[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [Full-Disclosure] outbreak update
- To: "'Gadi Evron'" <ge@egotistical.reprehensible.net>, bugtraq@securityfocus.com, full-disclosure@lists.netsys.com
- Subject: RE: [Full-Disclosure] outbreak update
- From: Kane Lightowler <kane.lightowler@it.alstom.com.au>
- Date: Tue, 27 Jan 2004 11:38:04 +1100
Yes it is alot of naming confustion
Trend is detecting this as the MIMAIL.R
Mcafee As Mydoom
Symantec as Novarg
CA as Shmig
Propogates via SMTP & Kazaa
Also it starts up 63 threads all requesting the index page of
www.sco.com every 300 milliseconds.
Kane
-----Original Message-----
From: Gadi Evron [mailto:ge@egotistical.reprehensible.net]
Sent: Tuesday, 27 January 2004 10:06 AM
To: bugtraq@securityfocus.com; full-disclosure@lists.netsys.com
Subject: [Full-Disclosure] outbreak update
Confirmed - just a name confusion.
This is the same worm.
It seems to possibly be a new mimail variants so Trend probably had the
name right.
Network slowdown is already being felt.
Gadi Evron
The Trojan Horses Research Mailing List - http://ecompute.org/th-list
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
_____________________________________________________________________
CONFIDENTIALITY: This e-mail and any attachments are confidential and may be
privileged. If you are not a named recipient,please notify the sender
immediately and do not disclose the contents to another person, use it for any
purpose or store or copy the information in any medium.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html