RE: New SASSER Worm varient ???

Andy Wagoner <[email protected]>
Newsgroups gmane.comp.security.intrusions
Organization LURHQ
Message-ID <1093643956.16662.43.camel@debstar>
My understanding is that bling.exe is an Rbot variant, and msxml32.exe
acts very similar to it.


On Fri, 2004-08-27 at 15:49, Newell, Tim wrote:
> Had the following report from someone at another organization this
> morning, don't have any further details:
> 
> "[a/v vendor] did not know anything about it until we spoke to them
> yesterday afternoon.  We have sent them the files and they have
> confirmed it.  It attacks the lsass issus that microsoft identified a
> few months back.(Port 445)  There are 2 different processes that load.
> bling.exe or msxml32.exe.  These are then loaded from the
> hkey_local/...../run as XML Service.  Its flooding our network"
> 
> - Tim
> 
> Tim Newell 
> Security & Business Continuity
> xwave, Halifax, NS 
> Phone    (902) 495-2836  
> Cellular  (902) 222-8815  
> Fax         (902) 495-2095  
> [email protected] 
> 
> 
> -----Original Message-----
> From: [email protected]
> [mailto:[email protected]] On Behalf Of Carey, Steve T
> GARRISON
> Sent: Friday, August 27, 2004 12:40 PM
> To: [email protected]
> Subject: [Intrusions] New SASSER Worm varient ???
> 
> 
> Anyone seeing a new varient of SASSER using port 4445 as the back door
> port?  I have had systems infected that were patched (and verified).
>  
> STEVEN T. CAREY
> LCIRT-R
> (256) 876-5811
> DSN 746-5811
> Cell (256) 759-9767
> [email protected]
>  
> _______________________________________________
> Intrusions mailing list
> [email protected]
> http://www.dshield.org/mailman/listinfo/intrusions
> _______________________________________________
> Intrusions mailing list
> [email protected]
> http://www.dshield.org/mailman/listinfo/intrusions
-- 


Andy Wagoner GSEC, GCIA
Information Security Analyst
843.903.4376
http://www.lurhq.com

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.