numenmail.com

Monday, July 28, 2008

DoS.Perl.Chopsui

Aliases
DoS.Perl.Chopsui (Kaspersky Lab) is also known as: DoS.Chopsui (Kaspersky Lab), UNIX/Exploit-Argosoft (McAfee), Hacktool.DoS (Symantec), Troj/Chopsui-A (Sophos), PERL/Chopsui* (RAV), DOSCHOPSUI.A (Trend Micro), Unix/Chopsui.A (FRISK), UNIX:Malware (ALWIL), Perl.DoS.Chopsui.A (SOFTWIN), DoS Program (Panda), Linux/DoS.Chopsui (Eset)

Technical details
This malicious program can be used to conduct a DoS attack on a remote server. The program itself is a script file written in Perl. The infected file is 913 bytes in size.

Payload
This script conducts a DoS attack on Argosoft Mail Server 1.0.0.2. In order to do this, it forms a string composed of 3000 letter 'X's.

This string will then be sent to port 79 of the remote server, resulting in it crashing.

Removal instructions
1. Delete the infected script file.
2. Perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus).

No comments: