This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Community Information

New worm in wild! Morto targets port 3389

1 min read

This thread's last reply is from August 29, 2011, 5:58 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

It’s retro day in the world of Internet security, with an Internet worm dubbed “Morto” spreading via the Windows Remote Desktop Protocol (RDP).

F-Secure is reporting that the worm is behind a spike in traffic on Port 3389/TCP. Once it’s entered a network, the worm starts scanning for machines that have RDP enabled. Vulnerable machines get Morto copied to their local drives as a DLL, a.dll, which creates other files detailed in the F-Secure post.


Story @ The Register
Brief report @ F-Secure

UPDATE:
Analysis by MMPC lists files and registry entries created, processes killed and details of known C&C servers. NB: The first IP address listed should be .82 in the last octet.
ZB