Security Incidents mailing list archives

Re: new scanner tool or blind luck?


From: "T. Esting" <t_esting () excite com>
Date: Thu, 14 Sep 2000 14:21:30 -0700

  Nope, they were strictly port 139 in every case.

On Mon, 14 Aug 2000 01:40:35 +0100, Thierry wrote:


 Hello,
 This could be Win32.Chainsaw

 NAME: Win32.Chainsaw v1.00
 TYPE: NetBios/SubSeven/NetBus worm.
 AUTHOR: T-2000 / Immortal Riot.
 E-MAIL: T2000_ () hotmail com
 PAYLOAD: Sector trashing.

 FEATURES:
 - Disables ZoneAlarm firewall.
 - Not visible in 9x tasklist.
 - Sends usenet message on installation.
 - DoS'es random hosts on 31st of any month.
 - Anti-debugging code.

 Randomly scans the Internet for hosts running either SubSeven 2, NetBus
1, or
 NetBios, and then installs itself in the systems it can get access to.
It's main
 payload is
 to IGMP DoS random Internet hosts on every 31st of the month, which will
BSOD
 every
 released version of Windoze 95/98 that isn't patched or firewalled.

 ---> infos found on TLSecurity

 So the question is if you also noticed scans on port 12345 (netbus) and
1243 (If
 my memory is good) (subseven) from the same IP ranges, if yes, this could
be the
 explanation for it.

 Thierry
 http://www.purge-it.com/?incidents






_______________________________________________________
Say Bye to Slow Internet!
http://www.home.com/xinbox/signup.html


Current thread: