Security Incidents mailing list archives
eurocalculator.exe analised a bit more
From: Rik van Riel <riel () CONECTIVA COM BR>
Date: Wed, 4 Oct 2000 17:09:36 -0300
[abuse () hotmail com notified because it looks like an address
on your server is being used as info gathering address for
what might be a new "email virus"]
---------- Forwarded message ----------
Date: Wed, 04 Oct 2000 17:09:59 -0300
From: Marcos B. Souza <balreira () catolico com br>
To: riel () CONECTIVA COM BR
Hi Rik !
Please, forward this information to the list. I think it´ll be very
useful. Regards, Marcos
This bo2k server disguised as eurocalculator.exe has the following
characteristics:
1) Server binds to TCP port 55555
2) Communication client-server uses standard XOR encryption with
password "game".
3) Upon successful installation & execution, it sends an email to
funguscrack () hotmail com via smtp mail.hotmail.com
4) After successful installation the executable name becomes UMGR32.EXE.
In the services list it will appear as "Remote Administration Service"
5) It´s not configured to run on startup
So, a netstat -an will show whether port 55555 is in listening state.
Hope this helps.
Current thread:
- eurocalculator.exe analised a bit more Rik van Riel (Oct 04)
