W32.Sasser.E.Worm

Name W32.Sasser.E.
Type
Affected Windows 2000, Windows XP
Risk Level 2: Low
Discovered May 9, 2004
Update February 13, 2007 12:22:50 PM
Length
Info

W32.Sasser.E. is a minor variant of W32.Sasser.. It attempts to exploit the LSASS vulnerability, described in Microsoft Security Bulletin MS04-011, and spreads by scanning randomly selected IP addresses for vulnerable systems.

W32.Sasser.E. differs from W32.Sasser. as follows:

  • Uses a different mutex: SkynetNotice.
  • Uses a different file name: lsasss.exe.
  • Creates a different value in the registry: "lsasss.exe"
  • Uses different port numbers, used by FTP server and the remote shell: 1023 and 1022.
  • After 2 hours of running it displays a message.
  • It deletes the values from the registry, which are known to be installed by Trojan.Mitglieder, W32.Beagle.W@mm, and W32.Beagle.X@mm.
  • The name of the file retrieved from the FTP server is followed by _update.exe.
  • The logs data into the file C:\ftplog.txt.
  • Has an updated routine for finding vulnerable computers. W32.Sasser.E. sends an ICMP echo request before attempting to make a connection. This change may prevent the from properly executing on Windows 2000 systems.

W32.Sasser.E. can run on, but not infect, Windows 95/98/Me computers. Although these operating systems cannot be infected, they can still be used to infect vulnerable computers.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 50 – 999
  • Number of Sites: More than 10
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Moderate

Damage

  • Damage Level: Low

Distribution

  • Distribution Level: High
Writeup By: Sergei Shevchenko
Details >W32.Sasser.E.Worm
convert this post to pdf. Tags: ,

Related Virus

"Free Scan W32.Sasser.E.Worm

Print This Virus article Print This Virus article


Leave a Comment

You must be logged in to post a comment.