-
January 27th, 2004, 05:02 PM
#21
To answer who asked why it was on Windows: The whole point of this virus, it seems, is to DDoS the SCO site, undoubtedly because of their attacks on Torvalds of recent. Linux users, generally, are much too savvy to 1) download a file attachment they don't know the send of or 2) wait more than one minute to patch their system. But, Windows users a lot of the time leave their computers succeptible to attacks because of a lot of their ignorance, and are thus better targets in this market... basically, the writers think they're too dumb to understand what's going on.
-
January 27th, 2004, 05:03 PM
#22
Originally posted here by 576869746568617
Not quite, DjM. See my post above. The symantec writeup does indeed say that the virus ignores .edu addresses.
I think that's what I said
Symantec does mention that it will bypass .edu accounts
Cheers:
-
January 27th, 2004, 05:07 PM
#23
I stand corrected....It's early and my mailserver's ate up like swiss cheese with this blasted worm! I misread your post.
My apologies
Windows 9x: n. A collection of 32 bit extensions and a graphical shell for a 16 bit patch to an 8 bit operating system originally coded for a 4 bit microprocessor. Written by a 2 bit company that can\'t stand 1 bit of competition.

-
January 27th, 2004, 05:16 PM
#24
Senior Member
Wow... this thing sounds serious.
I didn't catch any worm for last 4 years because:
- I don't open attachments of any kind if I don't expect them
- If it is espected, and it is some kind of animated stuff, I duble check it before I start it
- My AV is checking for updates automaticaly, and install them at once!
- I check out antivirus sites oftem for fast spreading viruses
- I run Windows Update at least once per week
And I don't still feel safe... Just remeber that damn Blaster thing...
Ikalo
------
Make your knowledge your deadliest weapon.
-
January 27th, 2004, 05:29 PM
#25
I do pretty much the same, but when the AV updates at one time, and the definitions come out after the update, you still aren't safe. Automation helps, but it's not a cure all.
Oh yeah, all you guys with IDS, here's the IDS signature for the trojan portion of the worm. This one is specific to Symantec IS, Manhunt, and SCS (IDS Signature provided by Symantec)....I'm looking for one one for snort....If I can't find one, I'll write one myself (unless Q.o.D. beats me to it!) I will post it here.
Symantec IDS Signature:
*******************start file********************
alert tcp any any -> any 80 (msg:"W32_Novarg_SCO_DOS"; content:"GET / HTTP/1.1|0d0a|Host: www.sco.com|0d0a0d0a|"; offset:0; dsize:37
*************EOF*********************
-
January 27th, 2004, 05:40 PM
#26
Junior Member
eSAFE and Novarg (MyDOOM, mimail.q)
Hi,
We got eSAFE installed and running fine, removing every attachment which contains a zip, exe, bat, and so on...
But here is what we see when eSAFE removes a ZIP attachment containing a threat.
------------------------------------------------------
*** eSafe detected a hostile content in this email and removed it. ***
/readme.zip/readme.txt .pif Msg #705 - The file type pif is on the Restricted List.
T-ˆ÷ŽŠŒåd~õIcaøc;WLóû~rÍ>gLÒ ë¢\Røi^z…q<è0Ñ{ˆ gD”g{ªe19Ð
&þèCÖ)à¿.NüZµÝN¿æ™œ«¯)ª/J×ÇèsSWÙyûm"µó¡ôö§«
KïižrE¹úoÚHdºp÷§EÞ~¯ÅYŠÚÁK^{r´ZùD¼8׊F-"ýÛs}Ït²™ö7jVéh'¶½„k5EÛØ:ãm‘bÕôo®ê*É$–ר}©d}UËjθ~’ãÀ÷þ?²-îO|²2wf²Ž”ç]ff^&_s9BÆŽŽ-׈6i]…H˪엫sg
æPclÛA•Mð%q 8U!RÍŠá’4¤Dàüwï_„æ‚M…Ó5ˇ2%„Åë0¥èøïÛ.«!mvB‘õüz×ïÉ•çÇé¯ÄvîÏ)ÍH_Í4Œkû‚¼ igŸÕMù>¾å2i7ñn1`
5ïmüúZ8óŒ9oлy6B\ìr ÈÇMXY#·Žò}â]8ÃãЯ&߯YÉ-QMo PÇ Õ
ÅülÙÍ‘jáPPöàþwñJ½C%X¿»ì‚¯#Ò– ñ}GØë¨27Sòß|$ ücC~-AÊK~YÓ¸ÔPÏ”gmÑQxL† o‡Ÿ|UTÁ,]~‰šÊ’²[çÖ-3•¿±Á ÏVÈüÎyA³ð]ÞRM/írÛ^ùѽ„n>®8–‚¿Z”;;Ñ¢*MI¡}vÌok“
~0èêç Õ |`ó~©)
ùa:곫Z3ó~Ö”¥BUÈzÄ×_&¶$Š
à,F¤ç
!¿(õÀ®ÛÞŒƒÖŽ87‰jÏ̾C ký©tm{Ç·zõ?©Sš/é“·<ÍÌ´žyã4ÜmðLíóƒÜ[D?or‹1TÉ|QH¹·&¸ CgYGÜ–¼´OE¢L÷!ß³–,©|(VÓˆ&ËŽÝôÕˆ Ï]ðë;sú#}Ë`˱Z&§Ä”¸{$œ1,û. »w}4‹æŸÇéËZFöÜY© ²qÚÄ# öˆqé®~^Ì2 ØÀ¢‡¢«nùA'ëÚzÊ1Ä8ZÆBü6wb&… ¬a—;Påƒyȇmø~šÓ0¼¾ñö‘éV¨MõÙ
~,Ä)ümFsʉ/mïó¿ <#‘„iíùßÀýkwÑlþD±S¬ÀBêEï¼_C·ÌyX¶~þðö«ôoº“CÙíB¯–×}S‹æ¬#¢‘q£òÝ;‰’ òÉ< ÈÆSV¬>°ßY~¬yTáÈp÷F ÷?âÚc141·¢!8µðRFE®è ‰Z)ÞÝh¸æ)ë§~Ž—7ZW‘šêçj„ßÐËsBÇÐóê¶s¨•c¸òwŠ¿ö°Q:²°|bïk‘¶ÙSÊÀÛ•
°—ýË¥t´yhYÿVè~c½
òožT^ô*œfØ^•…yí‚>®»ê À¨T’
•B;hË]M£.©Áfßx½IP‚Þ&·ÁŸš.þ±¹'Ý{×íxÀ?%ég<Y-“fû0:MÇShùý„åâîp êÄ£#;úä-‰N¬ ÜÆTúƒîQæÅúø ;i…-ŠqÁÊ<Ö)û•œ©¾¥ç\PÑF¯³Ùâ „,WÌžÕè,n»#>Ôc Q~yë¡W-°±n´/“ZqnH
!|õ^ó‘õˆùCNóÕÐ)—W³sì®ù…G,5K„'tTò샕íNiØ`D¨SúæKË#]
à5 8Ò0’ÂVn’–-ø3Í/[ÎØsb‡ª'A¤º‹ìï?Zùð'}à¤yC§_ÈÒÁ²óâ“ ÌØåù‰hñkø©‘ç µKMPOpÚáù
.·;鉚®–Ùº,_êÊŸùŽ®[½ù“×àpùùòZ ¶]d¢ßL 8nl-{›T6¼~sY„> ãã)(ÐHPÔÝØDYMKã‚EJç5 –è©Cé‹õ…‰B¢¢”|#ñ%jWkI1ál¤*CY~ÄäRÛîæÖ¨¾º¹^OâC¸Èëø:ß%*õ*~}Nt¸År~ùG>´„j¶Ò>ÈìG§AÄÍ…>VÞkýšâêË~Ü(_¿ÓØ9½ÚÝÞDzS>5r0¹*ä Àìxôóùp¬`39i ±/žú£Œ2Ô-ðY¨Úܯãtº Ù9ÜðÁAt1ý¸ u‡ ›0Ö0Ú]]ðk¯
nùZ´ åä£MÞ¢ã‚^eà ïOtù•Dr¿ô¼Úý¥õ5 e©(YÖdGÚ(ó HfôúÚY…|9õÂ_‚èûy‚å"ã²Qvç|ý¤
kpÇãþ—dd
îhª‡²‘«´f¨¯M$¬Vý”¤Ú¸º’…!}jëgPÖlw(ñ޶“„åÌ÷dK
nÚíñT/¹w ôÓcE"Éï¥å#™^ÌæµÓ«¤yy‚záRíúÚµ¯šRDÛ¾!©Q”áÛ,káä¨7_¶.‡9fÏÍuÕ{ÇÇ~çWçÛÜx°‰dåÊG..2 ‘P·ŒD~áE™&Š{“”íbørÀº Ë«X~Š×ç"¨ö¿8ÚýŒö‘·P¨âG{< I” ¸ŸŸÐ‘!Ó`à\õQ þõ|èPȵÑ÷0³G*[P±~¿jÙÌÉ NK¯Ôã1ì!m’-:1Õ›ZZmë"FŸBS|äÀQԤ̱ Q½!ò²`
ïY´çfQ1
•>£ë´DêÅ)S5xƆ{lUk‡tèýÖ·‘ûTiR,Ò]Ùi^Þ7õE_ßT}Ú|S´E/0ÙªŸ±lçôMž[æÛÞHw¼º›£-E ‘$ëÈsŸùK¶<{ñØŒLý!‰æÙFC¡IÞdÜò{
5 °}t®g\ø±$תTŠ¢ÄOãWž»´Ç[.¥Lã™9qƒg–»N÷q›¡…üú¢_‡a¨½6Âj~m)ÏVü™ók«pdç.œ’N ©ž¶›2[ ·o;Tƒ
°Uq®Ú[-^‡Tþ‡óó_K/§Ì‡Ê‘™‹qåÛµëò«ôT{Ì>ÖaÜ·K}щ¸fӥ㓶¸Ûç’a>ª-&ÓV~²ØµB¥9”DO10säpdz‚Ó¾ç)åÏi•Øfµg-
~ -v“óAš{)w9Á)äóÙ¤3œî
¿A©^è þ5±¨Žp¿©c`¢Pn°
X¾²ST_±ˆA¨O:¬²i7gðG‘’&*ï ·üi¡xÇ„'; CÏŒ,Ü -ÌGÈün-ÑÁ
÷ƒWaïêÉŠ6›BÚãý„5ŸšFU³j Æ
%[ÌšZÑYÄω;©Òtû¥Ê7‡è
«!.XB¾måÄ9š&D×¾Tg|&/
,è„`óùVgdÒ:zŸÅ|vÂã«ëOûÊB 0¹ ÊÓdž |¸»2ú6£3Ää~ÏNtüçB÷aZû…&žñ¤6Ü£g£Óhù-;v¾kuo
ÕÔÏy·…,P\ÔœFñcc{®Á,Òþ’§ÒÁr¿â—½î §©pÜ“Vü—†LŠzªñÚð±FuNiŽw»Rßù´
qtBÏ×aL™½÷ùk|©‘‹£¥Xk¤0#…ŽÏ~'ewÊÒÄ›
l—ño
------------------------------------------------------------------
You see in the top of the e-mail that everything is fine, it says it removed the hostile content but why do we get all that stuff? (with other files, not zips, we don't have this)
Any ideas!?
Thanks,
Roach4
-
January 27th, 2004, 05:42 PM
#27
A couple of additional notes:
1. If you are running snort with the Swen.A rule defined it picks up many of the instances of this virus.
2. One machine got infected inside my network by the look of it at a sister org who I have less control over....<sigh>. It probably got through before the definitions were available, my mailserver updates hourly. It was trying to send outbound email which is blocked at the firewall. An ethereal dump showed that it was resolving the domain of the recipients prior to attempting to send which was noted by Symantec.
3. An Nmap of the machine indicated VNC running. The machine is shut down awaiting their tech staff.
Don\'t SYN us.... We\'ll SYN you.....
\"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides
-
January 27th, 2004, 05:47 PM
#28
Originally posted here by Tiger Shark
3. An Nmap of the machine indicated VNC running.
Tiger, are you saying that the virus dropped VNC on to the system?
Cheers:
-
January 27th, 2004, 05:55 PM
#29
NMap claimed that 2 ports used by VNC were open on the target machine...... Unfortunately, being in a hurry I didn't save the scan results and I forget the ports. Added to that I had the machine shut down so I can't rerun the scan.
I tried to connect using Slarty's VNC thingy and it told me VNC was already running so the ports were definitely open and active. I didn't go any further but simply called the person who knows who's machine that is and had them close it down to stopp the "chatter" at the firewall so I could see if anything else got in.
Symantec and the rest say it drops a trojan on any number of ports so I guess VNC's ports coincide with the trojan..... I thought that would be of use to some since they may use a VNC client on their systems so it may not be immediately apparent that this may not be what they think it is.
Don\'t SYN us.... We\'ll SYN you.....
\"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides
-
January 27th, 2004, 06:13 PM
#30
Re: eSAFE and Novarg (MyDOOM, mimail.q)
Originally posted here by Roach4
You see in the top of the e-mail that everything is fine, it says it removed the hostile content but why do we get all that stuff? (with other files, not zips, we don't have this)
Any ideas!?
Thanks,
Roach4
I suspect this is the contents of the zip file before the virus is stripped away.
Cheers:
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|