 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Irregular Expressions &#187; Morto</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/Irregular-Expressions/tag/morto/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions</link>
	<description>Insight into current security related events and exploits, including virtualization security and tips.</description>
	<lastBuildDate>Sun, 28 Apr 2013 08:00:32 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>RDP Worm</title>
		<link>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/rdp-worm/</link>
		<comments>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/rdp-worm/#comments</comments>
		<pubDate>Tue, 30 Aug 2011 01:22:22 +0000</pubDate>
		<dc:creator>Dan O'Connor</dc:creator>
				<category><![CDATA[Morto]]></category>
		<category><![CDATA[Morto.Gen!A]]></category>
		<category><![CDATA[rdp worm]]></category>
		<category><![CDATA[windows worm]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/Irregular-Expressions/rdp-worm/</guid>
		<description><![CDATA[I was toying with something like this a while ago, I was playing with the idea of being able to do this from a *nix box for VA purposes (With out the gui part, I just wanted a yes or no back). http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Worm%3AWin32%2FMorto.A http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Worm%3aWin32%2fMorto.gen!A It&#8217;s current state should not get many hosts, the list of [...]]]></description>
				<content:encoded><![CDATA[<p>I was toying with something like this a while ago, I was playing with the idea of being able to do this from a *nix box for VA purposes (With out the gui part, I just wanted a yes or no back).</p>
<p><a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Worm%3AWin32%2FMorto.A">http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Worm%3AWin32%2FMorto.A</a></p>
<p><a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Worm%3aWin32%2fMorto.gen!A">http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Worm%3aWin32%2fMorto.gen!A</a></p>
<p>It&#8217;s current state should not get many hosts, the list of passwords is limited.</p>
<p><span class="notranslate"><em>*1234</em></span><br />
<span class="notranslate"><em>0</em></span><br />
<span class="notranslate"><em>111</em></span><br />
<span class="notranslate"><em>123</em></span><br />
<span class="notranslate"><em>369</em></span><br />
<span class="notranslate"><em>1111</em></span><br />
<span class="notranslate"><em>12345</em></span><br />
<span class="notranslate"><em>111111</em></span><br />
<span class="notranslate"><em>123123</em></span><br />
<span class="notranslate"><em>123321</em></span><br />
<span class="notranslate"><em>123456</em></span><br />
<span class="notranslate"><em>168168</em></span><br />
<span class="notranslate"><em>520520</em></span><br />
<span class="notranslate"><em>654321</em></span><br />
<span class="notranslate"><em>666666</em></span><br />
<span class="notranslate"><em>888888</em></span><br />
<span class="notranslate"><em>1234567</em></span><br />
<span class="notranslate"><em>12345678</em></span><br />
<span class="notranslate"><em>123456789</em></span><br />
<span class="notranslate"><em>1234567890</em></span><br />
<span class="notranslate"><em>!@#$%^</em></span><br />
<span class="notranslate"><em>%u%</em></span><br />
<span class="notranslate"><em>%u%12</em></span><br />
<span class="notranslate"><em>1234qwer</em></span><br />
<span class="notranslate"><em>1q2w3e</em></span><br />
<span class="notranslate"><em>1qaz2wsx</em></span><br />
<span class="notranslate"><em>aaa</em></span><br />
<span class="notranslate"><em>abc123</em></span><br />
<span class="notranslate"><em>abcd1234</em></span><br />
<span class="notranslate"><em>admin</em></span><br />
<span class="notranslate"><em>admin123</em></span><br />
<span class="notranslate"><em>letmein</em></span><br />
<span class="notranslate"><em>pass</em></span><br />
<span class="notranslate"><em>password</em></span><br />
<span class="notranslate"><em>server</em></span><br />
<span class="notranslate"><em>test</em></span><br />
<span class="notranslate"><em>user</em></span></p>
<p>Here is a list of hosts it will attempt to contact for updates.</p>
<pre><span><span class="notranslate"><em>210.3.38.82</em> </span>
<span class="notranslate"><em>jifr.info</em> </span>
<span class="notranslate"><em>jifr.co.cc</em> </span>
<span class="notranslate"><em>jifr.co.be</em> </span>
<span class="notranslate"><em>qfsl.net</em> </span>
<span class="notranslate"><em>qfsl.co.cc</em> </span>
<span class="notranslate"><em>qfsl.co.be</em> </span></span></pre>
<p>Always check your firewall logs just to be safe.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/Irregular-Expressions/rdp-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
