Full Disclosure mailing list archives
RE: (no subject)
From: Bart.Lansing () kohls com
Date: Mon, 9 Aug 2004 14:47:32 -0500
Discovery Date : 8/10/2004 (PHL)
Origin : USA
Description ( updated : 8/9/2004 11:03:26 AM )
There are reports now in the USA of a malware spreading via email. The
file, price.exe, is spread as a ZIP file, and is included in a supposedly
manually-spammed email.
This price.exe file is a downloader and attempts to download a file named
2.jpg from different sites. The sites are currently inaccessible at the
time of this writing.
Infected customers also report a file named as windll.exe running in the
system.
TrendLabs is still currently analyzing the files and will soon post a more
detailed analysis.
--------------------------------------------------------------------------------
EPS Deliverables
Pattern
OPR 953 for WORM_BAGLE.AC
- Pattern under QA Testing 8/9/2004 11:23:44 AM
Thank you,
Fooks, LynnBart Lansing
Manager, Desktop Services
Kohl's IT
262-703-2911
full-disclosure-admin () lists netsys com wrote on 08/09/2004 02:03:54 PM:
(In regards to new_price.zip file attachment) Anyone have any idea what this is, we had some clients just get pretty hard with this email. I am unable to find anything on it, from my VERY Limited knowledge it appears to be a virus exploiting one of the many holes in IE. Anyone else see anything on this yet? Jonathan Grotegut _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Re: (no subject), (continued)
- Re: (no subject) Maarten (Aug 12)
- Re: (no subject) Michael Simpson (Aug 10)
- Re: (no subject) Paul Schmehl (Aug 10)
- RE: (no subject) Todd Towles (Aug 09)
- RE: (no subject) spoofed addresses still confuse many... Ron DuFresne (Aug 09)
- RE: (no subject) spoofed addresses still confuse many... Todd Towles (Aug 09)
- Re: (no subject) joe smith (Aug 09)
- Re: (no subject) Micheal Espinola Jr (Aug 09)
- Re: (no subject) Michael (Aug 09)
- Re: (no subject) Bob Kehr (Aug 09)
- RE: (no subject) Bart . Lansing (Aug 09)
- Re: (no subject) Micheal Espinola Jr (Aug 09)
- RE: (no subject) Shannon Johnston (Aug 09)
- RE: (no subject) Eric Paynter (Aug 09)
- Re: (no subject) Dave King (Aug 09)
- Re: (no subject) Michael Erdely (Aug 09)
- Re: (no subject) van Helsing (Aug 09)
- Re: (no subject) Tremaine (Aug 09)
- Re: New virus Alan J. Wylie (Aug 09)
- RE: (no subject) Corey Hart (Aug 09)
- (no subject) Dufresne (Aug 09)
