Jump to content
Un.Neuron

New worm targeting weak passwords on Remote Desktop connections (port 3389)

Recommended Posts

We've had reports of a new worm in the wild and that generates increased RDP traffic for our users on port 3389. Although the overall numbers of computers reporting detections are low in comparison to more established malware families, the traffic it generates is noticeable. The worm is detected as Worm:Win32/Morto.A and you can see a detailed description of it at Worm:Win32/Morto.A.

Morto attempts to compromise Remote Desktop connections in order to penetrate remote systems, by exploiting weak administrator passwords. Once a new system is compromised, it connects to a remote server in order to download additional information and update its components. It also terminates processes for locally running security applications in order to ensure its activity continues uninterrupted. Affected users should note that a reboot may be required in order to complete the cleaning process.

This particular worm highlights the importance of setting strong system passwords. Using strong passwords can go a long way towards protecting your environment -- and the ability of attackers to exploit weak passwords shouldn't be underestimated. For example, Morto tries the following passwords:

*1234

0

111

123

369

1111

12345

111111

123123

123321

123456

168168

520520

654321

666666

888888

1234567

12345678

123456789

1234567890

%u%

%u%12

1234qwer

1q2w3e

1qaz2wsx

aaa

abc123

abcd1234

admin

admin123

letmein

pass

password

server

test

user

sursa> New worm targeting weak passwords on Remote Desktop connections (port 3389) - Microsoft Malware Protection Center - Site Home - TechNet Blogs

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...