Feeds

How Goner suspects were tracked down

Digital fingerprints left on IRC channel

  • alert
  • submit to reddit

Top three mobile application threats

Messages coded into the Goner worm and monitoring of the IRC channel used to control its activities led to the arrest of four suspected Israeli virus writers over the weekend.

One of the actions of Goner, which normally spreads as an infected attached-to-email message, is to install denial of service scripts for the mIRC Internet Relay Chat client. By monitoring the #pentagonex channel used to control the worm's activities, security experts working for DALnet IRC were able to track down its suspected creators.

Emma Monks, a volunteer with DALnet's exploits prevention team, said that after disabling the worm's denial of service abilities, which were believed to be targeted at a rival gang's ISP, DALnet's team set to track down the virus authors.

When activated the Goner worm displays a message, apparently from the author to his friends:

"Pentagone - coded by: suid. tested by ThE_SKuLL and [satan]. greetings to: TraceWar, k9-unit, stef16, ^Reno. Greetings also to nonick2 out there where ever you are."

DALnet records the IP address of anyone setting up an IRC channel which combined with the nicknames featured in the message the virus generates gave investigators vital clues.

Monks explained that by cross references the nicknames of those attempting to control drones from compromised machines on the channel with its database gave the IP addresses of members of the virus writing gang.

This information was turned over to the FBI, which in turn passed it on to the Israeli police. The four teenagers who were arrested on Friday are held in a juvenile detention centre pending a court appearance today and their computers have been seized. If convicted they could face a sentence of between three to five years in jail.

Goner is a fairly simple in its design, but it contains some nasty tricks up its sleeve including an attempt to disable antivirus and personal firewall applications. It spreads by ICQ as well as by Outlook. More details on the worm can be found here. ®

Related stories

Israeli kids fess up to stupid worm attack
Stupid worm spreads like wildfire
Hybrid viruses set to become bigger threat
Users haven't learned any lessons from the Love Bug
Rise in viruses within emails outpacing growth of email

Combat fraud and increase customer satisfaction

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Canadian taxman says hundreds pierced by Heartbleed SSL skewer
900 social insurance numbers nicked, says revenue watchman
German space centre endures cyber attack
Chinese code retrieved but NSA hack not ruled out
Burnt out on patches this month? Oracle's got 104 MORE fixes for you
Mass patch for issues across its software catalog
Reddit users discover iOS malware threat
'Unflod Baby Panda' looks to snatch Apple IDs
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.