Skip to main content

SubSeven Beta 2.3 is FAKE - A fake subseven backdoor with a dangerous payload!

posted onJanuary 27, 2002
by hitbsecnews

Source: SNP

l33tdawg: I've got a guy on my ICQ list who says that this isn't true -- the reason being he actually worked on development of SubSeven, and claims that this report is fake. Hmmmz... seems like a dubious claim to me, but all the same, I'll guide him here so he can post his comments/arguments for all of you.

What is a hacker to do when they find their favorite upgrade to the SubSeven trojan has been tampered with by virus writers looking for a few laughs. Floating around the Internet at the moment is what is claimed to be Version 2.3 of the infamous SubSeven program. And although the backdoor program claims to be the beta version 2.3 of the Subseven backdoor program it is actually an IRC bot dropper.

The bogus server component of this backdoor program copies itself to a WINDOWS.EXE file in the Windows directory or the System directory. This bogus server is an IRC bot that connects to an IRC server while it is running in memory. This IRC bot responds to the its author’s commands. It also has a bogus client that shows a graphical user interface (GUI) that claims to be the interface for beta version 2.3 of the Subseven backdoor trojan. However, clicking on the buttons of the GUI only causes an error and a termination of the bogus client.

Source

Tags

Networking

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th