Re: [Full-Disclosure] anyone seen this worm/trojan before?

From: Axel Pettinger (api_at_epost.de)
Date: 06/04/04

  • Next message: Jim Becher: "RE: [Full-Disclosure] anyone seen this worm/trojan before?"
    To: "Perrymon, Josh L." <PerrymonJ@bek.com>, full-disclosure@netsys.com
    Date: Fri, 04 Jun 2004 00:08:23 +0200
    
    

    "Perrymon, Josh L." wrote:
    >
    > I found this worm/ trojan on a laptop. Ran FPort and found the .exe.
    > Doesn't look like it propagates to other machines but rather communicates
    > with a compromised
    > web companies server using IRC. The compromised server has removed the IRC
    > service. Only sends RST packets back.
    >
    <snip>
    > I would like to know the attack vectors. I'm guessing LSASS.

    AntiVirus scanners identify our trojan as:

    BitDefender : Backdoor.SDBot.Gen
    Kaspersky : Backdoor.Rbot.gen
    McAfee : W32/Sdbot.worm.gen.g
    Symantec : W32.Spybot.Worm
    Trend Micro : WORM_SPYBOT.AP

    From a quick look at the file I'd say the following is the best
    description of that trojan. There're several attack vectors ...

    http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SPYBOT.AP&VSect=T

    Regards,
    Axel Pettinger

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Jim Becher: "RE: [Full-Disclosure] anyone seen this worm/trojan before?"

    Relevant Pages

    • Re: computer crashed
      ... I haven't been on IRC since. ... Suppose a trojan was ... It sounds like a CPU fault, since you haven't reported seeing any other ... startup messages or hearing any POST beeps. ...
      (alt.computer.security)
    • Re: computer crashed
      ... I haven't been on IRC since. ... Suppose a trojan was ... It sounds like a CPU fault, since you haven't reported seeing any other ... startup messages or hearing any POST beeps. ...
      (microsoft.public.security.virus)
    • Re: computer crashed
      ... >security hole. ... I haven't been on IRC since. ... Suppose a trojan was ... This does not sound like a computer security problem but ...
      (alt.computer.security)
    • Re: computer crashed
      ... >security hole. ... I haven't been on IRC since. ... Suppose a trojan was ... This does not sound like a computer security problem but ...
      (microsoft.public.security.virus)
    • Re: computer crashed
      ... I haven't been on IRC since. ... Suppose a trojan was ... >The monitor has a green light and a message on the screen. ...
      (microsoft.public.security.virus)

  • Quantcast