Re: Win32.Sircam.Worm Alert.....

From: Nicolas Gregoire (nicolas.gregoireat_private)
Date: Wed Jul 25 2001 - 01:05:35 PDT

  • Next message: David R. Conrad: "Re: A code red that could bring down the net?"

    Tom Geldner wrote :
    >
    > Some of our corporate accounts have been pounded on by a particular user
    > on verizon.net. None of those e-mail addresses are from someone's
    > address book. They are all things like info@, webmaster@, postmaster@
    > etc. so in our case, someone seems to be trying to propogate it
    > deliberately.
    
    The worm/virus use 2 sources of email adresses.
    The first one is the *.wab (Windows Adress Books) found on the
    hard-drives.
    The second one is from the Temporary Internet Files.
    
    Fox example, I usually receive emails for adresses like
    infoat_private & helpat_private and these 2 adresses are listed
    on our website. Every person infected by SirCam, using IE and browing
    our site will send me one of his personnal documents.
    I have receive more than 100 this week.
    
    Nicob
    Please excuse my shitty english, it's very early
    



    This archive was generated by hypermail 2b30 : Wed Jul 25 2001 - 11:45:54 PDT