Spyware Confidential

Larry Dignan, Jason Perlow, Tom Steinert-Threlkeld

Spamming malware: Parite.B and IRC backdoor disable anti-spyware programs

By | April 21, 2006, 8:31pm PDT

I got a spam this morning with a subject line of "yahoo send you postcard" from "postcard". Of course all the alarms went off in my head, but there was no attachment and I have a nice little freeware app called PocketKnife Peek that lets you preview an email in plain text, view the html source, the headers and attachments without opening the email. (Minor rant — why doesn’t Outlook 2003 have that feature?!)

The email was simple.  Note, I deactivated the link to the infected file.

Hello
You have just received a postcard from www.yahoo.com. If you’d like to see the rest of the message click here (tapshed.co.uk/~info/postcard.gif.exe) to receive your animated postcard!

===================

Thank you for using our  services !!!

Please take this opportunity to let your friends hear about us by sending them a postcard from our collection !

==================

I was sure that postcard.gif.exe was malware and I started VMware and downloaded the file from the link. The file looks innocent enough with this icon.

postcard_1.JPG

I ran the file with InCtrl5 to see exactly what it did.  It dropped a file svchost.exe in C:\WINDOWS\System\  — note not where the legitimate Windows file svchost.exe runs from, and it installed an IRC server in the same folder. I’ve seen lots of adware and spyware files and watched what they do, but this was my first time having an IRC server in my machine.  There was plenty of activity with many connections using TCP:6667, a known port for IRC and malware.  Here’s a portion of the IRC server config file:

n0=2peu.roSERVER:2peu.ro:6667GROUP:Undernet
n1=Lelystad.NL.EU.UnderNet.OrgSERVER:
Lelystad.NL.EU.UnderNet.Org:6667GROUP:Undernet
n2=Ede.NL.EU.UnderNet.OrgSERVER:
Ede.NL.EU.UnderNet.Org:6667GROUP:Undernet
n3=London.UK.Eu.UnderNet.orgSERVER:
London.UK.Eu.UnderNet.org:6667GROUP:Undernet

Apparently Undernet.org (link to whois) has been around for a long time and may be used for a lot of warez file swapping from what I’ve heard.

The installer and svchost.exe files were detected by scanners at Jotti’s online malware scan site as  Parite.B and all the IRC files were detected as Backdoor.IRC.Zapchast. You can read a description of Parite.B here (Panda) and Backdoor.IRC.Zapchast here (Sophos). Neither of these are new, but there appear to be some new variants making the rounds.

What’s bad about this scenario is that most users wouldn’t have any clue that they were infected if they don’t have an anti-virus.  Most of the connections completely bypassed the firewall running inside the vm. Using Task Manager to view the running processes might clue someone in if they noticed scvhost.exe running from an atypical location.

I started to run my anti-spyware scanners and got a surprise. SpywareDoctor didn’t want to open and gave an error message saying the program had been damaged and should be reinstalled. Spy Sweeper gave a similar error message and opened, but many of the options were grayed out, including the scan option. Ad-Aware and Spybot Search & Destroy both opened normally. I went back to Jotti and scanned the main executable for each app, including the two that opened normally, and they all came back infected with Parite or Parite.B!  I suppose if I’d had an anti-virus running inside the vm the same thing might have happened to it.

The other question is what would happen to the machine left infected over a period of time with a backdoor and IRC server running? It might become part of a bot net and spread malware, it might be used for spamming or in a DDoS attack. It would likely have more malware installed, possibly a rootkit and maybe some adware, too.  I saved a snapshot of the infected vm, so maybe I’ll find out.

