North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: Possibly yet another MS mail worm

  • From: Stephen Milton
  • Date: Sat Feb 28 01:45:08 2004

Yes, I got that one too.  To my peering alias by coincidence.  ClamAV
identifies it as "Worm.Bagle.A2".  ClamAV added it the database today,
and mentioned that it was not in most signature databases yet.

On Fri, Feb 27, 2004 at 07:12:42PM -0500, Todd Vierling wrote:
> This one may be a variant of the recent worms.  It's spreading by way of
> zipfile attachments.  I don't have more info yet, but my $orkplace has just
> been hit by it and it's unknown to McAfee and Symantec at this time.
> It's not W32.Netsky, as best I can tell, because of the attachment filename:
> this one uses things like that are new to me.  I don't have
> more info on it at this time, but will try to snare a sample in transit if
> it hits my home system.
> Just a heads-up,
> -- 
> -- Todd Vierling <[email protected]> <[email protected]>

Stephen Milton - Founder/VP Internet           (425) 881-8769 x102
ISOMEDIA.COM - Premium Internet Services        (425) 869-9437 Fax
[email protected]