Is anyone else experiencing large amounts of traffic that appears as
Sasser, then turns into an ircbot.trojan named smsc.exe

connecting on port 6667, then performs HUGE amounts of SNMP get
requests? <grin>  I am, and very few people seem to have any

clue what this is...Virus companies are jumping around trying to define
and be first in line with a solution, I just wondered if

anyone on this forum has seen it yet?

 

ISS sigs triggering thus far are:

 

MSRPC_LSASS_Bo

TCP_Network_Scan

MSRPC_LSASS_Request_Detected

Microsoft_Windows_Shell_Banner

 

(others have been turned off due to sheer volume)

 

Thanks,

Erin

_______________________________________________
ISSForum mailing list
[EMAIL PROTECTED]

TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to 
https://atla-mm1.iss.net/mailman/listinfo/issforum

To contact the ISSForum Moderator, send email to [EMAIL PROTECTED]

The ISSForum mailing list is hosted and managed by Internet Security Systems, 6303 
Barfield Road, Atlanta, Georgia, USA 30328.

Reply via email to