| Name |
W32.Sasser.E.Worm |
| Type |
Worm |
| Affected |
Windows 2000, Windows XP |
| Risk |
Level 2: Low |
| Discovered |
May 9, 2004 |
| Update |
February 13, 2007 12:22:50 PM |
| Length |
|
| Virus Info |
W32.Sasser.E.Worm is a minor variant of W32.Sasser.Worm. It attempts to exploit the LSASS vulnerability, described in Microsoft Security Bulletin MS04-011, and spreads by scanning randomly selected IP addresses for vulnerable systems.
W32.Sasser.E.Worm differs from W32.Sasser.Worm as follows:
- Uses a different mutex: SkynetNotice.
- Uses a different file name: lsasss.exe.
- Creates a different value in the registry: "lsasss.exe"
- Uses different port numbers, used by FTP server and the remote shell: 1023 and 1022.
- After 2 hours of running it displays a message.
- It deletes the values from the registry, which are known to be installed by Trojan.Mitglieder, W32.Beagle.W@mm, and W32.Beagle.X@mm.
- The name of the file retrieved from the FTP server is followed by _update.exe.
- The worm logs data into the file C:\ftplog.txt.
- Has an updated routine for finding vulnerable computers. W32.Sasser.E.Worm sends an ICMP echo request before attempting to make a connection. This change may prevent the worm from properly executing on Windows 2000 systems.
W32.Sasser.E.Worm can run on, but not infect, Windows 95/98/Me computers. Although these operating systems cannot be infected, they can still be used to infect vulnerable computers.
|
| Threat Assessment |
Wild
-
Wild Level: Low
-
Number of Infections: 50 – 999
-
Number of Sites: More than 10
-
Geographical Distribution: Low
-
Threat Containment: Easy
-
Removal: Moderate
Damage
Distribution
Writeup By: Sergei Shevchenko
|
| Details |
>W32.Sasser.E.Worm |
convert this post to pdf.
Tags:
Virus,
Worm
Related Virus
"Free Scan W32.Sasser.E.Worm
Print This Virus article
This entry was posted
on Wednesday, January 16th, 2008 at 11:46 am and is filed under
Virus.
You can follow any responses to this entry through the
RSS 2.0 feed.
You can
leave a response, or
trackback from your own site.
Leave a Comment
You must be logged in to post a comment.