Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 3rd, 2003, 10:36 PM
AplusWebMaster AplusWebMaster is offline
Frequent Poster
 
Join Date: Jun 2003
Location: Philadelphia, PA, USA
Posts: 239
Default Backdoor.IRC.Cirebot...installs a backdoor Trojan Horse.

FYI...from Symantec:
http://securityresponse.symantec.com...c.cirebot.html
"...Backdoor.IRC.Cirebot is a threat which exploits the Microsoft DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026) to install a backdoor Trojan Horse on vulnerable systems. Backdoor.IRC.Cirebot consists of a Backdoor component, and a Hacktool component which installs the backdoor on systems which are vulnerable to the exploit.
Signs of infection: the existence of the files c:\rpc.exe, c:\rpctest.exe, or c:\lolx.exe.
Signs that a network is being attacked: traffic on port 445 to sequential IP addresses.
Signs that an attack has succeeded (allowing a remote shell and downloading of the backdoor): port 57005 open; an ftp connection on port 69..."

- See also this thread: http://www.wilderssecurity.com/showt...77483#msg77483.
__________________
AplusWebMaster ~ www.apluswebmaster.net
Are you up to date or vulnerable to Hackers?
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:07 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums