RE: [Full-Disclosure] Mydoom

From: madsaxon (madsaxon_at_direcway.com)
Date: 01/27/04

  • Next message: Nick FitzGerald: "Re: [Full-Disclosure] Mydoom"
    To: full-disclosure@lists.netsys.com
    Date: Tue, 27 Jan 2004 16:37:35 -0600
    
    

    At 10:08 AM 1/28/2004 +1300, Nick FitzGerald wrote:

    >That page does not specifically address the "zip attachment" form at
    >all, and to the extent that it does mention .ZIP extensions it (_quite_
    >incorrectly) implies that the virus' executable is simply packaged with
    >such an extension. In fact, if it sends itself with a .ZIP extension,
    >Mydoom sends itself as a proper zip archive that contains a "stored"
    >(i.e. not compressed) copy of its executable.

    Two of the copies I've gotten have been proper .zip archives (with
    .zip extension) which contained a UPX compressed executable,
    many of whose ASCII strings were further obfuscated with ROT-13.

    m5x

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Nick FitzGerald: "Re: [Full-Disclosure] Mydoom"

    Relevant Pages

    • RE: [inbox] Re: [Full-Disclosure] Re: E-Mail viruses
      ... >> proprietary extension ... >> use that to unzip the rest of the virus won't read the text ... These folks, with all the sec training tossed ... at them bi-yearly should already know better, and don't thus opening their ...
      (Full-Disclosure)
    • Re: Problem with renaming Word documents
      ... but a virus still got through. ... >> You can only rename files and lose the extension if you display the ... >>> Whenever I had a special need to have the .doc extension ...
      (microsoft.public.word.printingfonts)
    • RE: [Full-Disclosure] Mydoom
      ... madsaxon to me: ... >>incorrectly) implies that the virus' executable is simply packaged with ... > .zip extension) which contained a UPX compressed executable, ... Computer Virus Consulting Ltd. Ph/FAX: ...
      (Full-Disclosure)
    • Re: Who can play this wav file?
      ... extension that calls the API that is required for "executing." ... greatest virus writer in the 21st century. ... only sufficient but necessary for a virus to infect. ... association for wav is messed up. ...
      (microsoft.public.windowsmedia.player)
    • Re: Running program files on XP with non-executable extension?
      ... > virus guard says may be a virus. ... > adding a couple of random letters to the extension. ... > AntiVir PE's guard does not detect it as a virus. ... interpreted by Windows and by various applications. ...
      (comp.security.misc)

  • Quantcast