|
|||||||||||
|
Re[2]: First Dcom Worm on wild
From: BrAinsTorM <BrAinsTorM(at)quakenet.biz>
Date: Mon Aug 11 2003 - 16:44:22 EDT Hello Carlos, don't forget to del the registry entrys in run :-) btw below the answer from mcafee which i send the virus. A.V.E.R.T. Sample Analysis Issue Number:279341 Virus Research Analyst: Brant Yaeger Identified:W32/Lovsan.worm
AVERT Labs, Beaverton
Current DAT Version:4283 Thank you for your submission. CL> We have found a file in XP servers named MSBLAST.EXE exploiting the DCOM CL> vulnerability. CL> Our servers kept rebooting, we deleted this file and they stopped. I CL> guess we are seeing as a new malicious code. CL> Carlos Lang CL> -----Mensaje original----- CL> De: Frank Nusko [mailto:BrAinsTorM@quakenet.biz] CL> Enviado el: Lunes, 11 de Agosto de 2003 02:37 p.m. CL> Para: focus-virus@securityfocus.com CL> Asunto: First Dcom Worm on wild CL> Today i detected the first worm on wild which spreads itself. CL> The executable is named msblast.exe and contains the strings: CL> "SAY LOVE YOU SAN!! Bill gates you make it possible" CL> as far as i covered from the compressed/packed exe it uses the 48 target CL> xpl. CL> After a succesful executing on your system it begins scanning other CL> system CL> starting from 192.168.0.1 and going up all ip and classes. CL> so long, CL> if you catch more informations lemme know them CL> regards CL> Frank CL> ------------------------------------------------------------------------ CL> --- CL> ------------------------------------------------------------------------CL> ---- Received on Mon Aug 11 16:57:00 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:40 EDT |
||||||||||
|
|||||||||||