Security Incidents mailing list archives

eurocalculator.exe analised a bit more


From: Rik van Riel <riel () CONECTIVA COM BR>
Date: Wed, 4 Oct 2000 17:09:36 -0300

[abuse () hotmail com notified because it looks like an address
on your server is being used as info gathering address for
what might be a new "email virus"]

---------- Forwarded message ----------
Date: Wed, 04 Oct 2000 17:09:59 -0300
From: Marcos B. Souza <balreira () catolico com br>
To: riel () CONECTIVA COM BR


       Hi Rik !

        Please, forward this information to the list.  I think it´ll be very
useful. Regards, Marcos

       This bo2k server disguised as eurocalculator.exe has the following
characteristics:

   1) Server binds to TCP port 55555
   2) Communication client-server uses standard XOR encryption with
password "game".
   3) Upon successful installation & execution, it sends an email to
funguscrack () hotmail com via smtp mail.hotmail.com
   4) After successful installation the executable name becomes UMGR32.EXE.
In the services list it will appear as "Remote Administration Service"
   5) It´s not configured to run on startup


     So, a netstat -an will show whether port 55555 is in listening state.
Hope this helps.


Current thread: