Re: WORM_MIMAIL.A Anyone have any info on what this does yet?

From: Sam Evans (samat_private)
Date: Fri Aug 01 2003 - 13:51:45 PDT

  • Next message: Peter Fry: "Re: RPC DCOM exploit"

    Likewise..  We haven't looked into this yet, as we are trying to unravel
    the mess it has created.
    
    I'm fearing the worst though...
    
    On Fri, 1 Aug 2003, Danny wrote:
    
    > We are getting flooded with these little puppies, does anyone have any
    > additional info on what this thing does once it infects a host?
    > I'll be infecting a box to test myself after i send this email but if
    > anyone has done testing already it would great to hear your input.
    >
    > Norton have released a Def for this and identify the virus as
    > WORM_MIMAIL.A
    > (http://securityresponse.symantec.com/avcenter/venc/data/
    > w32.mimail.aat_private)
    >
    > If any one would like a copy of the original code you can get it at
    > http://akasha.irt.drexel.edu/message.zip
    >
    >
    >
    > Danny
    > Work - http://www.eBoundary.com - Secure, FreeBSD hosting.
    > Play - http://www.eBoundary.net - Who really sets your electronic
    > boundaries?
    > AIM: eBoundaryTch  | ICQ: 3090141
    >
    >
    > ---------------------------------------------------------------------------
    > ----------------------------------------------------------------------------
    >
    >
    
    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    



    This archive was generated by hypermail 2b30 : Sun Aug 03 2003 - 08:40:12 PDT