Aliases
DoS.Perl.Imesh.102 (Kaspersky Lab) is also known as: DoS.Imesh.102 (Kaspersky Lab), UNIX/Exploit-Imesh (McAfee), Hacktool.DoS (Symantec), Troj/Imesh-A (Sophos), PERL/Imesh.102* (RAV), DOSIMESH.A (Trend Micro), Unix/Imesh.A (FRISK), UNIX:Malware (ALWIL), PERL.Imesh.102 (SOFTWIN), DoS Program (Panda), Linux/DoS.Imesh.102 (Eset)
Technical details
This malicious program can be used to conduct a DoS attack. It is a script file written in Perl. The infected file is 1350 bytes in size.
Payload
The script conducts a DoS attack on the iMesh 1.02 client. In order to do this, it listens on port 5000. If a connection is detected, a specially crafted request will be sent, which will lead to a buffer overrung.
As a result, a remote malicious user will be able to execute random code on the system under attack.
Removal instructions
1. Delete the infected script file.
2. Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus).




No comments:
Post a Comment