Tuesday, August 16, 2005

CNN Worm update #2

SANS - Internet Storm Center has released an other updated statement on the CNN worm:
This is an IRC bot worm, and will scan for TCP port 445, and for file shares. McAfee reports in it's bulletin that systems not patched for MS05-039 will continually reboot.

It appears this is a new worm, W32.Zotob.E. Symatec has release info here. McAfee released information as well, calling it W32/IRCbot.worm. McAfee has rated the risk assessment as high.


Post a Comment

<< Home