[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [Full-Disclosure] MyDoom Email targets
- To: <full-disclosure@netsys.com>
- Subject: RE: [Full-Disclosure] MyDoom Email targets
- From: "Geo." <geoincidents@getinfo.org>
- Date: Tue, 27 Jan 2004 13:43:42 -0500
Yes I've been seeing a LOT of that as well, and I believe it is an attempt
to mess up the blacklist spamtrap addresses such as the ones that spamcop
uses. The worm appears to generate a bunch of very common named email
addresses all on it's own.
Geo.
-----Original Message-----
I've noticed I'm getting a load of messages to my catch all domains with
addresses like adam@.... joe@.... sandra@.... - it's highly unlikely
that this would be part of anyone's address book - is there some
mechanism in the worm to try and propagate to random e-mail within a domain?
Scott Manley
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html