Re: [Full-disclosure] NT4 worm



Are the machines you have experience especially NT4.0 machines?
It appears that one of the PoC's (public on Monday 28th Aug) lists the following information:
"Systems Affected:
* Microsoft Windows 2000 SP0-SP4
* Microsoft Windows XP SP0-SP1
* Microsoft Windows NT 4.0"

but reportedly it is tested against XPSP1 and W2KSP4 systems.

I believe that fully patched NT4SP6a/SRP shipped with Netapi32.dll is affected.

- Juha-Matti


"Geo." <geoincidents@xxxxxxx> wrote:

Has anyone seen a writeup on this new NT4 worm that's spreading via port 139
MS06-040 yet? I'm seeing customers getting hit by it but I haven't seen any
real mention of it anywhere yet. It appears to run two CMD.EXE hidden
windows and sucks up all the cpu in the infected systems trying to spread.
I've also seen one customer who found csrsc.exe on the machine after the
worm hit them.

I did manage to find out once it exploits a machine it uses ftp.exe to
connect back to the infecting host and transfer something but I've not had
time to really dig into this thing. Hoping someone else has already. Looks
like it's spreading pretty quick

http://isc.incidents.org/port_details.php?port=139&repax=1&tarax=2&srcax=2&p
ercent=N&days=40


Geo.


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: Determine current boot.ini partition booted into
    ... about what boot.ini entry I selected at the time of bootup. ... when you've seen 14-15 machines, all like this, you'll have no clue as ... to what entry you selected at boot up... ... >> Microsoft Windows XP Professional ...
    (microsoft.public.win2000.general)
  • Re: Problem Reinstalling Windows XP
    ... It wouldn't boot from any of them, though all worked fine in other machines. ... It did boot & allow me to install from a COPY of one of the CDs. ... I tried using both the Microsoft Windows ...
    (microsoft.public.windowsxp.general)
  • Microsoft update
    ... I need to know how come all machines in my network except mine only show ... microsoft windows familly in the new and much improved microsoft update. ... I installed it on my own 3 machines and it's working great. ... I got really excited when I installed the new and improved microsoft update ...
    (microsoft.public.windowsupdate)
  • Java Errors
    ... I noticed I was receiving JAVA script errors a few weeks ago on all my ... Microsoft Windows XP SP2 machines. ...
    (microsoft.public.scripting.jscript)
  • JavaScript Errors
    ... I noticed I was receiving JAVA script errors a few weeks ago on all my ... Microsoft Windows XP SP2 machines. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)