Security Incidents mailing list archives

Re: Workstations trying to GET /download/IEService215.chm HTTP/1.1 fr om 67.109.249.3


From: Andy <brother_wolf () btopenworld com>
Date: Sat, 10 Jul 2004 12:19:19 +0100 (BST)

there are some trojans that use chm exploits to
install themselves.

here's what a chm exploit is:
http://www.pandasoftware.com/virus_info/encyclopedia/overview.aspx?idvirus=45119

you might have some sort of download.trojan.

regards

Andy

--- "Humes, David  G." <David.Humes () jhuapl edu> wrote:
Starting around July 8th we noticed workstations
trying to access
67.109.249.3 on port 80 and do a

GET /download/IEService215.chm HTTP/1.1

Analysis of the users' browsing activity did not
reveal any pattern that
would suggest that the activity was user-initiated. 
We suspect that this is
something trying to "phone home", but not sure quite
what.  A reverse lookup
of the IP just returns 67.109.249.3.ptr.us.xo.net,
and whois just tells me
that it belongs to XO.  Has anyone else seen this
and know what it is?

Thanks.

--Dave

 


Current thread: