RE: New SASSER Worm varient ???

"James C Slora Jr" <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
Steve Carey wrote:

> Anyone seeing a new varient of SASSER using port 4445 as the 
> back door port?  I have had systems infected that were 
> patched (and verified).

Do you have any captures to share, and do you know how the systems were
infected?

There is a new Sasser variant listed at Trend Micro, but it does not appear
to match your description.
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SASSER.
G&VSect=T

Theirs opens TCP 9996 as the initial shell backdoor and does not appear to
do anything that would nail a patched system.

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.