Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




dailydave logo Dailydave mailing list archives

Re: ello! =))
From: Peter Wood <peterw () firstbase co uk>
Date: Fri, 16 Apr 2004 08:17:11 +0100

I'm no expert either, but according to the Sophos site it looks like a Bagle worm. Interesting that it's using my address in the From field - I run Sophos up to date, and just for good measure, I just ran their Bagle disinfector which says I don't have it. Any ideas, anyone?

Pete

At 17:15 15/04/2004 -0400, you wrote:
>I admin I'm no expert when it comes to virus examination, but the
>obfuscation used by this program seems more elaborate than normal.  Does
>anyone recognize this?
>
>-Rob
>
>----- Original Message -----
>From: <peterw () firstbase co uk>
>To: <dailydave () lists immunitysec com>
>Sent: Thursday, April 15, 2004 7:55 AM
>Subject: [Dailydave] ello! =))
>
>
>> I  don't  bite,  weah!
>>
>> password  for archive: 47546
>>
>
>
>----------------------------------------------------------------------------
>----
--------------------------------------------------------------------------------------------------------------------------------

Peter Wood FBCS CITP MIMIS MIEEE
Chief of Operations
First Base Technologies
+44 (0)1273 454525
www.fbtechies.co.uk
www.white-hats.co.uk

_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://www.immunitysec.com/mailman/listinfo/dailydave


  By Date           By Thread  

Current thread:
  • ello! =)) peterw (Apr 15)
    • Message not available
      • Re: ello! =)) Peter Wood (Apr 16)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]