Re: [Full-Disclosure] W32.novarg.a - Highly distributed mass mailer

From: Nick FitzGerald (nick_at_virus-l.demon.co.uk)
Date: 01/27/04

  • Next message: Raymond Dijkxhoorn: "Re: [Full-Disclosure] Status"
    To: full-disclosure@lists.netsys.com
    Date: Tue, 27 Jan 2004 13:39:29 +1300
    
    

    Michael Skaff <michael@coolsign.com> wrote:

    > Apologies if this is off topic, but I thought it merited posting, given the
    > distribution.
    >
    > Norton has also tagged the same worm referenced in the previous posting from
    > McAfee, but they're calling it Novarg. No details yet. We've seen a
    > variety of file names and subject headers, although "Hi", "Hello" seem to be
    > the most popular so far. "Text" "File" and "Message" seem to be popular
    > file names. We are seeing ~25/hr @ the gateway, and rising.

    You will see a lot more -- this seems to have gone ballistic...

    BTW, NAV detecting it as "Novarg" and Trend as "Mimail.R" is just
    another case of multiple labs working on the same massive outbreak
    independently before realizing just how widespread it was (or at least
    had realistic potential of reaching). I have heard from analysts at
    Symantec that they will rename it Mydoor to be in keeping with the bulk
    of the other developers, and Trend is pretty good about renaming things
    in such situations, so I guess they will follow suit too.

    -- 
    Nick FitzGerald
    Computer Virus Consulting Ltd.
    Ph/FAX: +64 3 3529854
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Raymond Dijkxhoorn: "Re: [Full-Disclosure] Status"

    Relevant Pages

    • Re: Explorer crashes at least once all the time
      ... Do you really want to trust someone that was banned from posting ... And do you really want to trust someone that has had to change their ... Calling an illegal alien an "undocumented worker" is like calling a ... A .dll file is a special type of Windows program ...
      (microsoft.public.windowsxp.general)
    • Re: Has Anyone Seen Sean Baker This Summer?
      ... Just as is posting a private email. ... Joe's name calling is just that, ... Joe is a big boy, ... Thing is, though, nothing posted about Mark was not something that he had ...
      (rec.music.gdead)
    • Re: Good Ole Fox News Does It Again...
      ... Dude...Board is a tin foil hat moonbat. ... yet another gratuitous leg-hump insult from David. ... And I'm calling Board on specific behavior, ... You weren't even responding to his posting, ...
      (rec.sport.football.college)
    • Re: Private e-mail from DannyT
      ... Calling him a clown for that was out of line. ... this manner is terribly poor form and does no good whatsoever. ... Rich could have achieved putting everyone here 'on notice' by posting ...
      (alt.guitar.bass)
    • Re: [Bill Baka] Can we kill a cancer?
      ... John Fields wrote: ... calling you a bullshitting motherfucker racist KKK Nazi. ... Why are you posting to sci.electronics.basics? ...
      (sci.electronics.basics)