[Full-Disclosure] Netsky.P -> sneaky one!
Federated Information Security
FederatedInformationSecurity at federatedinv.com
Tue Mar 23 16:31:39 GMT 2004
Something different about netsky.p vs all the other variants: I'm
seeing this one spread evenly across all my mail gateways. Earlier
variants only hit my first MX record, this one is either ignoring MX
weights or getting them backwards. Maybe that's why this one's making
the rounds a bit more than other recent variants.
We're living in interesting times when even viruses have hotfixes...
From: full-disclosure-admin at lists.netsys.com
[mailto:full-disclosure-admin at lists.netsys.com] On Behalf Of Andrew Aris
Sent: Tuesday, March 23, 2004 5:45 AM
To: full-disclosure at lists.netsys.com
Subject: [Full-Disclosure] Netsky.P -> sneaky one!
just had a mail throught that NAV has detected as being Netsky.P, the
text of the mail was:
From: jaume at megacceso.com [mailto:jaume at megacceso.com]
Sent: 23 March 2004 08:24
Subject: Re: approved information
+++ Attachment: No Virus found
+++ MC-Afee AntiVirus - www.mcafee.com
I thought the "MC-Afee" bit was a nice touch, might just convince a fair
big fish internet ltd, 8 beetham road, milnthorpe, cumbria LA7 7QR
tel: +44 (0)15395 64580 http://www.bfinternet.co.uk
big fish internet limited t/a bf internet registered in england no.
Full-Disclosure - We believe in it.
Full-Disclosure is hosted and sponsored by Secunia.