Security Basics mailing list archives
Re: Worm.SCO.A
From: Brian Keefer <chort () amaunetsgothique com>
Date: 27 Jan 2004 16:43:20 -0800
On Mon, 2004-01-26 at 14:38, Shawn Jackson wrote:
Anyone else encountering this? I've just got hammered with a few hundred of these in the last hour and a half and I can't quite discern what exactly the virii is. There doesn't seam to be a map from ClamAV virus naming format to any other. Anyone have a clue of what this virus is?
It's MyDoom.A. Sophos lists it as: W32/MyDoom-A Aliases Mimail.R, Novarg.A, Shimg, W32.Novarg.A@mm, W32/Mydoom@MM More info is available on the usual sites. In summary it does the common "harvest e-mail addresses and remail myself" trick that we have seen so many times now. It also installs a backdoor for remote control, readies itself to DDoS SCO's website, and according to some (unsubstantiated, that I can tell) reports, it installs a keystroke logger. -- Brian Keefer, CISSP Systems Engineer CipherTrust Inc, www.CipherTrust.com --------------------------------------------------------------------------- Ethical Hacking at InfoSec Institute. Mention this ad and get $720 off any course! All of our class sizes are guaranteed to be 10 students or less. We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion Prevention, and many other technical hands on courses. Visit us at http://www.infosecinstitute.com/securityfocus to get $720 off any course! ----------------------------------------------------------------------------
Current thread:
- Worm.SCO.A Shawn Jackson (Jan 27)
- Re: Worm.SCO.A jamesworld (Jan 27)
- Token Authentication for Terminal Services erisk (Jan 28)
- Re: Worm.SCO.A Ricardo Oliva (Jan 28)
- Re: Worm.SCO.A Brian Keefer (Jan 28)
- Re: Worm.SCO.A Marcos E. Rodriguez (Jan 28)
- RE: Worm.SCO.A Reggie Jackson (Jan 28)
- <Possible follow-ups>
- RE: Worm.SCO.A Michael Bellears (Jan 28)
- RE: Worm.SCO.A Hamish Stanaway (Jan 28)
- RE: Worm.SCO.A Shawn Jackson (Jan 28)
- RE: Worm.SCO.A Jones, Steve (Jan 28)
- RE: Worm.SCO.A Shawn Jackson (Jan 29)
- Re: Worm.SCO.A jamesworld (Jan 27)