Jump to content

new MS04-011: Plexus.A worm


nellie2
 Share

Recommended Posts

This new worm attempts to spread in a number of different ways. It can spread by email, open email shares, or unpatched Microsoft security vulnerabilities (MS03-026 and MS04-011).

MS04-011: Plexus.A worm (email and Internet worm)

http://secunia.com/virus_information/9831/plexus/

http://www.symantec.com/avcenter/[email protected]

http://vil.nai.com/vil/content/v_126116.htm

http://www.trendmicro.com/vinfo/vir...e=WORM_PLEXUS.A

Article: Worm Exploits Multiple Windows Vulnerabilities

http://www.techweb.com/wire/story/TWB20040603S0007

Plexus.A worm - Characteristics

Subject of email: RE: order For you Hi, Mike Good offer. RE:

Name of attachment: SecUNCE.exe AtlantI.exe AGen1.03.exe demo.exe release.exe

Size of attachment: 16,208

Time stamp of attachment: n/a

Ports: TCP 1250, a random TCP port

Shared drives: Copies itself to network shares

Target of infection: Copies itself to KaZaA shared folder

Methods of Infection - Retrieves email address from files with .htm, .html, .php, .tbb, and .txt extensions, on all fixed drives from C through Y.

* Uses its own SMTP engine to send itself to the email addresses it finds.

* Spreads through network shares and the Kazaa file-sharing network.

* Attempts to propagate by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS04-011)

* DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026) through TCP ports 135 and 445.

* Listens on TCP port 1250 and a random TCP port

source

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy