[Dshield] Mydoom, Navarg, Sco what ever

Johannes B. Ullrich jullrich at sans.org
Tue Jan 27 03:09:54 GMT 2004


We breifly considered raising the infocon, but the virus seems to be
dying off slowly as the AV vendors
role out new signatures.

I setup a quick graph of the 'MyDoom' e-mails dropped
by our mail server here:
http://isc.sans.org/images/virus.png

BTW: I have it running in a honeypot, and I don't see the SCO.com attack
so far. Has anybody on the list here seen this?

also: www.caldera.com responds fine for me.




On Mon, 2004-01-26 at 20:39, Paul Marsh wrote:
> This thing is just cook'in along, I'm seeing them come in at spurts of a
> rate of 7 plus per minute.  This has got to be eating up bandwidth
> across the internet?  Should infocon be raised to yellow?  Wonder what
> sco.com did to piss off the author?
> 
> Update and scan your info store before you let your users open mail
> tomorrow.
> 
> Thanx, Paul
> 
> _______________________________________________
> list mailing list
> list at dshield.org
> To change your subscription options (or unsubscribe), see: http://www.dshield.org/mailman/listinfo/list
-- 
CTO SANS Internet Storm Center               http://isc.sans.org
phone: (617) 837 2807                          jullrich at sans.org 

contact details: http://johannes.homepc.org/contact.htm
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://www.dshield.org/pipermail/list/attachments/20040126/67ba5712/attachment.bin


More information about the list mailing list