[Dshield] WMF exploit

Mark Tombaugh mtombaugh at alliedcc.com
Wed Jan 18 16:02:37 GMT 2006


On Wed, 2006-01-18 at 07:32 -0700, Philip H. O'Neill wrote:
> WMF exploit is flying through YaHoo groups. I have not looked at the
> payload. In the last 2 day I received over 100 messages from various
> groups always sized 180-181 of HXQ or UUE and 129 for PIF type files. 

I don't think these are exploiting WMF. Sounds more like:

http://www.sophos.com/virusinfo/analyses/w32nyxemd.html
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%
5FGREW%2EA&VSect=T






More information about the list mailing list