Full Disclosure mailing list archives

Does anyone have MyDoom.B?


From: Daniel Spisak <dspisak () nonmundane org>
Date: Thu, 29 Jan 2004 12:11:02 -0800

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

I'm looking for a copy of MyDoom.B to analyze. It seems as if the only  
people/places that have seen this are the large A/V people.

Trend Micro seems to think only one system (at the time I write this)  
has been infected (as they track it at least which isn't very  
accurate). Source:  
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp? 
VName=WORM_MYDOOM.B&VSect=S

MessageLabs doesn't even list MyDoom.B on their list of active viruses  
they've seen in the wild. Source:  
http://www.messagelabs.com/viruseye/threats/list/default.asp

I've seen some news reports that would seem to indicate that MyDoom.B  
might not be propagating as fast as MyDoom.A has been and in fact might  
be potentially flawed in how it spreads itself? Source:  
http://www.theaustralian.news.com.au/common/story_page/ 
0,5744,8533540%255E1702,00.html

I've gotten plenty of copies of MyDoom.A into my various inboxes but  
have yet to see a single instance of MyDoom.B and from talking to a few  
here and on other lists this seems to be the common case. No one I've  
talked to has this new variant. If anyone has a copy of MyDoom.B or  
gets a copy I would really appreciate it if anyone could email it to  
me, thanks!

Daniel E. Spisak
Security Engineer
OnlineSecurity
www.onlinesecurity.com
dan () onlinesecurity com
Cell: 562.331.1603

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.0.3

iQA/AwUBQBlo4RUn/Hz8mr7jEQL5PgCfTyOyJf8Z4YpN6J/gYZH7k5KB7SgAnA8c
45dTpRdDKwEETU83llXMiIJr
=f3Cn
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: