RE: msblast.exe available

From: Kirt Cathey (kirtat_private)
Date: Tue Aug 12 2003 - 05:03:45 PDT

  • Next message: Christopher Lyon: "RE: MSBLASTER Infecting despite 03-026 patch?"

    Be careful... when I went to look at the Matta web site, it was not listed.
    When I tried to delete it from the hard drive, the system said that I did
    not
    have the proper priveleges. May be time to scrape this system clean
    anyway...
    
    /***************************************
    Kirt S. Cathey, CIA, CISA, CISSP, MCSE
    PricewaterhouseCoopers - Tokyo, Japan
    Intrusion Detection, Forensics, and Audit
    www.systemsrisk.com
    ***************************************/
    
    -----Original Message-----
    From: Sekurity Wizard [mailto:s.wizardat_private]
    Sent: Tuesday, August 12, 2003 12:27 PM
    To: incidentsat_private
    Subject: RE: msblast.exe available
    
    
    
    Has anyone dis-assembled this puppy yet, to get a good idea of what the
    heck it does, exactly?  I'm working on it and would like to collaborate
    with anyone?
    
    ./Wiz
    
    -----Original Message-----
    From: Chris McNab [mailto:chris.mcnabat_private]
    Sent: Monday, August 11, 2003 6:47 PM
    To: bugtraqat_private
    Cc: incidentsat_private
    Subject: msblast.exe available
    
    
    Hi,
    
    This is publicly available for analysis from:
    
    www.trustmatta.com/downloads/msblast.exe
    
    Regards,
    
    Chris
    
    Chris McNab
    Technical Director
    
    Matta Consulting
    18 Noel Street
    London W1F 8GN
    
    08700 77 11 00
    
    www.trustmatta.com
    
    
    ------------------------------------------------------------------------
    ---
    ------------------------------------------------------------------------
    ----
    
    
    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    
    
    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    



    This archive was generated by hypermail 2b30 : Tue Aug 12 2003 - 16:44:49 PDT