Vulnerability Development mailing list archives

Re: New Worm


From: "Naseer Bhatti" <naseer () fibre net pk>
Date: Wed, 19 Sep 2001 02:25:02 +0500

The worm sends E-mail to the following mail servers

omega.serpro.gov.br (161.148.173.118)
server1.sans.org (167.216.133.33 )
smtp.china.com (61.135.144.88)
perninha.conectiva.com.br (200.250.58.156)
phuck.nether.net (204.42.254.5)
mx.ideal.ru (212.69.101.252)
tarkin.fdt.net (209.212.128.45)


----- Original Message -----
From: "Enrique A. Compañ Gzz." <enrique () virtekweb net>
To: <vuln-dev () securityfocus com>
Sent: Tuesday, September 18, 2001 9:17 PM
Subject: New Worm


Yes, yes.... a new "$%"·$ worm.

Again, by chinesse terrorist (I cannot refer them other way).


an example of this (BECAREFUL) can be seen at http://64.218.116.235

Don't go there if you aren't protected. it downloads readme.eml
automatically and executes.

It seg faults on my machine... fortunally




Current thread: