OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[Full-Disclosure] Re: anyone seen this worm/trojan before?

From: Feher Tamas (etomcatfreemail.hu)
Date: Thu Jun 03 2004 - 15:02:04 CDT


Hello,

>http://www.packetfocus.com/analysis/wkssvrs.zip

Kaspersky AV says: "Backdoor.RBot.gen" malware

Virus description:
"http://uk.trendmicro-
europe.com/enterprise/security_info/ve_detail.php?
id=59366&VName=BKDR_RBOT.A"

Try the above URL with RBOT_n (n = B,C,D,E, etc.) ending for more
variants.

The fact that it is identified as "something.GEN" means it is likely a new
RBot variant, identified with antivirus heuristics.

Sincerely: Tamas Feher.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html