Re: Worm1800.exe on UnderNet

From: modem modem (modemat_private)
Date: Sat Jun 22 2002 - 03:59:17 PDT

  • Next message: Brian Collins: "port 32814"

    This is not really a new thing.
    It looks to me like it is a modified version of GT (Global Threat) a mIRC zombie that is mainly used as a irc flood/packet net.
    The original was written a year or two back, just some bright spark has decided to register a domain, and then "social engineer" it around the network. This happens quite often on DALnet (why doesnt that suprise me?). It is nothing to worry about, it is probably some 14 year old sitting at home trying to ./packet his school, or something lame like that. The majority of the people who will be silly enough to download and execute this bot, will never see these posts so why concern ourselves with some 14 year-old's pipe dream?
    
    _____________________________________________________________
    Get your Free, Private email at: http://email.nu/
    
    _____________________________________________________________
    Promote your group and strengthen ties to your members with emailat_private by Everyone.net  http://www.everyone.net/?btn=tag
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Sat Jun 22 2002 - 10:55:23 PDT