SANS - Internet Storm Center - Cooperative Cyber Threat Monitor And Alert System - Current Infosec News and Analysis
SANS - Internet Storm Center - Cooperative Cyber Threat Monitor And Alert System - Current Infosec News and Analysis: "New Virus Behavior / GDIScan Questions
New virus behavior
Our fellow handler Patrick Nolan sent this news about the Surila.k virus. According to the VirusList.com website 'In order to gain full access to the Internet, Surila registers itself in the Windows FirewallPolicy, thereby becoming a legal program with full Internet rights.'
This will bypass any Firewall settings that may otherwise block the virus from contacting the IRC server is connects to for remote control. The virus installs an HTTP and SMTP proxy server. Traffic to these proxies will be permitted by the modified firewall rules. "
New virus behavior
Our fellow handler Patrick Nolan sent this news about the Surila.k virus. According to the VirusList.com website 'In order to gain full access to the Internet, Surila registers itself in the Windows FirewallPolicy, thereby becoming a legal program with full Internet rights.'
This will bypass any Firewall settings that may otherwise block the virus from contacting the IRC server is connects to for remote control. The virus installs an HTTP and SMTP proxy server. Traffic to these proxies will be permitted by the modified firewall rules. "
0 Comments:
Post a Comment
<< Home