Wilders Security Forums  

Go Back   Wilders Security Forums > Official Colasoft Support Forum > Capsa Network Analyzer
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 3rd, 2011, 11:21 PM
Colasoft Support's Avatar
Colasoft Support Colasoft Support is offline
Colasoft Moderator
 
Join Date: Dec 2007
Posts: 220
Default Is there any Mydoom virus in your network? Use this filter to capture them

This is an advanced Capsa capture filter to capture only the traffic of the notorious and aged Mydoom virus. By using this filter, all packets matching the filter's conditions will be displayed and you know there is Mydoom virus movements in your network.

Now download the filter and follow the instructions below to load and apply the filter.

Download Mydoom worm virus filter: mydoom-filter.zip

How to use this filter?
  1. Download the filter file and decompress it
  2. Run Capsa (if it's not installed, get one free)
  3. On the Start Page, click Set Capture Filter link on the upper right corner
  4. Click Import... icon down below the open Filter window
  5. Select the filter file and click Open
  6. Click No when see "Do you want to empty the existed packet filter in current list?"
  7. Then check the Accept checkbox back on the Filter window
  8. Click OK
  9. Click Start button to start a capture

What is Mydoom worm?

Defination from Wikipedia: Mydoom, also known as W32.MyDoom@mm, Novarg, Mimail.R and Shimgapi, is a computer worm affecting Microsoft Windows. It was first sighted on 26 January 2004. It became the fastest-spreading e-mail worm ever (as of January 2004), exceeding previous records set by the Sobig worm.
__________________
Colasoft LLC
Official Website: http://www.colasoft.com
Contact Support: http://www.colasoft.com/support/contact/index.php
Follow us on twitter: colasoft
  #2  
Old July 6th, 2011, 09:37 PM
Spooony's Avatar
Spooony Spooony is offline
Frequent Poster
 
Join Date: Apr 2011
Posts: 514
Default Re: Is there any Mydoom virus in your network? Use this filter to capture them

Quote:
Originally Posted by Colasoft Support
This is an advanced Capsa capture filter to capture only the traffic of the notorious and aged Mydoom virus. By using this filter, all packets matching the filter's conditions will be displayed and you know there is Mydoom virus movements in your network.

Now download the filter and follow the instructions below to load and apply the filter.

Download Mydoom worm virus filter: Attachment 227936

How to use this filter?
  1. Download the filter file and decompress it
  2. Run Capsa (if it's not installed, get one free)
  3. On the Start Page, click Set Capture Filter link on the upper right corner
  4. Click Import... icon down below the open Filter window
  5. Select the filter file and click Open
  6. Click No when see "Do you want to empty the existed packet filter in current list?"
  7. Then check the Accept checkbox back on the Filter window
  8. Click OK
  9. Click Start button to start a capture

What is Mydoom worm?

Defination from Wikipedia: Mydoom, also known as W32.MyDoom@mm, Novarg, Mimail.R and Shimgapi, is a computer worm affecting Microsoft Windows. It was first sighted on 26 January 2004. It became the fastest-spreading e-mail worm ever (as of January 2004), exceeding previous records set by the Sobig worm.
anything for conflicker?
__________________
I've discovered that people on IRC don't get offended or riled up by racism, nor politically incorrect jokes, nor feminism, nazism, nor goatse, or even tubgirl, not even jokes about 9/11 get a rise out of anybody but as soon as I tell somebody that macs are better than PCs, things get ugly.
  #3  
Old July 10th, 2011, 10:28 PM
Colasoft Support's Avatar
Colasoft Support Colasoft Support is offline
Colasoft Moderator
 
Join Date: Dec 2007
Posts: 220
Default Re: Is there any Mydoom virus in your network? Use this filter to capture them

Hi Spooony,

On the web, we know Conficker worm is rampant and it has the following features:

Domain controllers respond slowly to client requests.
System network gets unusually congested. This can be checked with network traffic chart on Windows Task Manager.
Port 445/TCP scanning (A/B)
Multicast UPnP requests
High-port TCP and UDP P2P Activity
Abnormal DNS lookup activity


--ConfickerWorkingGroup.org

The simplest way to find conficker is to start from DNS queries. Because the DNS queries are random, it's hard to offer a universal filter. We can find clues from the Log tab in Capsa, when you see lots of DNS error items, you should pay attention to them always. They may not be conficker, but definitely something is wrong.

This picture shows the DNS activities of a typical Conficker worm.

Name:  Picture1.jpg
Views: 422
Size:  144.5 KB

You may notice that the host sent DNS packets quickly and lots of error returned.
__________________
Colasoft LLC
Official Website: http://www.colasoft.com
Contact Support: http://www.colasoft.com/support/contact/index.php
Follow us on twitter: colasoft
  #4  
Old July 10th, 2011, 11:06 PM
Colasoft Support's Avatar
Colasoft Support Colasoft Support is offline
Colasoft Moderator
 
Join Date: Dec 2007
Posts: 220
Default Re: Is there any Mydoom virus in your network? Use this filter to capture them

Resource: Protecting Against the Rampant Conficker Worm:

http://www.pcworld.com/article/15787...cker_worm.html
__________________
Colasoft LLC
Official Website: http://www.colasoft.com
Contact Support: http://www.colasoft.com/support/contact/index.php
Follow us on twitter: colasoft
  #5  
Old July 11th, 2011, 07:26 PM
Spooony's Avatar
Spooony Spooony is offline
Frequent Poster
 
Join Date: Apr 2011
Posts: 514
Default Re: Is there any Mydoom virus in your network? Use this filter to capture them

Quote:
Originally Posted by Colasoft Support
Hi Spooony,

On the web, we know Conficker worm is rampant and it has the following features:

Domain controllers respond slowly to client requests.
System network gets unusually congested. This can be checked with network traffic chart on Windows Task Manager.
Port 445/TCP scanning (A/B)
Multicast UPnP requests
High-port TCP and UDP P2P Activity
Abnormal DNS lookup activity


--ConfickerWorkingGroup.org

The simplest way to find conficker is to start from DNS queries. Because the DNS queries are random, it's hard to offer a universal filter. We can find clues from the Log tab in Capsa, when you see lots of DNS error items, you should pay attention to them always. They may not be conficker, but definitely something is wrong.

This picture shows the DNS activities of a typical Conficker worm.

Attachment 228031

You may notice that the host sent DNS packets quickly and lots of error returned.
Hi
Thanks man for the wonderfull reply. Even my wife understood it (and she only knows how to go on facebook and start Itunes).

Scary thing about conflicker is it can sit and wait for years awaiting new instructions and a lot of users run their own private network these days. And unfortunately or fortunately depends what way you look at it systems are so good and quick these days so users who finds malware on a pc go by approach format that will remove a worm from my pc which is connected in a network. Then some time later they ask how they got infected again.
__________________
I've discovered that people on IRC don't get offended or riled up by racism, nor politically incorrect jokes, nor feminism, nazism, nor goatse, or even tubgirl, not even jokes about 9/11 get a rise out of anybody but as soon as I tell somebody that macs are better than PCs, things get ugly.
 

Wilders Security Forums > Official Colasoft Support Forum > Capsa Network Analyzer « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:57 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums