Security Basics mailing list archives

RE: forcdos.exe, msagent directory, DOS or warez??


From: "Wayne S. Ackley" <wackley () ideorlando org>
Date: Mon, 8 Dec 2003 16:10:09 -0500

Craig,

I don't know it it helps, but.....

forcedos.exe - Runs programs in MSDOS mode

I think you are right, it probably was renamed.

**************************************************
Wayne S. Ackley
IT Manager - Senior Network Engineer
IDEORLANDO Facility
3045 Technology Parkway
Orlando, Florida 32826
321-235-7524
321-235-1484
text pager: page_wayne () ideorlando org
Pager phone: 1-800-946-4646 pin#1431304
**************************************************


-----Original Message-----
From: Craig Broad [mailto:craig () broadband-computers com]
Sent: Thursday, December 04, 2003 6:53 PM
To: security-basics () securityfocus com
Subject: forcdos.exe, msagent directory, DOS or warez??


Hi all,

on a box recently moved to a managed network rack (GX networks), over the
last 2 weeks we have noticed strange behaviour.  One of the box's on the
subnet has been maxing out the link's bandwidth, on further investigation,
massive activity was found on ports 63501, 63502, 1734 and other high range
ports.  The behaviour was at least 8 hours of fully limiting output, and
then up to 8 hours of normal level operation and then a return to full
output.  at least ever 3 cycles, there would be a upload to the server at a
limit of abt 512kbps.

using a sniffer (netprobe) the ports were identified, and using fport these
were all linked to a executable called forcdos.exe.  i have searched all
search engines, and have seen not one single link, so i'm assuming it's
something else renamed.  The files has been placed in
C:\winnt\system32\msagent\local\com1\server directory.  We are assuming at
this time it has come in via some SQL exploit.  it look's as a full backdoor
access has been achieved.  Due to the non-local nature of the box, and the
com1 directory name, we have crrently been unable to access the directory to
retrieve the exe file.

The box has been locked down with the windows inbuilt firewall, locking all
tcpip ports not needed.  the exe is still running within the computer, but
is currently unable to get out of the box.

Firstly does anyone have any advice on how to get to this exe file?  I dont
want to just posix rd it, as i want to see the file first, and secondly does
anyone have any idea what this could be?  DOS or Warez?

many thanks for any advice.  if anyone can suggest how to get to the file,
we will make it available for analysis.

-----------
Craig Broad


---------------------------------------------------------------------------
----------------------------------------------------------------------------



---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: