Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

EnergyMech IRC Bot - ported to Mac, Linux, and FreeBSD

This is not a major concern, except that AV detection is almost non-existant for anyone who might be careless in these environments 0

EnergyMech IRC Bot - ported to Mac, Linux, and FreeBSD
http://isc.sans.org/diary.html?storyid=4042

QUOTE: Yesterday I received samples of an IRC bot. This in itself would be nothing interesting except the fact that the archive contained binaries for FreeBSD and Mac (Darwin, ppc). After initial analysis I found out that it's nothing special – just a port of a well known IRC bot called EnergyMech. The most interesting thing was that the attacker compiled it for FreeBSD and Mac. This probably didn't require any extra effort though since it compiles out of the box on FreeBSD and Linux anyway.