Full Disclosure mailing list archives
Re: (no subject)
From: "Bernardo Quintero" <bernardo () hispasec com>
Date: Mon, 9 Aug 2004 21:43:10 +0200
(In regards to new_price.zip file attachment) Anyone have any idea what this is, we had some clients just get pretty hard with this email. I am unable to find anything on it, from my VERY Limited knowledge it appears to be a virus exploiting one of the many holes in IE. Anyone else see anything on this yet?
http://www.incidents.org/diary.php?date=2004-08-09 Scan results (http://www.virustotal.com) File: price.zip Date: 08/09/2004 21:41:30 ---- BitDefender 7.0/20040809 found [JS.Dword.dropper] ClamWin devel-20040727/20040809 found [Trojan.JS.RunMe] eTrustAV-Inoc 4641/20040728 found [JScript/IE.VM.Exploit] F-Prot 3.15/20040809 found [HTML/ObjData@exp] Kaspersky 4.0.2.23/20040809 found nothing McAfee 4383/20040804 found [JS/IllWill] NOD32v2 1.836/20040809 found [Win32/Bagle.AI] Norman 5.70.10/20040806 found [W32/Malware] Panda 7.02.00/20040809 found [Fichero Sospechoso] Sybari 7.5.1314/20040809 found [JS/IllWill] Symantec 8.0/20040809 found nothing TrendMicro 7.000/20040809 found [HTML_BAGLE.AC] _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- (no subject) Dufresne (Aug 09)
- <Possible follow-ups>
- (no subject) Dufresne (Aug 09)
- RE: (no subject) Jonathan Grotegut (Aug 09)
- RE: (no subject) Jonathan Grotegut (Aug 09)
- Re: (no subject) Bernardo Quintero (Aug 09)
- Re: (no subject) Frank Knobbe (Aug 09)
- Re: (no subject) Nick FitzGerald (Aug 09)
- Re: (no subject) Maarten (Aug 12)
- Re: (no subject) Nick FitzGerald (Aug 12)
- Re: (no subject) Todd Burroughs (Aug 13)
- Re: (no subject) Harlan Carvey (Aug 13)
- Re: (no subject) Barry Fitzgerald (Aug 13)
- Re: (no subject) Harlan Carvey (Aug 13)
- Re: (no subject) Barry Fitzgerald (Aug 13)
- Re: (no subject) Frank Knobbe (Aug 13)
- Re: (no subject) Bernardo Quintero (Aug 09)