Comments
ha, i got an idea, imagine if these bots start grabbing legitimate pics and names from your friends list or profile and have it resend a friend request, if the profile settings are set to private, allot of things can be grabbed by google cache eh?
I sent this MySpace link to Tyler over at the Security Shoggoth...he does a ton of Malware analysis and tore this one apart:
I dl'd the malware and did a quick analysis. Virustotal is a little less than helpful:
http://www.virustotal.com/a...
but I did some rudimentary strings analysis. Its packed with an unmodified UPX so easy to unpack. The following URLs are in it:
DON'T GO TO THESE!
hxxp://mycashloads.com/newuser.php?saff=
hxxp://windows-privacy-protection.com/?aid=
It also looks to be written in VB6 as I found this in it:
C:\Program Files\Microsoft Visual Studio\VB98\VB6.OLB
as well as some VB-related function calls.
There were also a bunch of these types of messages:
Your computer is infected with spyware!
Windows has detected spyware infection on your PC.#CR##CR#It is recommended to u
pdate your antispyware protection to prevent data loss. Click here to download a
nd install the most up-to-date antispyware for you.#CR##CR#Click here for more i
nformation...
Warning:
Your computer is infected with spyware!#CR#Help to protect your computer and rem
ove spyware!#CR##CR#Click here for more information...&
and so on.
If I had to guess, this is a trojan downloader which would trick you into downloading rogue anti-spyware software by putting those "You've been infected" messages on your system. IMO (and from the limited stuff I've looked at on it) its not specifically bot-related...however, the stuff it downloads might be.
When submitting a comment you may not see it until it is approved by the moderator!


