RE: msblast.exe available

David.Pavone_at_apcc.com
Date: 08/12/03

  • Next message: Jordan Wiens: "RE: MSBLASTER Infecting despite 03-026 patch?"
    To: s.wizard@boundariez.com
    Date: Tue, 12 Aug 2003 05:00:40 -0400
    
    

    Symantec has done a pretty good job:

    <-Clip->
    Symantec has been tracking its activity and is
    currently conducting analysis/full disassembly of the malicious code,
    which has been named "Blaster". The results of our analysis are
    being made available to the public at the following location:

    https://tms.symantec.com/members/AnalystReports/030811-Alert-DCOMworm.pdf

    It is expected that this report will be updated frequently as more
    information is discovered. Readers are advised to download/refresh
    it throughout the day to ensure that any new information is not missed.

    David Mirza Ahmad
    Symantec

    <end-clip->

    David Pavone
    Senior IT Systems Analyst - Infrastructure Services Group
    david.pavone@apcc.com
    1-401-789-5735 Ext. 2036
    APC - American Power Conversion

    |---------+--------------------------->
    | | "Sekurity |
    | | Wizard" |
    | | <s.wizard@bounda|
    | | riez.com> |
    | | |
    | | 08/11/2003 11:27|
    | | PM |
    | | |
    |---------+--------------------------->
    >-------------------------------------------------------------------------------------------------------------------------------|
      | |
      | To: <incidents@securityfocus.com> |
      | cc: |
      | Subject: RE: msblast.exe available |
    >-------------------------------------------------------------------------------------------------------------------------------|

    Has anyone dis-assembled this puppy yet, to get a good idea of what the
    heck it does, exactly? I'm working on it and would like to collaborate
    with anyone?

    ./Wiz

    -----Original Message-----
    From: Chris McNab [mailto:chris.mcnab@trustmatta.com]
    Sent: Monday, August 11, 2003 6:47 PM
    To: bugtraq@securityfocus.com
    Cc: incidents@securityfocus.com
    Subject: msblast.exe available

    Hi,

    This is publicly available for analysis from:

    www.trustmatta.com/downloads/msblast.exe

    Regards,

    Chris

    Chris McNab
    Technical Director

    Matta Consulting
    18 Noel Street
    London W1F 8GN

    08700 77 11 00

    www.trustmatta.com

    ------------------------------------------------------------------------

    ---
    ------------------------------------------------------------------------
    ----
    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    

  • Next message: Jordan Wiens: "RE: MSBLASTER Infecting despite 03-026 patch?"

    Relevant Pages

    • RE: Strange servicepack.exe file (not service.exe) found.
      ... One of the things I have noticed with Symantec (and I am sure other vendors ... >> detailed information about your submission is required. ... >> README.TXT does not appear to contain malicious code. ... please contact Symantec Technical Support ...
      (Incidents)
    • Re: [normal] RE: [Full-Disclosure] Re: Secure.dcom.exe
      ... I finally got a reply back from symantec regarding the file you posted to the list, ... Please contact your Technical Support representative if more detailed information about your submission is required. ... that you have submitted and found no evidence of malicious code. ...
      (Full-Disclosure)
    • Re: [normal] RE: [Full-Disclosure] Re: Secure.dcom.exe
      ... I finally got a reply back from symantec regarding the file you posted to the list, ... Please contact your Technical Support representative if more detailed information about your submission is required. ... that you have submitted and found no evidence of malicious code. ...
      (Full-Disclosure)
    • Re: [normal] RE: [Full-Disclosure] Re: Secure.dcom.exe
      ... I finally got a reply back from symantec regarding the file you posted to the list, ... Please contact your Technical Support representative if more detailed information about your submission is required. ... that you have submitted and found no evidence of malicious code. ...
      (Incidents)
    • Re: msblast.exe available
      ... > Symantec has been tracking its activity and is ... > currently conducting analysis/full disassembly of the malicious code, ... > David Mirza Ahmad ... > Chris McNab ...
      (Incidents)

  • Quantcast