This is the Trend Micro detection for a hacking tool that can be used to launch a denial of service attack by exploiting the Remote Desktop Protocol Vulnerability (CVE-2012-0002).
This malware is a Proof-of-Concept (PoC) code for exploiting MS12-020. While the said Remote Desktop Protocol vulnerability could allow remote access to target machines, this PoC is only designed to perform denial of service (DoS) to a target machine through exploiting the vulnerability.
This hacking tool may be manually installed by a user.
Ports used: TCP port 3389 (MS WBT Server)
File size: 279,040 bytes
File type: EXE
Memory resident: No
Initial samples received date: 17 Mar 2012
Arrival Details
This hacking tool may be manually installed by a user.
NOTES:
This is the Trend Micro detection for a hacking tool that can be used to launch a denial of service attack by exploiting the Remote Desktop Protocol Vulnerability (CVE-2012-0002). When executed with no command-line parameters, the following message is displayed:

The first usage sends random data to a target machine. This can be used to test if the remote desktop service in the target machine is enabled. The parameter with -l specifies the size of data to send. The parameter -c causes the tool to pause for 5 seconds for every iteration. When the number of iterations is specified, this can function as a denial of service tool.
The second usage crashes the operating system.
More information on this vulnerability can be found below:
Connect with us on
| | | |