y.o. webcam girls (nuddie) '
'12 - 13 yrs_old teen models UPDATED SITE'
'12yo ICQ girls'
'13 yo. webcam girls (1/1)'
'pteen chat grls (11-12yrs)'
'10 yr/old babydoll tittys'
'NEW URL 12 yr. old Michelle 1/1'
'10yrs. P-teen G1RLS? here:'
'Girls of 13-16'
'14 yo_webcam girls'
'15 yo. lolitas room'
'13 y/o ICQ girl'
'14yo daughter, nude asleep pics'
'Cindy 15 yrs_old'
A random string is appended to the subject line (up to 30
characters).
The trojan also adds the 'X-No-Archive: Yes' field to the header.
Message body contains a randomly chosen advertisment like this:
'take a look
http://xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx/
babydolls chatting nudy on IRC, mirc, dalnet'
followed by a fake random file name ('*.jpg') and a fake error
message:
'Error: Specified file not found to attach!'
A couple of empty lines and random characters (up to 250) are
closing the message.
An example of the possible messages:
From: CRogers@my-deja.com (Charlie Rogers)
Subject: Girls of 13-16 y
Newsgroups: alt.comp.virus,alt.comp.virus
X-No-Archive: Yes
Organization:
NNTP-Posting-Host: 127.0.0.1
Message-ID: <3b065ceb$1@user.>
Date: 19 May 2001 14:45:47 +0300
X-Trace: user. 990272747 127.0.0.1 (19 May 2001 14:45:47 +0300)
Lines: 28
Path: user.
Xref: user alt.comp.virus:3
young, babyface adolescents
http://www.computer2030.com/miembro/schoolpervs
free previews
now improved new site !! view of pthc xxx FREE !Y.jpg
Error: Specified file not found to attach!
It does not do anything to hide it's activity. Once it is started
it runs until the next reboot.
[Analysis: Gergely Erdelyi, F-Secure Corp.; June 2001]
|