|
|||||||||||
|
Re: Worm on 445/tcp?
From: Scott Fendley <scottf(at)uark.edu>
Date: Tue Dec 17 2002 - 12:24:42 EST I think what you are seeing is the newest worm to come out called LIOTEN or Iraqi Oil worm. It appears that it is only infecting windows 2k/XP servers via SMB connections. There appears to be a lot of details amongst the following URLs which can do a better job describing this worm then I could. --Scott http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.lioten.htmlhttp://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_LIOTEN.Ahttp://vil.mcafee.com/dispVirus.asp?virus_k=99897http://www.mynetwatchman.com/kb/security/articles/iraqiworm/index.htmhttp://www.unixwiz.net/iraqworm/
At 08:56 AM 12/17/2002 +0100, Scott A.McIntyre wrote:
--- Scott Fendley scottf@uark.edu Systems/Security Analyst (479) 575-2022 University of Arkansas (479) 575-4753 fax ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.comReceived on Tue Dec 17 13:55:08 2002 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:54 EDT |
||||||||||
|
|||||||||||