The moral of this story? Don’t click on links in emails from unknown sources, or in even from known sources because the senders can be forged, unless you are sure it’s safe. I know people reading this blog already know that but apparently a lot of people don’t know or don’t care, otherwise the malware pushers wouldn’t continue sending these spams.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Biography

Suzi Turner is webmaster and owner of SpywareWarrior.com, a comprehensive site that includes a spyware help forum, spyware blog and reviews of anti-spyware software by noted spyware expert Eric L. Howes. Suzi became angry about spyware in 2002 after being infected by a drive-by-download of a browser hijacker and unwanted adware/spyware and decided to help others in the same predicament. In April 2005, Microsoft awarded Suzi its MVP (Most Valued Professional) Award in recognition of her work to help internet users protect their privacy by removing and preventing spyware. Suzi is also a nurse for a national disability management company.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
10
Comments

Join the conversation!

Just In

agreed
Suzi_z 5th May 2006
Someone is spamming for StopZilla, probably an affiliate, and it sure doesn't reflect well on the company. /insert rolling eyes emoticon/
0 Votes
+ -
Thanks!
Arnie Vios 22nd Apr 2006
Thanks for the heads-up, Suzi.
Spywarequake invaded over 30 of my clients computers and they have no phone number on their site and the software is difficult to remove. ZDNET should reprimand them and take away the good rating they claim you gave them. I have been an IT consultant for 15 years and this and Malwarewipe are two companies that shoulld change their ways or go out of business. They are being reported by myself and others to the Ma. attoryney general and the FTC
They don't even have away of contacting them on the www.spywarequake.com website. That is because the softare is really malware and they are afraid of being contacted by the average user so that they can leave their evil warnings on your PC. I can remove it but the average user can't
Kit Carle
0 Votes
+ -
indeed!
Suzi_z 25th Apr 2006
SpywareQuake is evil and believed to be associated with the CoolWebSearch gangsters. SpywareQuake will never have their contact info on their site or in their domain registration info because they don't want to be found. There is some information here about the domain registration information and IP address of the SpywareQuake site:

http://blogs.zdnet.com/Spyware/?p=802

Actually they may have moved to different servers and IP addresses twice since that blog entry.

If SpywareQuake is available for download at ZDNet, I'll ask to have it removed. I'm sure ZDNet does not want be associated with this program if they are aware of what it does.
0 Votes
+ -
Spywarequake and SpyAxe
Arnie Vios 26th Apr 2006
It seems that Spywarequake and SpyAxe came from ONE SOURCE.
Anyway, Lavasoft's AdAware can be used to remove said malware.
0 Votes
+ -
Wow....
Arnout Groen 26th Apr 2006
This is the first time, is see my living area mentioned in a blog at ZDnet... Wished it was in a positive way..

n2=Ede.NL.EU.UnderNet.OrgSERVER:
0 Votes
+ -
Hi
Suzi_z 5th May 2006
Arnout, I just saw your commnet. I'd never heard of Undernet.org before they took up occupancy in my computer. I was watching the packet transmissions and wondering what was actually going on with the people using my machine. Why are Parite.B and the IRC Zapchast trojan being spammed?
0 Votes
+ -
Combat Spyware
iamannenne 2nd May 2006
I recently began using STOPzilla and it works, it is well worth the money. The software automatically suppresses adware, spyware applications and more without interrupting your web experience. It is unobtrusive and does everything that I hoped it would do. You can check it out by going to href="http://www.stealthsurfer.biz/stopzilla/stopzilla.html" Stopzilla
0 Votes
+ -
Combat Spyware
iamannenne 2nd May 2006
I recently began using STOPzilla and it works, it is well worth the money. The software automatically suppresses adware, spyware applications and more without interrupting your web experience. It is unobtrusive and does everything that I hoped it would do. You can check it out by going to http://www.stealthsurfer.biz/stopzilla/stopzilla.html
0 Votes
+ -
Spam right there ^^^
bumberfsck 4th May 2006
that looks an awful lot like spam. It sure reads like an advertisement.
0 Votes
+ -
agreed
Suzi_z 5th May 2006
Someone is spamming for StopZilla, probably an affiliate, and it sure doesn't reflect well on the company. /insert rolling eyes emoticon/

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix