Re: Strange activity in IIS logs

From: Craig Janssen (cjanssen_at_mail.millikin.edu)
Date: 10/10/03

  • Next message: Jimi Thompson: "Re: Would you bet your life on your security?"
    Date: Fri, 10 Oct 2003 13:36:42 -0500
    To: <security-basics@securityfocus.com>, <keydet89@yahoo.com>
    
    

    There were some references to Code Red that I found, but that's probably due to the AAAAAAAAAAAAAAAAAA string. I have never seen a virus that used the SEARCH http command in conjunction with an overlong string, such as what this one apparently uses.

    I'm pretty sure this is a virus of some kind, I was just curious if anyone else had run into this before. I didn't experience any problems with the server following this activity, so whatever it's trying to exploit it's obviously patched against it.

    Craig

    >>> H Carvey <keydet89@yahoo.com> 10/10/03 05:59AM >>>
    In-Reply-To: <sf852434.064@mail.millikin.edu>

    >Has anyone seen anything similar to this in their IIS W3SVC logs? It
    >sure looks like a buffer overflow attempt of some kind, but I'm not
    >familiar with it. I have googled and SARC'd, and didn't come up with
    >anything definite:

    Ok, but what have you come up with? Maybe some of the indefinite stuff will give a clue. Have you tried BugTraq or VulnDev?

    >2003-10-08 09:03:42 <origin IP> - <destination ip> 80 SEARCH
    >/-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
    >
    >... and so on...
    >
    >AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    >|-|0|404_Object_Not_Found 404 -
    >
    >Almost looks like a different spin on Code Red or Nimda. Is this a new
    >virus, or has someone else heard of this?

    Interesting. Doesn't look anything like Nimda...but does look a little like CR.

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Jimi Thompson: "Re: Would you bet your life on your security?"

    Relevant Pages

    • Re: Virus Scan on uploads
      ... I was wondering how would one go about running virus scan on an ... application where users upload their documents? ... i perform a virus scan similar to that of Yahoo Mail? ... public String scanthrows IOException { ...
      (comp.lang.java.help)
    • Re: [Full-Disclosure] Show me the Virrii!
      ... There are not really any virus standards. ... The only heuristic pattern I have ... The presence of "NetBus" string in all versions of the ... including packed files -easy heuristics;) ...
      (Full-Disclosure)
    • Re: Obtaining a "Faux Virus"?
      ... virus but doesn't act like a virus ... That string was designed for exactly that purpose. ... and most AV programs will have the signature in their ... Dustin Cook [Malware Researcher] ...
      (alt.comp.anti-virus)
    • Re: [Dialog] Virus on Compact
      ... It is similar to the scenario of the test string provided by the ... Are you saying that because the virus scanner doesn't recognise the ... No, I am saying that PRE compaction, there was no string in the data file ... to trigger the warning. ...
      (news.software.readers)
    • Re: [Dialog] Virus on Compact
      ... Between saving the world and having a spot of tea SINNER said ... It is similar to the scenario of the test string provided by the ... Are you saying that because the virus scanner doesn't recognise the ...
      (news.software.readers)