|
|||||||||||
|
RE: WORM_MIMAIL.A Anyone have any info on what this does yet?
From: att13543 <skid(at)attglobal.net>
Date: Tue Aug 05 2003 - 13:26:23 EDT
-----Original Message-----
att13543 wrote Monday, August 04, 2003 9:54 AM > I'd be interested if anyone can correlate what I've seen: we have 2
All of ours were sent to one specific mail server that is way down the priority list. This matches previous spammed email malware patterns, and I cannot recall any previous worm that looked up all the mail servers and used the lowest-priority one. I'm guessing that the ones we have received were sent by the worm distributors rather than from infected machines. I've dropped them all before the full headers were delivered, so I don't have any way to positively verify this theory. AV vendor descriptions say the worm takes SMTP server info from the infected computer, which is inconsistent with copies arriving through a low-priority mail server that user are not aware of. Has anyone examined the message headers to see if there is a detectable difference between messages coming from an infected system and those spammed by the worm author? Received on Tue Aug 5 18:53:35 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:15 EDT |
||||||||||
|
|||||||||||