[Dshield] New Outlook virus?
frank at cstech.com.au
Wed Oct 2 03:25:00 GMT 2002
yes this morning submitted it to symantec australia (sample)
----- Original Message -----
From: "John Draper" <crunch at shopip.com>
To: <list at dshield.org>
Sent: Tuesday, October 01, 2002 7:35 PM
Subject: Re: [Dshield] New Outlook virus?
> > Has anyone seen a potentially new Outlook virus in the wild?
> > It appears that you receive an infected message that shows no
> >attachment when viewed in Outlook. When opened the virus sends email
> >out to people in your address book with a subject and content taken
> >from a previously sent message. One person reported seeing something
> >flash on their screen very quickly when it was opened. The virus is
> >attaching itself using the name of an attachment you sent before.
> > Up to date Mcafee and Norton virus scanners do not appear to be
> >catching it. My Anomy Sanitizer at home caught that there was an .scr
> >attachment with the message and defanged it. Other people reported
> >that their virus scanner did not catch it but an email defanger did.
> Do you appen to have a copy of the virus in binary form? I want to write
a "snort" rule for it right away.
More information about the list