[60132] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: maybe this should be on sec focus but.

daemon@ATHENA.MIT.EDU (Forrest Houston)
Fri Aug 1 14:35:06 2003

Date: Fri, 1 Aug 2003 14:28:54 -0400 (Eastern Daylight Time)
From: Forrest Houston <fhouston@east.isi.edu>
To: Drew Weaver <drew.weaver@thenap.com>
Cc: "'nanog@merit.edu'" <nanog@merit.edu>
In-Reply-To: <75634F04BFCFD511BF69009027DC86497D1885@mailman.thenap.com>
Errors-To: owner-nanog-outgoing@merit.edu


That's funny, I had atleast one person here receive a similar email which
was forwarded on to me.  I ran it through McAfee (4.5.1 engine, 4.0.4280
DAT) and it picked it right up (Trojan Name: Exploit-Code Base
http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=99383).
Potentially it's a different incident than what they are talking about but
the admin@domainname and the attachment are similar (it was a zip file
containing an html file [according to the extensions]).

Forrest

On Fri, 1 Aug 2003, Drew Weaver wrote:

>             I have had like 4 users call and tell me that they're receiving
> email from admin@ourdomainname with a unidentified attachment, possibly a
> worm that exploits the new Microsoft vulnerability last week, all 4 of these
> people reported that their updated this morning antivirus software missed
> it.
>
>
>
> FYI.
>
>
>
>
>
>

home help back first fref pref prev next nref lref last post