<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii">
<TITLE>Message</TITLE>
<META content="MSHTML 6.00.2800.1264" name=GENERATOR></HEAD>
<BODY style="COLOR: #000000; FONT-FAMILY: ">
<DIV><SPAN class=031480613-28102003>
<P><FONT face=Arial><FONT size=2><SPAN class=031480613-28102003>Has any body
</SPAN>detect<SPAN class=031480613-28102003>ed </SPAN>a new variant of the Nachi
worm infecting machines not patched with MS03-039<SPAN
class=031480613-28102003>. I couldn't find any details on it propagation
except</SPAN></FONT></FONT><FONT face=Arial size=2> <SPAN
class=031480613-28102003>o</SPAN>nce a host is infected, it attempts to
propagate via SMB over TCP (port 445). Any details on exploit
code <SPAN
class=031480613-28102003>/payload...</SPAN><BR><BR></FONT></SPAN></P></DIV>
<DIV><FONT face=Arial size=2></FONT> </DIV>
<DIV align=left><FONT face=Arial color=#0000ff size=2>Best Regards;</FONT></DIV>
<DIV align=left><FONT face=Arial size=2></FONT> </DIV>
<DIV align=left><FONT face=Arial size=2>Farrukh Awan</FONT></DIV>
<DIV align=left>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN
style="FONT-SIZE: 10pt"><FONT face=Arial>(202) -727-8856
(Office)</FONT></SPAN></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN
style="FONT-SIZE: 10pt"><FONT face=Arial></FONT></SPAN> </P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><STRONG><SPAN
style="FONT-SIZE: 10pt"></SPAN></STRONG> </P></DIV>
<DIV><FONT face=Arial size=2></FONT> </DIV>
<P></P></BODY></HTML>