Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Hacked web server

From: sunzi <sunzi(at)mod-x.co.uk>
Date: Tue Jan 14 2003 - 08:28:48 EST

Rogelio,

on Nimda.E from Symantec:
This worm is similar in functionality to W32.Nimda.A@mm. Differences include the modification of file names used by the worm.

    The attachment received has been changed to: Sample.exe     The dropped .dll file is now: Httpodbc.dll     The worm now copies itself to the \%Windows% folder as Csrss.exe instead of Mmc.exe

Try looking for c:\winnt\csrss.exe for the virus.

Also, this isn't where the ncx99.exe came from. I'd do a thorough search for any usage of cmd.exe/root.exe in your web logs and start there, after taking it offline.

hth,
sunzi
----- Original Message -----
From: "Michael Katz" <mike@procinct.com> To: <incidents@securityfocus.com>
Cc: "Rogelio Vidaurri Courcelle" <rvidaurri@haciendachiapas.gob.mx> Sent: Sunday, January 12, 2003 9:20 PM
Subject: Re: Hacked web server

> At 1/10/2003 12:39 PM, Rogelio Vidaurri Courcelle wrote:
detailed
> in Microsoft Security Bulletin MS00-057
by
> most antivirus software as malware.

--

> This list is provided by the SecurityFocus ARIS analyzer service.
---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
Received on Tue Jan 14 19:10:04 2003
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:56 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library