nanog mailing list archives
Re: RPC errors
From: Chris Reining <creining () packetfu org>
Date: Mon, 11 Aug 2003 16:35:41 -0500
On Mon, Aug 11, 2003 at 04:17:53PM -0400, Sean Donelan wrote:
On Mon, 11 Aug 2003, Jack Bates wrote:I'm showing signs of an RPC sweep across one of my networks that's killing some XP machines (only XP confirmed). How wide spread is this at this time. Also, does anyone know if this is just generating a DOS symptom or if I should be looking for backdoors in these client systems?http://isc.sans.org/diary.html?date=2003-08-11 The worm uses the RPC DCOM vulnerability to propagate. One it finds a vulnerable system, it will spawn a shell and use it to download the actual worm via tftp. The name of the binary is msblast.exe. It is packed with UPX and will self extract. The size of the binary is about 11kByte unpacked, and 6kBytes packed:
I have a copy of this worm at http://www.packetfu.org/malware/msblast.zip
Attachment:
_bin
Description:
Current thread:
- RPC errors Jack Bates (Aug 11)
- Re: RPC errors Sean Donelan (Aug 11)
- Re: RPC errors Jack Bates (Aug 11)
- Re: RPC errors Dominic J. Eidson (Aug 12)
- Re: RPC errors Crist Clark (Aug 12)
- Re: RPC errors Dominic J. Eidson (Aug 12)
- Re: RPC errors Jack Bates (Aug 11)
- Re: RPC errors Chris Reining (Aug 11)
- Re: RPC errors Sean Donelan (Aug 11)
- Re: RPC errors /m (Aug 11)
- Re: RPC errors william (Aug 11)
- <Possible follow-ups>
- RE: RPC errors Drew Weaver (Aug 11)
- RE: RPC errors McBurnett, Jim (Aug 11)
- RE: RPC errors Mike Damm (Aug 11)
- RE: RPC errors Kevin Houle (Aug 11)
- RE: RPC errors Drew Weaver (Aug 11)
- RE: RPC errors Brennan_Murphy (Aug 11)
- Re: RPC errors John Dvorak (Aug 11)
- RE: RPC errors Bob German (Aug 11)