Security Incidents mailing list archives

Re: Suspect e-mail from bfrazzon () lcc furb br.


From: Ryan Russell <ryan () SECURITYFOCUS COM>
Date: Tue, 8 May 2001 15:35:30 -0600

Further thoughts on this.  I've have several sample emails from the virus
described at:
http://vil.mcafee.com/dispVirus.asp?virus_k=99040&;

They are all using this:
Content-Type: application/octet-stream;
For the .exe attachment type, not the gif type described by Yotam.  That,
and the fact that the .exe attached is not recognized by McAfee (which
does obviously recognize the virus they describe on their site) makes me
think this is a new variant.

                                        Ryan


Current thread: