|
Incidents
Kuang2 strikes again, is it just me? Feb 16 2003 01:35AM Jeff Kell (jeff-kell utc edu) (4 replies) Re: Kuang2 strikes again, is it just me? Feb 16 2003 05:39PM Jeff (spam-fighter bigfoot com) (2 replies) RE: Kuang2 strikes again, is it just me? Feb 16 2003 11:28PM Trevor Metzger (trevor e-oasis com) (1 replies) Re: Kuang2 strikes again, is it just me? Feb 16 2003 04:18AM Johannes Ullrich (jullrich euclidian com) RE: Kuang2 strikes again, is it just me? Feb 16 2003 04:02AM Rob Shein (shoten starpower net) (1 replies) |
|
|
Privacy Statement |
2/13/2003, and the worm/Trojan was based the older mIRC Trojan (ocxdll.exe/
taskmngr.exe). The original analysis is at
http://www.klcconsulting.net/mirc_virus_analysis.htm
I saw a more than usual port 445 activities on incidents.org around 2/8-2/9,
and again on the last few days, so I cross-checked Symantec site, and found
the mIRC worm/Trojan variant, Backdoor.IRC.Zcrew. This variant used port
445 like the older ocxdll.exe Trojan. As I did some more research, I
noticed that TrendMicro analyzed this variant back in 12/3/2002, so I guess
it was not new, but just re-spreading.
I am curious how many people have seen this activities?
If you have a copy of this virus, can you contact me? I am interested in
analyzing this worm/Trojan file(s).
Symantec -
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.irc.zcr
ew.h
tml
TrendMicro -
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_FLO
OD.B
I.DR
Thanks,
/Kyle
Kyle Lai, CISSP, CISA
KLC Consulting, Inc.
617-921-5410
klai (at) klcconsulting (dot) net [email concealed]
www.klcconsulting.net
---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.454 / Virus Database: 253 - Release Date: 2/10/2003
------------------------------------------------------------------------
----
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com
[ reply ]