ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

New PnP worm spreading

highVulnerabilityimportance 42

Indicators of compromiseAll →

TypeIndicatorContext
md57a67f7a8c844820c1bae3ebf720c1cd9s a basic IRCBot with Trojan-Downloader functionality. MD5: 7a67f7a8c844820c1bae3ebf720c1cd9 An urgent update has been released. Latest Webinars Reports
Full article151 words · extracted from securelist.com · click to collapse

Incidents

Incidents

17 Aug 2005

minute read

We’ve received numerous reports on a new worm spreading via the PnP vulnerability.
We detect it as Net-Worm.Win32.Small.d.

Normally the worm’s filename is wintbp.exe, it contains a basic IRCBot with Trojan-Downloader functionality. MD5: 7a67f7a8c844820c1bae3ebf720c1cd9

An urgent update has been released.

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/new-pnp-worm-spreading/30050/