This is an impressive and first-time experience in my anti-virus career. I chatted with a hacker while debugging a virus. Yes, it’s true. It happened when the Threat team were researching key loggers for Diablo III while many game players playing this game found their accounts stolen. A sample is found in battle .net in Taiwan.
The hacker posted a topic titled “How to farm Izual in Inferno” (Izual is a boss in Diablo III ACT 4), and provided a link in the content which, as he said, pointed to a video demonstrating the means.
Below is the ‘Video’. It’s a RAR archive actually containing two executable files. These two files are almost the same except the icon.
The malware will connect to a remote server via TCP port 80 and download a new file packed by Themida.
That’s very simple Downloader/Backdoor behavior and we are only interested in looking for key logging code for Diablo III so we didn’t pay much attention to it.
But an astonishing scene staged at this time. A chatting dialog popped up with a text message:
(Translated from the image below)
Hacker: What are you doing? Why are you researching my Trojan?
Hacker: What do you want from it?
The dialog is not from any software installed in our virtual machine. On the contrary, it’s an integrated function of the backdoor and the message is sent from the hacker who wrote the Trojan. Amazing, isn’t it? It seems that the hacker was online and he realized that we were debugging his baby.
We felt interested and continued to chat with him. He was really arrogant.
(Translated from the image below)
Chicken: I didn’t know you can see my screen.
Hacker: I would like to see your face, but what a pity you don’t have a camera.
He is telling the truth. This backdoor has powerful functions like monitoring victim’s screen, mouse controlling, viewing process and modules, and even camera controlling.
We then chatted with hacker for some time, pretending that we were green hands and would like to buy some Trojan from him. But this hacker was not so foolish to tell us all the truth. He then shut down our system remotely.
Regarding this malware, no Diablo III key logging code was captured. What it really wants to steal is dial up connection’s username and password.
It sounds like a movie story, but it’s real. We are familiar with malware and we are fighting with them every day. But chatting with malware writers in real time doesn’t happen so often. Next time, I will be on the alert.
The malware and its components are detected by the AVG as Trojan horse BackDoor.Generic variants.
Franklin Zhao & Jason Zhou
-
http://www.facebook.com/profile.php?id=100002611191654 To No
-
Anonymous
-
http://www.facebook.com/marcinx Marcin Olszowy
-
Anonymous
-
http://twitter.com/GODJonez Joonas Lehtolahti
-
http://www.wandernauta.nl Wander Nauta
-
http://www.facebook.com/profile.php?id=100002084425052 Sergiu Wittenberger Badau
-
http://twitter.com/horsebones Leke
-
http://twitter.com/PolBias Political Bias
-
Rob Ayers
-
Anonymous
-
http://twitter.com/TerrorBite TerrorBite
-
http://twitter.com/CosmicParrot Cosmic Parrot
-
http://www.facebook.com/people/Kaye-Scrue/100001966302049 Kaye Scrue
-
Anonymous
-
http://www.facebook.com/profile.php?id=100001647322939 Alex Connolly
-
http://twitter.com/thomhastings Thom Hastings
-
http://twitter.com/thomhastings Thom Hastings
-
http://twitter.com/Trollaroid Trollaroid
-
Anonymous
-
http://twitter.com/kieranjscott Kieran James Scott
-
Anonymous
-
http://tonytonyjan.github.com/ Jian, Wei-Hang
-
http://twitter.com/Darestium Jordan Hodgson
-
Joe Mudaka
-
Ray Wang
-
http://blogs.avg.com Charlie Sanchez
-
http://www.liquidmatrix.org/blog/2012/06/20/researcher-chats-with-hacker-within-a-virus/ Researcher Chats With Hacker Within A Virus | Liquidmatrix Security Digest
-
http://arstechnica.com/security/2012/06/hacker-uses-malware-built-in-chat-to-toy-with-researchers/ Hacker uses malware built-in chat to toy with researchers | Ars Technica
-
http://covac-software.com/ Christian Sciberras
-
http://visualrobots.wordpress.com/2012/06/20/hacker-uses-malware-built-in-chat-to-toy-with-researchers/ Hacker uses malware built-in chat to toy with researchers | vis a vis | visual mind
-
Anonymous
-
Juan Fernando M
-
Anonymous
-
Anonymous
-
http://www.yehuoji.com/archives/39731.html 中国黑客通过木马内置聊天功能和AVG研究人员聊天_互联网资讯最新报道_野火集
-
http://xjspace.org/1451.html 黑客通过内置聊天功能和木马研究人员聊天 – Official blog for xjspace
-
http://intranet.securemymind.com/%e4%b8%ad%e5%9b%bd%e9%bb%91%e5%ae%a2%e9%80%9a%e8%bf%87%e6%9c%a8%e9%a9%ac%e5%86%85%e7%bd%ae%e8%81%8a%e5%a4%a9%e5%8a%9f%e8%83%bd%e5%92%8cavg%e7%a0%94%e7%a9%b6%e4%ba%ba%e 中国黑客通过木马内置聊天功能和AVG研究人员聊天 | 安全业界观察
-
http://exploitarchive.com/boot-up-nokia-and-windows-8-hackers-in-the-virus-why-dont/ Boot up: Nokia and Windows 8, hackers in the virus, why don’t … | Exploit Archive
-
http://cn.cybersharq.com/131697.html 中国黑客通过木马内置聊天功能和AVG研究人员… | 博鲨科技 跨界畅游|中国领先的网站制作、电子商务、在线交易方案提供商
-
http://www.freebuf.com/news/4503.html 中国黑客通过木马内置聊天功能和AVG研究人员聊天- FreebuF.COM
-
http://vansrealm.com/boot-up-nokia-windows-8-hackers-virus-dont-android-tablets-sell/ VAN'S REALM – TAKE CAUTION! YOU HAVE NOW ENTERED MY ZONE.
-
http://www.gyvernetworks.com/TechBlog/2012/06/have-you-ever-chatted-with-a-hacker-within-a-virus/ Gyver Networks | Desktop, laptop, netbook, PC workstation hardware & software replacement & support
-
http://xlinesoft.com/ Sergey Kornilov
-
http://diablo3.ingame.de/525933/diablo-3-hacker-verbreitet-trojaner-uber-battle-net-forum/ Diablo 3: Hacker verbreitet Trojaner über Battle.net-Forum | Diablo 3 – inDiablo.de
-
Chris DeJoseph
-
Justin White
-
http://twitter.com/kodemage Benjamin F. Klahn
-
http://nerdinaboxonline.com/2012/06/21/malware-author-taunts-security-researchers-with-built-in-chat/ Malware author taunts security researchers with built-in chat » Nerd In A Box Online
-
http://profile.yahoo.com/REDGCN6NVNFTCIKQV56OKOWZ64 julia
-
http://justinkent.me/ Justin Kent
-
http://twitter.com/chrishacken Chris Hacken
-
http://rcstar.net/2012/596/obratnaya-svyaz-c-xakerom.jsp Обратная связь c хакером « Исчадие Ада
-
http://arscity.ru/2012/06/22/programmisty-avg-poobshhalis-s-xakerom-po-vstroennomu-v-troyan-chatu.htm Программисты AVG пообщались с хакером по встроенному в троян чату | Виртуальный город ArsCity
-
Thomas …
-
http://qualsec.ulb.ac.be/2012/06/22/have-you-ever-chatted-with-a-hacker-within-a-virus/ Have you ever chatted with a Hacker within a virus? » Quality and security of information systems
-
子 场
-
http://technabob.com/blog/2012/06/22/chat-with-a-hacker/ Want to Chat with a Hacker? Debug His Malware
-
http://rivaldesign.wordpress.com/2012/06/22/want-to-chat-with-a-hacker-debug-his-malware/ Want to Chat with a Hacker? Debug His Malware « Rival Design
-
http://twitter.com/exittoshell Tim M.
-
http://twitter.com/saiberfun SAI Gaming
-
Anonymous
-
http://neutek.net/blog/hacker-uses-malware-built-in-chat-to-toy-with-researchers/ : neutek : Hacker uses malware built-in chat to toy with researchers
-
http://taylanisikdemir.wordpress.com/2012/06/24/have-you-ever-chatted-with-a-hacker-within-a-virus/ Have you ever chatted with a Hacker within a virus? « Development Notes
-
http://www.blacknewbieteam.org/2012/06/25/hacker-interrupts-avgs-malware-analysis/ Hacker interrupts AVG’s malware analysis | BLACK NEWBIE TEAM
-
http://speartipllc.wordpress.com/2012/06/25/diablo-hacker-springs-reverse-engineers/ Diablo hacker springs reverse engineers « speartipllc
-
崇河 舒
-
http://blog.jobbole.com/22417/ 你通过病毒和黑客聊过天么? – 博客 – 伯乐在线
-
http://www.lanfeng.net/archives/46685.html 反病毒工作经历:中国的黑客究竟有多张狂? – 蓝枫博客
-
Anonymous
-
Anonymous
-
http://niebezpiecznik.pl/post/rozmowa-z-tworca-trojana/ » * Rozmowa z twórcą trojana — Niebezpiecznik.pl –
-
http://www.blugadgets.com/2012/06/26/hacker-chattet-mit-anti-virus-experten/ Hacker chattet mit Anti-Virus Experten | BluGadgets
-
http://www.ritholtz.com/blog/2012/06/tuesday-pm-reads-11/ 10 Tuesday PM Reads | The Big Picture
-
http://profile.yahoo.com/UI4EEYVRRLSEPHRVIUYGKV3HS4 BrianR
-
http://www.facebook.com/profile.php?id=727428732 Per Edman
-
云峰 张
-
http://www.facebook.com/lishu.li.7 Lishu Li
-
http://www.facebook.com/lishu.li.7 Lishu Li
-
b g
-
http://techarena.xtreemhost.com/?p=246 Have you ever chatted with a Hacker within a virus? | Tech Arena
-
http://blog.lucrativesolution.com/boot-up-nokia-and-windows-8-hackers-in-the-virus-why-dont-android-tablets-sell-and-more/ Boot up: Nokia and Windows 8, hackers in the virus, why don’t Android tablets sell?, and more – Lucrative blog
-
Anonymous
-
http://www.facebook.com/777Magnum777 Paul Helm
-
http://www.facebook.com/777Magnum777 Paul Helm
-
http://www.facebook.com/777Magnum777 Paul Helm
-
http://www.facebook.com/sdphoto35 Steven Davis
-
http://www.facebook.com/kyle.pippig Kyle Pippig
-
Anonymous
-
http://avtacha.wordpress.com/2012/08/19/%d7%94%d7%90%d7%9d-%d7%a1%d7%99%d7%9f-%d7%94%d7%99%d7%90-%d7%94%d7%9e%d7%95%d7%a8%d7%99%d7%90%d7%a8%d7%98%d7%99-%d7%a9%d7%9c-%d7%94%d7%9e%d7%90%d7%94-%d7%94-21/ האם סין היא המוריארטי של המאה ה-21 « אבטחה
-
http://www.tisf.co/avtacha/2012/08/19/%d7%94%d7%90%d7%9d-%d7%a1%d7%99%d7%9f-%d7%94%d7%99%d7%90-%d7%94%d7%9e%d7%95%d7%a8%d7%99%d7%90%d7%a8%d7%98%d7%99-%d7%a9%d7%9c-%d7%94%d7%9e%d7%90%d7%94-%d7%94-21/ האם סין היא המוריארטי של המאה ה-21 | אבטחה
-
http://cryptoarm.ru/Ya-Rabinovich-ya-vas-otkluchayu Я – Рабинович! Я Вас отключаю! | КриптоАРМ
-
http://www.facebook.com/profile.php?id=1285147634 Pamala Ann Human-Smith










