RE: New SASSER Worm varient ???
"James C Slora Jr" <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
Steve Carey wrote: > Anyone seeing a new varient of SASSER using port 4445 as the > back door port? I have had systems infected that were > patched (and verified). Do you have any captures to share, and do you know how the systems were infected? There is a new Sasser variant listed at Trend Micro, but it does not appear to match your description. http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SASSER. G&VSect=T Theirs opens TCP 9996 as the initial shell backdoor and does not appear to do anything that would nail a patched system. _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions