FW: Lioten Worm 135-139 and 445

From: Pricher Jeffrey Contr AFCA/GCF (jeffrey.pricher@scott.af.mil)
Date: 12/17/02

  • Next message: dev: "Re: fswserv.html ????"
    Date: Tue, 17 Dec 2002 11:43:33 -0600
    From: "Pricher Jeffrey Contr AFCA/GCF" <jeffrey.pricher@scott.af.mil>
    To: <incidents@securityfocus.com>
    
    

    This came from the incidents.org list this am. Figured I'd pass it along since I've seen some discussion about port 445 probes come up lately.
    J. Pricher

    -----Original Message-----
    From: James C Slora Jr [mailto:Jim.Slora@phra.com]
    Sent: Tuesday, December 17, 2002 8:45 AM
    To: intrusions@incidents.org
    Subject: Lioten Worm 135-139 and 445

    Incidents.org reports the Lioten worm as active. AV vendor sites report its
    existence but show no infections. It spreads on NT/W2K through TCP and UDP
    on ports 135-139 and 445 - through NetBIOS. It uses short brute force
    password attacks on all enumerated users found during a null session probe,
    and installs itself as %system%\Iraq_oil.exe.

    Has anyone seen this worm in the wild? Any packet captures?

    http://www.sarc.com/avcenter/venc/data/w32.hllw.lioten.html (signature not
    released yet)
    http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_LIOTEN.
    A (signature released)
    http://vil.nai.com/vil/content/v_99897.htm (signature not released yet)

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management
    and tracking system please see: http://aris.securityfocus.com



    Relevant Pages

    • Re: AdAware, SpyBot S &D, etc. + leave PC connected to Internet
      ... > non-critical patches. ... just did stealth scan again nd the result is shown below. ... FTP DATA 20 BLOCKED This port has not responded to any of our probes. ...
      (comp.security.firewalls)
    • Re: Need help, ask for your advice
      ... Signature analysis was the first method implemented in intrusion detection. ... BlackIce to open port 1434 and enabled IDS on the open port. ... data of network traffic, otherwise known as protocols. ...
      (comp.security.firewalls)
    • Re: port 22 scans + 53 scans
      ... port 22 scans + 53 scans ... The tcp:53 probes seem to be some sort of distance-metrics/load ... balancing activity. ... > If firewalls are dropping these packets, ...
      (Incidents)
    • Re: now wtf is this good for (Was: Re: ISP blocking smtp port and a way how to solve the issue)
      ... > crap as it does fsck up the display of messages. ... > way to include a signature without fscking up the display unless you ... The port seems unusable at the moment. ...
      (comp.unix.bsd.freebsd.misc)
    • RE: TCP port 5000 syn increasing
      ... > port scans. ... IMHO it has *never* been sufficient to simply count and analyse probes ... The ability to say "12.53 % of unsolicited traffic at my network ... Security Linux, the comprehensive security solution that combines six ...
      (Incidents)