Full Disclosure mailing list archives

Gibe (was Re: new virus:)


From: disclosure () exotope com
Date: Fri, 19 Sep 2003 13:30:03 -0400 (EDT)

My H+BEDV AntiVir is alerting on both the Swen virus (bogus Microsoft
patch) and this variant, tagging them both as Gibe.C.1

This version doesn't mention any patch.  It seems more closely related
to the older Gibe variants.

Here's the text/html from the new 'bounce' variant:
-<snip>----------------------------------------------------------
<HTML>
<HEAD></HEAD>
<BODY>
<iframe src=3D"cid:awirev" height=3D0 width=3D0></iframe>
<BR><BR>Hi.
<BR>This is the qmail program<BR>
<BR><BR><BR>Undelivered mail to <B>user () example com</B>
</BODY></HTML>

-<snip>--------------------------------------------------------

I'm also seeing 'bounce' versions of Gibe.C.1 with .bat attachments
instead of .exe (though the filetype is still an exe).

                      ...Eric

On Fri, 19 Sep 2003, Ron Clark wrote:


Has anyone seen an email going around with subject bug message
containing a supposed audio attachment that is really an exe named
ckcwr.exe.

Is this a possible new virus? I have recieved numerous cpoies of this
email since last night.

Ron Clark
System Administrator
Armstrong Atlantic State University

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: