<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AVG Blogs &#187; Have you ever chatted with a Hacker within a virus?</title>
	<atom:link href="http://blogs.avg.com/news-threats/chatted-hacker-virus/feed/?withoutcomments=1" rel="self" type="application/rss+xml" />
	<link>http://blogs.avg.com</link>
	<description>AVG Blogs</description>
	<lastBuildDate>Fri, 17 May 2013 15:11:44 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Have you ever chatted with a Hacker within a virus?</title>
		<link>http://blogs.avg.com/news-threats/chatted-hacker-virus/</link>
		<comments>http://blogs.avg.com/news-threats/chatted-hacker-virus/#comments</comments>
		<pubDate>Mon, 18 Jun 2012 09:08:55 +0000</pubDate>
		<dc:creator>Hynek Blinka</dc:creator>
				<category><![CDATA[News & Threats]]></category>
		<category><![CDATA[AVG]]></category>
		<category><![CDATA[Battle.net]]></category>
		<category><![CDATA[Blizzard]]></category>
		<category><![CDATA[Diablo 3]]></category>
		<category><![CDATA[Latest threats]]></category>
		<category><![CDATA[Threat Labs]]></category>
		<category><![CDATA[Threat News]]></category>
		<category><![CDATA[Threat Report]]></category>
		<category><![CDATA[Web threats]]></category>

		<guid isPermaLink="false">http://blogs.avg.com/?p=14081</guid>
		<description><![CDATA[This is an impressive and first-time experience in my anti-virus career. I chatted with a hacker while debugging a virus. Yes, it’s true. It happened when the Threat team were researching key loggers for Diablo III while many game players playing this game found their accounts stolen.  A sample is found in battle .net in [...]]]></description>
			<content:encoded><![CDATA[<p>This is an impressive and first-time experience in my anti-virus career. I chatted with a hacker while debugging a virus. Yes, it’s true. It happened when the Threat team were researching key loggers for Diablo III while many game players playing this game found their accounts stolen.  A sample is found in battle .net in Taiwan.</p>
<p>The hacker posted a topic titled “How to farm Izual in Inferno” (Izual is a boss in Diablo III ACT 4), and provided a link in the content which, as he said, pointed to a video demonstrating the means.</p>
<p><a href="http://blogs.avg.com/wp-content/uploads/2012/06/image1.png"><img title="image1" src="http://blogs.avg.com/wp-content/uploads/2012/06/image1.png" alt="" width="578" height="316" /></a></p>
<p>&nbsp;</p>
<p>Below is the ‘Video’. It’s a RAR archive actually containing two executable files. These two files are almost the same except the icon.</p>
<p><a href="http://blogs.avg.com/wp-content/uploads/2012/06/image2.png"><img class="alignnone size-full wp-image-14105" style="margin-bottom: 10px; margin-right: 500px;" title="image2" src="http://blogs.avg.com/wp-content/uploads/2012/06/image2.png" alt="" width="213" height="104" /></a></p>
<p>&nbsp;</p>
<p>The malware will connect to a remote server via TCP port 80 and download a new file packed by Themida.</p>
<p><a href="http://blogs.avg.com/wp-content/uploads/2012/06/image3.png"><img class="alignnone size-full wp-image-14106" title="image3" src="http://blogs.avg.com/wp-content/uploads/2012/06/image3.png" alt="" width="1062" height="609" /></a></p>
<p>&nbsp;</p>
<p>That’s very simple Downloader/Backdoor behavior and we are only interested in looking for key logging code for Diablo III so we didn’t pay much attention to it.</p>
<p>But an astonishing scene staged at this time. A chatting dialog popped up with a text message:</p>
<p>(Translated from the image below)</p>
<p>Hacker: What are you doing? Why are you researching my Trojan?</p>
<p>Hacker: What do you want from it?</p>
<p><a href="http://blogs.avg.com/wp-content/uploads/2012/06/image4.jpeg"><img class="alignnone size-full wp-image-14107" style="margin-right: 400px;" title="image4" src="http://blogs.avg.com/wp-content/uploads/2012/06/image4.jpeg" alt="" width="529" height="262" /></a></p>
<p>&nbsp;</p>
<p>The dialog is not from any software installed in our virtual machine. On the contrary, it’s an integrated function of the backdoor and the message is sent from the hacker who wrote the Trojan. Amazing, isn’t it? It seems that the hacker was online and he realized that we were debugging his baby.</p>
<p><a href="http://blogs.avg.com/wp-content/uploads/2012/06/image5.png"><img class="alignnone size-full wp-image-14108" style="margin-right: 400px;" title="image5" src="http://blogs.avg.com/wp-content/uploads/2012/06/image5.png" alt="" width="601" height="731" /></a></p>
<p>&nbsp;</p>
<p>We felt interested and continued to chat with him. He was really arrogant.</p>
<p>(Translated from the image below)</p>
<p>Chicken: I didn’t know you can see my screen.</p>
<p>Hacker: I would like to see your face, but what a pity you don’t have a camera.</p>
<p><a href="http://blogs.avg.com/wp-content/uploads/2012/06/image6.png"><img class="alignnone size-full wp-image-14109" style="margin-right: 400px;" title="image6" src="http://blogs.avg.com/wp-content/uploads/2012/06/image6.png" alt="" width="458" height="236" /></a></p>
<p>&nbsp;</p>
<p>He is telling the truth. This backdoor has powerful functions like monitoring victim’s screen, mouse controlling, viewing process and modules, and even camera controlling.</p>
<p><a href="http://blogs.avg.com/wp-content/uploads/2012/06/image8.png"><img class="alignnone size-full wp-image-14111" title="image8" src="http://blogs.avg.com/wp-content/uploads/2012/06/image8.png" alt="" width="989" height="478" /></a></p>
<p>&nbsp;</p>
<p><a href="http://blogs.avg.com/wp-content/uploads/2012/06/image8.png"><img class="alignnone size-full wp-image-14111" title="image8" src="http://blogs.avg.com/wp-content/uploads/2012/06/image8.png" alt="" width="989" height="478" /></a></p>
<p>We then chatted with hacker for some time, pretending that we were green hands and would like to buy some Trojan from him. But this hacker was not so foolish to tell us all the truth. He then shut down our system remotely.</p>
<p>Regarding this malware, no Diablo III key logging code was captured. What it really wants to steal is dial up connection’s username and password.</p>
<p><a href="http://blogs.avg.com/wp-content/uploads/2012/06/image9.png"><img class="alignnone size-full wp-image-14103" title="image9" src="http://blogs.avg.com/wp-content/uploads/2012/06/image9.png" alt="" width="1538" height="768" /></a></p>
<p>&nbsp;</p>
<p>It sounds like a movie story, but it’s real. We are familiar with malware and we are fighting with them every day. But chatting with malware writers in real time doesn’t happen so often. Next time, I will be on the alert.</p>
<p>The malware and its components are detected by the AVG as <strong>Trojan horse BackDoor.Generic</strong><strong> </strong>variants<strong>.</strong></p>
<p>Franklin Zhao &amp; Jason Zhou</p>
<p>&nbsp;</p>
<div class="nr-shortcode" style="float:left;width:100%;\">
<div class="nr_clear"></div>	
	<div id="nrelate_related_2" class="nrelate nrelate_related nrelate_ nr_ nr_120"></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_').removeClass('nrelate_');</script>
	<![endif]-->
	
	<script type="text/javascript">
	/* <![CDATA[ */
		
		var entity_decoded_nr_url = jQuery('<span/>').html("http://api.nrelate.com/rcw_wp/0.51.1/?tag=nrelate_related&keywords=Have+you+ever+chatted+with+a+Hacker+within+a+virus%3F&domain=blogs.avg.com&url=http%3A%2F%2Fblogs.avg.com%2Fnews-threats%2Fchatted-hacker-virus%2F&nr_div_number=2").text();
		nRelate.getNrelatePosts(entity_decoded_nr_url);
	/* ]]&gt; */
	</script>
<div class="nr_clear"></div></div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_1" class="nrelate nrelate_related nrelate_ nr_ nr_120"></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_').removeClass('nrelate_');</script>
	<![endif]-->
	
	<script type="text/javascript">
	/* <![CDATA[ */
		nRelate.domain = "blogs.avg.com";
		var entity_decoded_nr_url = jQuery('<span/>').html("http://api.nrelate.com/rcw_wp/0.51.1/?tag=nrelate_related&keywords=Have+you+ever+chatted+with+a+Hacker+within+a+virus%3F&domain=blogs.avg.com&url=http%3A%2F%2Fblogs.avg.com%2Fnews-threats%2Fchatted-hacker-virus%2F&nr_div_number=1").text();
		nRelate.getNrelatePosts(entity_decoded_nr_url);
	/* ]]&gt; */
	</script>
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://blogs.avg.com/news-threats/chatted-hacker-virus/feed/</wfw:commentRss>
		<slash:comments>93</slash:comments>
		</item>
	</channel>
</rss>
