2006-03-20 10:55 Age: 6 yrs

[Virus Alert] 2 new worms found

Worm name: ELF_LUPPER.H

Risk rating: HIGH

Damage Potential: HIGH

Distribution Potential: HIGH

 

Description:

This executable Linux file is either dropped or downloaded by other malware. Upon execution, it acts as a backdoor program.

 

It connects to a certain Internet Relay Chat (IRC) server and joins a specific IRC channel. Once a connection is established, it enables a remote malicious user to issue certain commands on the system. The said routine gives the remote malicious user virtual control over the affected system.

 

 

Worm name: HTML_SCRIPTACT.A

Risk rating: HIGH

Damage Potential: HIGH

Distribution Potential: HIGH

 

Description:

This malicious HTML file is a zero-day exploit that causes the Internet Explorer (IE) browser to crash due to several onClick event handlers contained in its code. It should be noted that an onClick event handler is a script element, which dictates the particular action a system does whenever an active text or image is clicked.

 

 

 

References: http://www.trendmicro.com/vinfo/ (TrendMirco Virus Security Info)

www.trendmicro.com/vinfo/zh-tw/default.asp (Traditional Chinese TrendMicro Virus Securit






  |    |