Re: Win32.Sircam.Worm Alert.....

From: Meritt James (meritt_james@bah.com)
Date: 07/27/01


Message-ID: <3B6193B5.856B7221@bah.com>
Date: Fri, 27 Jul 2001 12:15:49 -0400
From: "Meritt James" <meritt_james@bah.com>
To: Juanita Fernando <jsscn@optushome.com.au>
Subject: Re: Win32.Sircam.Worm Alert.....

Quite a few add the extension as a way of "hiding" what is going on, not
just Sircam. If you get an attachment with THREE groupings, assume it
is a 'bad thing' and act appropriately. Has anyone seen a three-group
attachment and it been ok?

V/R

Jim

Juanita Fernando wrote:
>
> Hi,
>
> We were caught by surprise by the virus.. it affected 200 workstations
> before we "caught" it. Vet is on top of it now. As a matter of interest,
> the way we identified suspect file attachments was that those affected seem
> to have two file extensions - eg. "word.doc.bat". This signature enabled us
> to get users involved in its control prior to the VET patch installation
> which deletes it from the server and affected workstations.
>
> Cheers
>
> Juanita
> ----- Original Message -----
> From: "Kyle Plate" <kyle@CLASSIFIEDTECHNOLOGIES.COM>
> To: <vuln-dev@securityfocus.com>; <SECURITY-BASICS@securityfocus.com>
> Sent: Thursday, July 26, 2001 8:04 AM
> Subject: RE: Win32.Sircam.Worm Alert.....
>
> > FYI:
> >
> > Using Symantec's NAV for Exchange (Virus def: 7/18/01 12:00am) has been
> > successful for us in detecting and moving to quarantine all Sircam
> infected
> > messages that have been sent to our server.
> >
> > -----Original Message-----
> > From: Jeremy Rodriguez [mailto:jrodriguez@intellinet-tech.com]
> > Sent: Wednesday, July 25, 2001 9:19 AM
> > To: Tom Geldner; 'Johnson, Greg'; vuln-dev@securityfocus.com;
> > SECURITY-BASICS@securityfocus.com
> > Subject: RE: Win32.Sircam.Worm Alert.....
> >
> > Yesterday the worm infected 3 of our systems. Just to test I downloaded
> it,
> > save it a specific folder and scanned it with Norton's (using the latest
> > defs) and to my suprise it did not pick it up.
> > The fix Symantec has:
> > http://www.sarc.com/avcenter/FixSirc.com
> >
> > Did find the worm and repair it.
> >
> >

-- 
James W. Meritt, CISSP, CISA
Booz, Allen & Hamilton
phone: (410) 684-6566



Relevant Pages

  • Re: Win32.Sircam.Worm Alert.....
    ... There are a few joke programs and hoaxes that have the double extensions. ... > just Sircam. ... > Juanita Fernando wrote: ... >>> messages that have been sent to our server. ...
    (Security-Basics)
  • SirCam Protection
    ... Subject: SirCam Protection ... blocking vbs, exe, eml, and the like at the server. ... delete all of the attachments as they go through, ... infected email will sit in a user's inbox for a few minutes before its ...
    (Security-Basics)
  • Re: SirCam Protection
    ... Subject: SirCam Protection ... First of all how are you blocking these attachments? ... blocking vbs, exe, eml, and the like at the server. ...
    (Security-Basics)
  • RE: Sircam
    ... Your product did not eradicate SirCam with your initial Definition file. ... Configuring your gateway or Exchange server to block PIF or LNK extensions ... the gateway is great, but it doesn't help with someone uses Web Email or POP ... What if i suggest to STOP the coming of this virus at all???? ...
    (Security-Basics)