The Mudcat Café TM
Thread #49033 Message #1102698
Posted By: Stilly River Sage
27-Jan-04 - 01:41 PM
Thread Name: Caution: new outbreak of computer worm
Subject: RE: Caution: new outbreak of computer worm
Yesterday my university was clobbered by this latest worm. It does the typical thing, it "spoofs" addresses by taking recently used addresses in the infected computer and remailing itself. This is the alert sent out this morning:
A new variant of the MIMAIL worm has been found. This mass-mailing worm has the ability of generating random email subjects, message bodies and attachment file names. If you get an email with the following information below, please DELETE the email immediately.
Virus Characteristics:
This is a mass-mailing worm that arrives in an email message as follows:
From: (spoofed)
Subject: (any of the following) * Error * Status * Server Report * Mail Transaction Failed * Mail Delivery System * Hello or Hi
Message Body: (any of the following) * The message contains Unicode characters and has been sent as a binary attachment. * The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment. * Mail transaction failed. Partial message is available. * test
Attachment: (varies [.exe, .pif, .cmd, .scr] - often arrives in a ZIP archive) (22,528 bytes)
Examples (common names, but can be random) * doc.bat * document.zip * message.zip * readme.zip * text.pif * hello.cmd * body.scr * test.htm.pif * data.txt.exe * file.scr * deleted.txt
****Also, please check your Virus Definition Files.
You can, as usual, visit Symantec and read all about it.