[Full-Disclosure] possible MS03-026 worm?

From: mobly99 (dhopper_at_ameritech.net)
Date: 08/02/03

  • Next message: tcpdumb: "Re: [Full-Disclosure] possible MS03-026 worm?"
    To: <full-disclosure@lists.netsys.com>
    Date: Sat, 2 Aug 2003 11:58:00 -0500
    
    
    

    Seems to be a possible worm based on the RPC/DCOM exploit making the
    rounds?

    puts these files in %systemdrive%
    rpc.exe
    rpctest.exe
    tftpd.exe
    worm.exe
    lolx.exe

    also in %windir%\system32
    lolx.exe
    dcomx.exe

    rpc.exe and dcomx.exe appear in the running tasks.

    I pulled samples of them and submitted to SARC.

    -Dave

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: tcpdumb: "Re: [Full-Disclosure] possible MS03-026 worm?"

    Relevant Pages

    • Re: Nadal made to work harder
      ... Puts the performance of those 2 Spanish clowns in ... intense in this second set. ... his previous rounds in perspective. ...
      (rec.sport.tennis)
    • Re: Nadal made to work harder
      ... rounds. ... Puts the performance of those 2 Spanish clowns in ... Not playing with the ...
      (rec.sport.tennis)
    • Re: Nadal made to work harder
      ... Puts the performance of those 2 Spanish clowns in ... intense in this second set. ... his previous rounds in perspective. ...
      (rec.sport.tennis)
    • Nadal made to work harder
      ... to win 4 games so far against Djokovic than he had been in the past 2 ... rounds. ... Puts the performance of those 2 Spanish clowns in ...
      (rec.sport.tennis)

  • Quantcast