[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[ISSForum] New Sasser variant?



Is anyone else experiencing large amounts of traffic that appears as
Sasser, then turns into an ircbot.trojan named smsc.exe

connecting on port 6667, then performs HUGE amounts of SNMP get
requests? <grin>  I am, and very few people seem to have any

clue what this is...Virus companies are jumping around trying to define
and be first in line with a solution, I just wondered if

anyone on this forum has seen it yet?

 

ISS sigs triggering thus far are:

 

MSRPC_LSASS_Bo

TCP_Network_Scan

MSRPC_LSASS_Request_Detected

Microsoft_Windows_Shell_Banner

 

(others have been turned off due to sheer volume)

 

Thanks,

Erin

_______________________________________________
ISSForum mailing list
ISSForum@xxxxxxx

TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to https://atla-mm1.iss.net/mailman/listinfo/issforum

To contact the ISSForum Moderator, send email to mod-issforum@xxxxxxx

The ISSForum mailing list is hosted and managed by Internet Security Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328.