Tracking SirCam

From: Peter Krawczyk (petek@mc.net)
Date: 07/25/01


Date: Wed, 25 Jul 2001 10:49:05 -0600 (MDT)
From: Peter Krawczyk <petek@mc.net>
To: <incidents@securityfocus.com>
Subject: Tracking SirCam
Message-ID: <Pine.LNX.4.33.0107251043150.6319-100000@equerry.bsod.net>

Trying to track the SirCam virus without looking at the body of the
message, we've found a way to track it via headers.

In the header of the message, everything looks dynamic, and so tracking it
seems to be hard. However, there is a slip -- the Date: header actaully
appears as 'date:'.

A cursory examination of thousands of emails from mailing lists, private
sources, and other sources shows that the only messages using the lower
case 'date:' for the header are sent by the SirCam virus.

This may help those of you who want to filter on headers and not on
message body.

-Pete K

--
Pete Krawczyk <petek@mc.net>
  Senior System Administrator
  mc.net <http://www.mc.net/>
  (847) 594-5111

---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Tracking SirCam
    ... Subject: Tracking SirCam ... there is a slip -- the Date: header actaully ... | case 'date:' for the header are sent by the SirCam virus. ... but one of these I've seen came through mail lists, ...
    (Incidents)
  • Re: track changes and header problem
    ... Don't turn on change tracking after updating the document - As soon as ... anything causes the header/footer to update, they'll register a change. ... > but the header still shows deleted text and the revised text (the header ...
    (microsoft.public.word.pagelayout)
  • Re: Tracking SirCam
    ... Subject: Tracking SirCam ... Peter Krawczyk wrote: ... the virus engineers its own SMTP header. ... Is the FROM: information correct? ...
    (Incidents)
  • track changes and header problem
    ... a couple of suggestions on how to fix this, there were no clear answers and ... Running 2000 with tracking changes enabled. ... but the header still shows deleted text and the revised text (the header is ... send this out to a customer and am just trying to remove the last remnants ...
    (microsoft.public.word.pagelayout)