RE: New SASSER Worm varient ???
"Carey, Steve T GARRISON" <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <2A39B3177D295F4583659FD74E26FE71E021ED@redstone817.ad.redstone.army.mil> |
Actually may not be SASSER. Turns out it is an IRCBOT that takes advanatage of a vulnerability in LSASS. Don't think it is the same vulnerability as previous reported by Microsoft, these systems were patched for that vulnerability and had current anti-virus. I have packet captures of the overflow, or at least most of it, don't have the packets for the traffic to port 4445 (my sensor I used to see this is pretty much maxed out and the data 'rolled' on me). Haven't looked at the systems myself to see what I can find, will try and do that this week. Steve Carey ________________________________ From: [email protected] on behalf of James C Slora Jr Sent: Fri 8/27/2004 5:01 PM To: 'Intrusions List (GCIA Practicals)' Subject: RE: [Intrusions] New SASSER Worm varient ??? Steve Carey wrote: > Anyone seeing a new varient of SASSER using port 4445 as the > back door port? I have had systems infected that were > patched (and verified). Do you have any captures to share, and do you know how the systems were infected? There is a new Sasser variant listed at Trend Micro, but it does not appear to match your description. http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SASSER. G&VSect=T Theirs opens TCP 9996 as the initial shell backdoor and does not appear to do anything that would nail a patched system. _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions