{"id":18705,"date":"2012-09-20T13:28:48","date_gmt":"2012-09-20T20:28:48","guid":{"rendered":"http:\/\/blogs.mcafee.com\/?p=18705"},"modified":"2025-06-03T19:41:59","modified_gmt":"2025-06-04T02:41:59","slug":"ngrbot-spreads-via-chat","status":"publish","type":"post","link":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/","title":{"rendered":"NGRBot Spreads Via Chat"},"content":{"rendered":"<p>NGRBot is a worm that propagates through chat messengers, the Internet Relay Chat channel, social networking sites etc. It steals FTP and browser passwords and can cause a denial of service by flooding.<\/p>\n<p>NGRBots use the IRC network for file transfer, sending and receiving commands between zombie network machines and the attacker&#8217;s IRC server, and monitoring and controlling network connectivity and intercept. It employs a user-mode rootkit technique to hide and steal its victim&#8217;s information. This family of bot is also designed to infect HTML pages with iframes, causing redirections, blocking victims from getting updates from security\/antimalware products, and killing those services. The bot is designed to connect via a predefined IRC channel and communicate with a remote botnet.<\/p>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/?attachment_id=18727\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18727\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/pic12.png\" alt=\"\" width=\"89\" height=\"159\" \/><\/a><\/p>\n<p>Figure 1: We see &#8220;ngrbot&#8221; string in memory.<\/p>\n<p>Once connected to the IRC channel, the bot can function as backdoor and receive commands from a remote attacker.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" title=\"Modules\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/34.png\" alt=\"\" width=\"473\" height=\"610\" \/><\/p>\n<p>The following message box is displayed if someone tries to reverse engineer the malware:<\/p>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/?attachment_id=18728\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18728\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/sec1.png\" alt=\"\" width=\"192\" height=\"61\" \/><\/a><\/p>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/?attachment_id=18731\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18731\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/61.png\" alt=\"\" width=\"518\" height=\"670\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/61.png 518w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/61-231x300.png 231w\" sizes=\"auto, (max-width: 518px) 100vw, 518px\" \/><\/a><\/p>\n<p>Figure 2: NGRBot\u2019s paths of operation and related activity.<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>A Look at NGRBot: Self-update and DNS-setting modification modules<\/strong><\/h2>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/?attachment_id=18732\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18732\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/71.png\" alt=\"\" width=\"558\" height=\"176\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/71.png 558w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/71-300x94.png 300w\" sizes=\"auto, (max-width: 558px) 100vw, 558px\" \/><\/a><\/p>\n<p><strong>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 RushKill Module\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Grabber Module<\/strong><\/p>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/?attachment_id=18715\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18715\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/8.png\" alt=\"\" width=\"431\" height=\"228\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/8.png 431w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/8-300x158.png 300w\" sizes=\"auto, (max-width: 431px) 100vw, 431px\" \/><\/a><\/p>\n<p>With the help of the Grabber module, the bot can intercept communications between the victim and browser chat and steals the username and password.<\/p>\n<h2><strong>Flooder Module Strings<\/strong><\/h2>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/?attachment_id=18716\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18716\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/10.png\" alt=\"\" width=\"463\" height=\"142\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/10.png 463w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/10-300x92.png 300w\" sizes=\"auto, (max-width: 463px) 100vw, 463px\" \/><\/a><\/p>\n<h2><strong>IRC Communicator Module Strings<\/strong><\/h2>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/?attachment_id=18735\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18735\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/112.png\" alt=\"\" width=\"580\" height=\"185\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/112.png 580w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/112-300x95.png 300w\" sizes=\"auto, (max-width: 580px) 100vw, 580px\" \/><\/a><\/p>\n<h2><strong>Spreader Module<\/strong><\/h2>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/?attachment_id=18719\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18719\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/12.png\" alt=\"\" width=\"397\" height=\"452\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/12.png 397w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/12-263x300.png 263w\" sizes=\"auto, (max-width: 397px) 100vw, 397px\" \/><\/a><\/p>\n<h2><strong>String Related to Bot Joining IRC Channel<\/strong><\/h2>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/?attachment_id=18720\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18720\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/13.png\" alt=\"\" width=\"607\" height=\"226\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/13.png 607w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/13-300x111.png 300w\" sizes=\"auto, (max-width: 607px) 100vw, 607px\" \/><\/a><\/p>\n<h2><strong>Behavioral characteristics:<\/strong><\/h2>\n<ul>\n<li>Injects into many running processes<\/li>\n<li>Hooks several APIs of various loaded modules<\/li>\n<li>Injects into explorer.exe and connects to 27.54.193.102\u00a0 through post 7171<\/li>\n<li>Can spread through removable devices with the autorun.inf<\/li>\n<li>Name of sample copy dropped inside %appdata% folder by calling GetVolumeInformation() API for Hard Disk serial number<\/li>\n<\/ul>\n<p>NGRBot uses mutual exclusion to ensure one of its instances is always running:<\/p>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/?attachment_id=18721\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18721\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/14.png\" alt=\"\" width=\"550\" height=\"111\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/14.png 550w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/14-300x60.png 300w\" sizes=\"auto, (max-width: 550px) 100vw, 550px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/?attachment_id=18722\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18722\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/15.png\" alt=\"\" width=\"534\" height=\"270\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/15.png 534w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/15-300x151.png 300w\" sizes=\"auto, (max-width: 534px) 100vw, 534px\" \/><\/a><\/p>\n<p><strong>A message from the NGRBot author and the script file for deleting downloaded files<\/strong><\/p>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/?attachment_id=18723\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18723\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/16.png\" alt=\"\" width=\"606\" height=\"347\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/16.png 606w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/16-300x171.png 300w\" sizes=\"auto, (max-width: 606px) 100vw, 606px\" \/><\/a><\/p>\n<p>NGRBot downloads other malicious files onto a victim&#8217;s machine. We noticed the fake AV Live Platinum Security (8.exe in the next screen) and the trojan KillAV (7.exe) in the %appdata% folder and then executing.<\/p>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/?attachment_id=18724\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18724\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/17.png\" alt=\"\" width=\"606\" height=\"338\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/17.png 606w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/17-300x167.png 300w\" sizes=\"auto, (max-width: 606px) 100vw, 606px\" \/><\/a><\/p>\n<p>The dropped malwares survive after rebooting by making &#8220;Run&#8221; entries on the machine.<\/p>\n<p>The dropped KillAV Trojan has many antidebugging tricks to make it difficult to reverse-engineer. This Trojan also checks for more than 100 running security\/antimalware processes and kills them.<\/p>\n<table border=\"0\" width=\"342\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">scfmanager<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">Fsaw<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">livesrv<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">mscif<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">vir.exe<\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">savser<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">Fspex<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">bdmcon<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">mpft<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">webproxy<\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">savadmins<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">fsm32<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">bdagent<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">mpfser<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">pavfnsvr<\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">alsvc<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">Tsanti<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">xcommsvr<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">mpfag<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">avengine<\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">almon<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">Kavpf<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">PXConsole<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">mcvss<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">avciman<\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">npfmsg2<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">Kav<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">PXAgent<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">mcvs<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">apvxdwin<\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">zlh<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">dpasnt<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">kpf4ss<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">mcupd<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">avp<\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">zanda<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">Msfw<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">kpf4gui<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">mcupdm<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">cavtray<\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">cclaw<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">msmps<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">sunthreate<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">mctsk<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">cavrid<\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">npfsvice<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">mpeng<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">sunserv<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">mcshi<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\"><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">njeeves<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">Msco<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">sunprotect<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">mcdet<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\"><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">nipsvc<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">winssno<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">counter<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">mcage<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\"><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">nip<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">symlcsvc<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">clamwin<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">zlcli<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\"><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">nvcsched<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">spbbcsvc<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">clamtray<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">vsmon<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\"><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">nvcoas<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">sndsrvc<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">avgnt<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">webroot<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\"><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">spidernt<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">nscsrvce<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">avguard<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">spysw<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\"><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">spiderui<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">navapsvc<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">avesvc<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">firewalln<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\"><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">drweb<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">ccsetmgr<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">avcenter<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">vrmo<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\"><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">pxcons<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">ccproxy<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">ashwebsv<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">vrfw<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\"><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">pxagent<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">ccetvm<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">ashdisp<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">hsock<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\"><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">guardxkickoff<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">Ccapp<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">ashmaisv<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">wmiprv<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\"><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">vba32ldr<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">alusched<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">ashserv<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">mxtask<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\"><\/td>\n<\/tr>\n<tr>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"82\">nod32kui<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">Oascl<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"67\">isafe<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\">caissdt<\/td>\n<td valign=\"bottom\" nowrap=\"nowrap\" width=\"64\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p>The Trojan connects to two sites:<\/p>\n<ul>\n<li>http:\/\/92.241.163.23\/0xabad1dea.php?a=67658d6248b79e364ccfd3e9039361e2d47480f72e7815132d&amp;b=39002&amp;c=37050<\/li>\n<li>http.xxxx.zaberno.com<\/li>\n<\/ul>\n<p>The Fake AV Live Security Platinum blocks victims from several files:<\/p>\n<ul>\n<li>regsvr32.exe<\/li>\n<li>cmd.exe<\/li>\n<li>rundll32.exe<\/li>\n<li>regedit.exe<\/li>\n<li>verclsid.exe<\/li>\n<li>ipconfig.exe<\/li>\n<\/ul>\n<p>The malware stops the victim from downloading files with the following file extensions:<\/p>\n<ul>\n<li>exe<\/li>\n<li>com<\/li>\n<li>pif<\/li>\n<li>scr<\/li>\n<\/ul>\n<h2><strong>Advice to Customers<\/strong><\/h2>\n<p>McAfee successfully unhooks and completely cleans the malware. Update your scanners with the latest DATs. Avoid clicking on suspicious links in chat windows or on social networking sites without first searching online. Beware of social engineering tricks used by malware authors to lure victims into clicking malicious links. Make sure you have a reputable firewall installed in your machine.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>NGRBot is a worm that propagates through chat messengers, the Internet Relay Chat channel, social networking sites etc. It steals&#8230;<\/p>\n","protected":false},"author":674,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[442],"tags":[49],"coauthors":[3973],"class_list":["post-18705","post","type-post","status-publish","format-standard","hentry","category-mcafee-labs","tag-botnet"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>NGRBot Spreads Via Chat | McAfee Blog<\/title>\n<meta name=\"description\" content=\"NGRBot is a worm that propagates through chat messengers, the Internet Relay Chat channel, social networking sites etc. It steals FTP and browser\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NGRBot Spreads Via Chat | McAfee Blog\" \/>\n<meta property=\"og:description\" content=\"NGRBot is a worm that propagates through chat messengers, the Internet Relay Chat channel, social networking sites etc. It steals FTP and browser\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/\" \/>\n<meta property=\"og:site_name\" content=\"McAfee Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/McAfee\/\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/McAfee\/\" \/>\n<meta property=\"article:published_time\" content=\"2012-09-20T20:28:48+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-04T02:41:59+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/pic12.png\" \/>\n\t<meta property=\"og:image:width\" content=\"89\" \/>\n\t<meta property=\"og:image:height\" content=\"159\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"McAfee\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@McAfee\" \/>\n<meta name=\"twitter:site\" content=\"@McAfee\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"McAfee\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/\"},\"author\":{\"name\":\"McAfee\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/47851fdb92fad9456152405839c92efa\"},\"headline\":\"NGRBot Spreads Via Chat\",\"datePublished\":\"2012-09-20T20:28:48+00:00\",\"dateModified\":\"2025-06-04T02:41:59+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/\"},\"wordCount\":620,\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/pic12.png\",\"keywords\":[\"botnet\"],\"articleSection\":[\"McAfee Labs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/\",\"name\":\"NGRBot Spreads Via Chat | McAfee Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/pic12.png\",\"datePublished\":\"2012-09-20T20:28:48+00:00\",\"dateModified\":\"2025-06-04T02:41:59+00:00\",\"description\":\"NGRBot is a worm that propagates through chat messengers, the Internet Relay Chat channel, social networking sites etc. It steals FTP and browser\",\"breadcrumb\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/#primaryimage\",\"url\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/pic12.png\",\"contentUrl\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/pic12.