Skip to main content

NewsFlood

Classification

Category:

Malware

Type:

Trojan

Aliases:

  • NewsFlood
  • Win32/NewsFlood.7168.A
  • Trojan.Win32.NewsFlood

Summary

Newsflood is a trojan with the purpose of posting vast amount of messages to certain usenet groups.

It is 7 kilobytes in size (28 uncompressed).

Removal

Technical Details

When executed it starts to post messages in an endless loop using 'news.hispeed.ch' as newsserver. It has functionality for supplying username and password combination on the server but that feature is not used. It is also capable of encoding itself in uuencode format that might be used to send the trojan along with the other messages. Fortunately this is also disabled. When communicating with the news server all the events are logged to a logfile called 'Starorbita.txt' in the same directory where the trojan is located.

The targeted newsgroups:

'news.admin.net-abuse.usenet' 'alt.binaries.nospam.teenfem.nonude' 'alt.2600' 'alt.binaries.pictures.erotica.male' 'alt.religion.scientology' 'alt.comp.virus' 'alt.hackers.malicious' 'alt.religion.christian' 'alt.politics.bush' 'alt.binaries.pictures.asparagus'

Each message is posted to two randomly chosen groups (sometimes to the same group twice).

The random meassages are created from the following components:

Sender adresses in the form 'jdavis@aol.com (Jack Davis)' using

First names:

'Neil Jack Frank Randy Keith Rick Timothy Mark Charlie Mike Gordon Joe Habib George Albert Herbert Roosevelt David Carl Nicholas Peter Shaniqua'

Last names:

'Black Rogers White Colt Smith Elm Bell Ash Walton Davis Carter Wilson Andrews Chung Elliott Harvey Brown Williams Todd Sawyer Jones Axelrod'

Domains:

'scientology.org' 'elsitio.com' 'EnlargeYourPenisToday.Com' 'netexplora.com' 'google.com' 'my-deja.com' 'yahoo.com' 'hotmail.com' 'aol.com' 'fed.rr.com' 'mailman.lanl.gov' 'nuddie.com' 'baldpussy.org' 'hairless.net' 'fuck-a-preteen.com' 'postmans0.tripod.com' 'fenvhs.org' 'pteens.net' 'nohairboys.com' 'nohairgirls.com' 'preteen-paradise.net' 'buddingtittys.com' 'tenyearolds.net' 'allvirgins.com' 'little-virgins.com'

Organization field:

'Martiza Internet Services' 'Disorganized' 'Amigo Org.' 'Wakkina Software' 'Executive Orifice of the President' 'The Christian Coalition' 'little or none at all' 'FBI-CIA-NSA-DOJ-MI5-AOL-TimeWarner, Inc.' 'Lbh unir gbb zhpu shpxvat serr gvzr' 'wHipcreme' 'Iggerbay Enispay' ' '

Subject line is constructed from:

'12-15 yo. girls on nuddie webcam' '13 y.o. webcam girls (nuddie) ' '12 - 13 yrs_old teen models UPDATED SITE' '12yo ICQ girls' '13 yo. webcam girls (1/1)' 'pteen chat grls (11-12yrs)' '10 yr/old babydoll tittys' 'NEW URL 12 yr. old Michelle 1/1' '10yrs. P-teen G1RLS? here:' 'Girls of 13-16' '14 yo_webcam girls' '15 yo. lolitas room' '13 y/o ICQ girl' '14yo daughter, nude asleep pics' 'Cindy 15 yrs_old'

A random string is appended to the subject line (up to 30 characters).

The trojan also adds the 'X-No-Archive: Yes' field to the header.

Message body contains a randomly chosen advertisment like this:

'take a look http://xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx/ babydolls chatting nudy on IRC, mirc, dalnet'

followed by a fake random file name ('*.jpg') and a fake error message:

'Error: Specified file not found to attach!'

A couple of empty lines and random characters (up to 250) are closing the message.

An example of the possible messages:

From: CRogers@my-deja.com (Charlie Rogers) Subject: Girls of 13-16 y Newsgroups: alt.comp.virus,alt.comp.virus X-No-Archive: Yes Organization: NNTP-Posting-Host: 127.0.0.1 Message-ID: [3b065ceb$1@user.] Date: 19 May 2001 14:45:47 +0300 X-Trace: user. 990272747 127.0.0.1 (19 May 2001 14:45:47 +0300) Lines: 28 Path: user. Xref: user alt.comp.virus:3 young, babyface adolescents http://www.computer2030.com/miembro/schoolpervs free previews now improved new site !! view of pthc xxx FREE !Y.jpg Error: Specified file not found to attach!

It does not do anything to hide it's activity. Once it is started it runs until the next reboot.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.