[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-Disclosure] New MyDoom or Netsky variant?



http://vil.nai.com/vil/newly-discovered-viruses.asp

-- Mary

----- Original Message ----- 
From: "Vic Vandal" <vvandal@xxxxxxxx>
To: <full-disclosure@xxxxxxxxxxxxxxxx>
Sent: Monday, July 19, 2004 6:11 PM
Subject: [Full-Disclosure] New MyDoom or Netsky variant?


Anyone seeing what looks like a brand new MyDoom variant?
Comes in e-mail as a message.zip, extracts to a message.doc
followed by a LOT of spaces and then a .pif extension.
I've only started to look at the encoded attachment, but
someone who opened it had a LSASS.EXE start up and take
about 96% CPU utilization.  I scanned the offending Outlook
attachment with the latest Symantec sigs, but it didn't recognize
it.  The .pif appears to be packed with UPX.

I'm tempted to infect my own machine to study the effects, but
would rather not do so and find out it's eaten a bunch of my
work I don't have time to back up.  But the infected user has
shut down his machine and left, so I can't study it there either.
I do have the Exchange admin trying to filter mail with the
attachment for the moment.

I see another e-mail from the infected, with a tgy.zip attachment
I have yet to start to dissect.  I did a Google search on that,
with no results.

It's not much fun running around in circles with your hair on
fire.  Thank the stars that all my personal e-mail comes to a
SunOS box - 15 years without a single infection!

Vic

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html