W32/IRCbot worm beats Sasser record

Experts raise risk assessment

Robert Jaques

Security experts today raised the risk assessment to high on the recently discovered W32/IRCbot.worm!MS05-039 worm, which is also known as IRCbot.worm!MS05-039. The worm, an Internet Relay Chat (IRC) Bot, includes the ability to spread by exploiting systems that are not yet patched for the MS05-039 vulnerability.

According to McAfee's AVERT antivirus team, the IRCbot.worm!MS05-039 worm has emerged in the wild seven days following the initial announcement of the Microsoft vulnerability, demonstrating the fastest time between the announcement of a vulnerability and the success of a mass propagating exploit - even faster than Sasser, which took 14 days.

Advertisement

"The vulnerability, which was announced by Microsoft on August 9, 2005, has also been targeted by virus writers who produced multiple variants of the ever expanding SDBot family, as well as a newly discovered family now known as Zotob, " AVERT warned.

"The IRCbot.worm!MS05-039 worm was the first of these threats to mass propagate successfully. To date, McAfee AVERT has received more than 150 reports of the worm being stopped or infecting users from the field. Most of these reports have arrived from the United States, although AVERT has also received reports from Asia and Europe."

The IRCbot.worm!MS05-039, once activated, is designed to contact a remote IRC server and wait for further instructions. If this worm is run on a system that has not yet been patched for the MS05-039 vulnerability, it will continually reboot. Infected systems will be listening on TCP port 8594.

When the file is run, the virus copies itself to the Windows System directory (eg C:\Windows\System32\ on Windows XP) as WINTBP.EXE. The file can be run automatically by exploiting the MS05-039 vulnerability or by a person directly executing the worm.

More information on IRCbot.worm!MS05-039 can be found here.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Netsky.b worm spreading fast

Warning issued as medium-risk mass mailer worm emerges in wild

High-risk worm warning

Ability to spread is high, says Symantec

Sober worm causes headaches

Virus firms warn of new email attachment-based malware

MiMail.I worm warnings upgraded

Increasing prevalence of fake PayPal message that attempts to steal credit card data

Related whitepapers

Related jobs

Most watched

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

a padlock

Microsoft to plug security holes

Microsoft has given advance warning of a number of security...

Nokia handset

Top 10 articles, 10 July 09

No Nokia Android phone, ActiveX attacks and Google enters into...

Can Google beat Microsoft at its own game?

Google's announcement this week that it plans to step into...

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Primary Navigation