numenmail.com

Monday, July 28, 2008

DoS.Perl.Imesh.102

Aliases
DoS.Perl.Imesh.102 (Kaspersky Lab) is also known as: DoS.Imesh.102 (Kaspersky Lab), UNIX/Exploit-Imesh (McAfee), Hacktool.DoS (Symantec), Troj/Imesh-A (Sophos), PERL/Imesh.102* (RAV), DOSIMESH.A (Trend Micro), Unix/Imesh.A (FRISK), UNIX:Malware (ALWIL), PERL.Imesh.102 (SOFTWIN), DoS Program (Panda), Linux/DoS.Imesh.102 (Eset)

Technical details
This malicious program can be used to conduct a DoS attack. It is a script file written in Perl. The infected file is 1350 bytes in size.

Payload
The script conducts a DoS attack on the iMesh 1.02 client. In order to do this, it listens on port 5000. If a connection is detected, a specially crafted request will be sent, which will lead to a buffer overrung.

As a result, a remote malicious user will be able to execute random code on the system under attack.

Removal instructions
1. Delete the infected script file.
2. Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus).

No comments: