
The Dell SonicWall Threats Research team has observed a recent wave of IRC bots posing as legitimate applications. The bot installer may arrive with file names such as, chrome.exe or facebook-images.exe on the victim machine. It attempts to masquerade itself as Google Chrome by using the following icon and file properties:
Infection Cycle:
Upon execution the bot creates a copy of itself into the following directories:
In order to start after reboot the bot adds the following keys to the registry:
It also executes the following command to allow itself through the windows firewall:
It connects to a remote IRC based Command and Control server and waits for further instructions:
It then joins an IRC channel named #biz:
During our analysis, we noticed the Command and Control server sending instructions to download an additional malware component:
The downloaded malware is copied into the following directory:
The following registry keys were added by the bot to persist infection upon system reboot:
It also sent an instruction to create another component which uses the Pidgin icon and is copied into the following directory:
Dell SonicWALL Gateway AntiVirus provides protection against this threat via the following signatures:
Share This Article

An Article By
An Article By
Security News
Security News