subject: (Fwd) new trojan - scanning for open shares ... posted: Tue, 17 Oct 2000 14:26:20 +0100
i don't make much sense of this, except:
1. mentions networks.vbs
2. share-level password vulnerability mentioned (I'm not sure I recall
seeing this before - but why I am not surprised)
3. list of trojaned machines at end.
Stuart
------- Forwarded message follows -------
Date sent: Mon, 16 Oct 2000 04:45:29 +0200
Send reply to: Philippe Bourcier <[email protected]>
From: Philippe Bourcier <[email protected]>
Organization: CyberAbuse
Subject: new trojan - scanning for open shares ...
To: [email protected]
Hi
We've seen on different IRC networks some strange botnets
("dmanz
botnet :>") all coming from a new trojan.
This trojan is really mysterious, since the only thing found is it's
using networks.vbs to scan for open shares, and save the list of IPs
found. Then I think the coder of the trojan (adman, who is using his
static IP on IRC) take those lists (with a special command given to
the bots), but why he does that is still mysterious (perhaps it has
something to do with the "Share Level Password" Vulnerability
recently
discovered). The entire package couldn't be analysed, so we still
don't know if there is a DoS tool with it or not. You can see a big
list of trojaned machines at
www.documents.cyberabuse.org/?doc=11
Philippe Bourcier
-------------------------------------
www.documents.cyberabuse.org
------- End of forwarded message -------
generated by msg2page 0.06 on Jul 21, 2006 at 19:05:05