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Blog\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Other Blogs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"McAfee Labs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"NGRBot Spreads Via Chat\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"name\":\"McAfee Blog\",\"description\":\"Internet Security News\",\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\",\"name\":\"McAfee\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"width\":1286,\"height\":336,\"caption\":\"McAfee\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/McAfee\/\",\"https:\/\/x.com\/McAfee\",\"https:\/\/www.linkedin.com\/company\/mcafee\/\",\"https:\/\/www.youtube.com\/McAfee\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/47851fdb92fad9456152405839c92efa\",\"name\":\"McAfee\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/1ffadfeeda1f4f9e7891a81f27a9ecf4\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/08\/Original-Logo-96x96.png\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/08\/Original-Logo-96x96.png\",\"caption\":\"McAfee\"},\"description\":\"We're here to make life online safe and enjoyable for everyone.\",\"sameAs\":[\"https:\/\/www.facebook.com\/McAfee\/\",\"https:\/\/www.linkedin.com\/company\/mcafee\/\",\"https:\/\/x.com\/McAfee\"],\"url\":\"https:\/\/www.mcafee.com\/blogs\/author\/mcafee\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NGRBot Spreads Via Chat | McAfee Blog","description":"NGRBot is a worm that propagates through chat messengers, the Internet Relay Chat channel, social networking sites etc. It steals FTP and browser","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"NGRBot Spreads Via Chat | McAfee Blog","og_description":"NGRBot is a worm that propagates through chat messengers, the Internet Relay Chat channel, social networking sites etc. It steals FTP and browser","og_url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/","og_site_name":"McAfee Blog","article_publisher":"https:\/\/www.facebook.com\/McAfee\/","article_author":"https:\/\/www.facebook.com\/McAfee\/","article_published_time":"2012-09-20T20:28:48+00:00","article_modified_time":"2025-06-04T02:41:59+00:00","og_image":[{"width":89,"height":159,"url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2012\/09\/pic12.png","type":"image\/png"}],"author":"McAfee","twitter_card":"summary_large_image","twitter_creator":"@McAfee","twitter_site":"@McAfee","twitter_misc":{"Written by":"McAfee","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/#article","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/"},"author":{"name":"McAfee","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/47851fdb92fad9456152405839c92efa"},"headline":"NGRBot Spreads Via Chat","datePublished":"2012-09-20T20:28:48+00:00","dateModified":"2025-06-04T02:41:59+00:00","mainEntityOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/"},"wordCount":620,"publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/#primaryimage"},"thumbnailUrl":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/pic12.png","keywords":["botnet"],"articleSection":["McAfee Labs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/","url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/","name":"NGRBot Spreads Via Chat | McAfee Blog","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/#primaryimage"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/#primaryimage"},"thumbnailUrl":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/pic12.png","datePublished":"2012-09-20T20:28:48+00:00","dateModified":"2025-06-04T02:41:59+00:00","description":"NGRBot is a worm that propagates through chat messengers, the Internet Relay Chat channel, social networking sites etc. It steals FTP and browser","breadcrumb":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/#primaryimage","url":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/pic12.png","contentUrl":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/2012\/09\/pic12.png"},{"@type":"BreadcrumbList","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/ngrbot-spreads-via-chat\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https:\/\/www.mcafee.com\/blogs\/"},{"@type":"ListItem","position":2,"name":"Other Blogs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/"},{"@type":"ListItem","position":3,"name":"McAfee Labs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/"},{"@type":"ListItem","position":4,"name":"NGRBot Spreads Via Chat"}]},{"@type":"WebSite","@id":"https:\/\/www.mcafee.com\/blogs\/#website","url":"https:\/\/www.mcafee.com\/blogs\/","name":"McAfee Blog","description":"Internet Security News","publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.mcafee.com\/blogs\/#organization","name":"McAfee","url":"https:\/\/www.mcafee.com\/blogs\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","width":1286,"height":336,"caption":"McAfee"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/McAfee\/","https:\/\/x.com\/McAfee","https:\/\/www.linkedin.com\/company\/mcafee\/","https:\/\/www.youtube.com\/McAfee"]},{"@type":"Person","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/47851fdb92fad9456152405839c92efa","name":"McAfee","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/1ffadfeeda1f4f9e7891a81f27a9ecf4","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/08\/Original-Logo-96x96.png","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/08\/Original-Logo-96x96.png","caption":"McAfee"},"description":"We're here to make life online safe and enjoyable for everyone.","sameAs":["https:\/\/www.facebook.com\/McAfee\/","https:\/\/www.linkedin.com\/company\/mcafee\/","https:\/\/x.com\/McAfee"],"url":"https:\/\/www.mcafee.com\/blogs\/author\/mcafee\/"}]}},"_links":{"self":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/18705","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/users\/674"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/comments?post=18705"}],"version-history":[{"count":2,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/18705\/revisions"}],"predecessor-version":[{"id":215021,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/18705\/revisions\/215021"}],"wp:attachment":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/media?parent=18705"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/categories?post=18705"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/tags?post=18705"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/coauthors?post=18705"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}