W32.Welchia.Worm studying

From: kowts (kowts_at_freesurf.fr)
Date: 10/29/03


Date: Wed, 29 Oct 2003 12:41:08 +0100

Hi All,

Does anyone did a research or know how this malware made the HTTP request
with the WebDav of MicroSoft?

Anyone know a web site talking about that?

Additionally, it also uses a WebDAV exploit in order to propagate to
vulnerable systems. For detailed information about the said exploit, please
refer to the following Microsoft Web page:

  Microsoft Bulletin MS03-007

Using these exploits, it sends a shell code to a vulnerable system, which in
turn will execute a remote shell on the target system. The remote shell
connects to a random selected port between port 666 to port 765 of the
infected host where it receives commands to download the worm copy via TFTP.

Thanks for your help

Kowts.



Relevant Pages

  • RE: SBS 2003 Reporting - error message
    ... I have an SBS server with the same issue and tried Crina's suggestion below ... We have a web site that is running on port 80 so I changed ... If I change the DWS back to port 80, ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: Website Port Assignment
    ... I was able to get this to work after switching the site to port 80 on an XP machine. ... customize web site. ... This newsgroup is primarily for issues involving deployment, configuration, ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • RE: default
    ... If you've configured other web sites to listen on port 80, ... Right click the web site and click Properties. ... Microsoft CSS Online Newsgroup Support ... This posting is provided "AS IS" with no warranties, ...
    (microsoft.public.windows.server.sbs)
  • RE: Website Port Assignment
    ... customize web site. ... This newsgroup is primarily for issues involving deployment, configuration, ... client and use 80 port to test this issue. ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • [NT] Microsoft Data Access Components (MDAC) Function Code Execution (MS06-014)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... Microsoft Data Access Components Function Code Execution ... for the Internet security zone to prompt before running ActiveX controls. ...
    (Securiteam)