W32/IRCbot worm beats Sasser record

Experts raise risk assessment

Robert Jaques

Security experts today raised the risk assessment to high on the recently discovered W32/IRCbot.worm!MS05-039 worm, which is also known as IRCbot.worm!MS05-039. The worm, an Internet Relay Chat (IRC) Bot, includes the ability to spread by exploiting systems that are not yet patched for the MS05-039 vulnerability.

According to McAfee's AVERT antivirus team, the IRCbot.worm!MS05-039 worm has emerged in the wild seven days following the initial announcement of the Microsoft vulnerability, demonstrating the fastest time between the announcement of a vulnerability and the success of a mass propagating exploit - even faster than Sasser, which took 14 days.

Advertisement

"The vulnerability, which was announced by Microsoft on August 9, 2005, has also been targeted by virus writers who produced multiple variants of the ever expanding SDBot family, as well as a newly discovered family now known as Zotob, " AVERT warned.

"The IRCbot.worm!MS05-039 worm was the first of these threats to mass propagate successfully. To date, McAfee AVERT has received more than 150 reports of the worm being stopped or infecting users from the field. Most of these reports have arrived from the United States, although AVERT has also received reports from Asia and Europe."

The IRCbot.worm!MS05-039, once activated, is designed to contact a remote IRC server and wait for further instructions. If this worm is run on a system that has not yet been patched for the MS05-039 vulnerability, it will continually reboot. Infected systems will be listening on TCP port 8594.

When the file is run, the virus copies itself to the Windows System directory (eg C:\Windows\System32\ on Windows XP) as WINTBP.EXE. The file can be run automatically by exploiting the MS05-039 vulnerability or by a person directly executing the worm.

More information on IRCbot.worm!MS05-039 can be found here.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Netsky.b worm spreading fast

Warning issued as medium-risk mass mailer worm emerges in wild

High-risk worm warning

Ability to spread is high, says Symantec

Sober worm causes headaches

Virus firms warn of new email attachment-based malware

MiMail.I worm warnings upgraded

Increasing prevalence of fake PayPal message that attempts to steal credit card data

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

IT white papers

Search white papers

Top categories

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

Piracy, privacy and processing power set to be hot topics for V3.co.uk Summit

Have you got a burning desire to quiz experts from...

iPhone

World's first iPhone virus surfaces

Images of 80s icon Rick Astley spell trouble

Airvana HubBub

Airvana debuts 3G femtocell for offices

HubBub improves indoor network coverage for businesses

shopping key

E-commerce on brink of SaaS revolution

Figleaves founder argues platform-as-a-service vendor will emerge to shake up...

Primary Navigation