|
||
8/3: Scaner-A Worm Uses Port 445 W32/Scaner-A is a worm that exploits the LSASS vulnerability detailed in MS04-011.
The worm connects to a randomly-generated IP addresses on port 445 and uses the LSASS vulnerability to execute code on the remote computer. This code attempts to download a file from a preconfigured web server and execute it. During tests, this web server was not responding.
W32/Scaner-A may report its progress to the author via HTTP POST submissions.
|
||
|