Full Disclosure mailing list archives

Re: HEADS UP VIRUS BEING SPREAD one of our rea


From: Nick FitzGerald <nick () virus-l demon co uk>
Date: Sun, 25 May 2003 17:17:37 +1300

<scheidell () secnap net> wrote:

did a google for update880.exe, found nothing yet.

Dude -- ever hear (or think) of self-mailers generating random 
attachment names to make them less immediately identifiable?

And here's a real shocker of an idea (though not actually relevant in 
this case) -- imagine if it was a _parasitic_ file infector!

It is an existing, well-known (and "old") virus, reliably ID'ed by 
just about any virus scanner updated since late Feb this year.  There 
are abundant informed and informative descriptions of how it works 
all over the web.  It seems Mr Wood and your good self must be about 
the only "security experts" who have not already encountered it.


-- 
Nick FitzGerald
Computer Virus Consulting Ltd.
Ph/FAX: +64 3 3529854
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: