|
December
2003.
|
|
|
|
|
|
|
|
November
2003.
|
|
|
|
|
|
|
|
October
2003.
|
|
|
-
W32.Sober aka Sober:a mass-mailing worm
that Will disguis itself as a security warning for
a new worm and a fix from an AV company. Using its
own SMTP engine to spread. Attachment will have
a .bat, .com, .exe, .pif, or .scr file extension.
|
|
September
2003.
|
|
|
|
|
|
August
2003.
|
|
|
-
W32.Blaster.Worm aka Lovsan: HP OpenView
has determined that the worm virus recently referred
to as "Blaster" or "W32.Blaster.worm",
may impact hp OpenView products running on Microsoft
Windows, HPUX, Solaris and Linux.
|
|
|
|
|
-
W32.Sobig.F aka Sobig.F: a new Sobig member.
Sends itself to all the email addresses that it
finds in the files with the following extensions:
.dbx, .eml, .hlp, .htm, .html, .mht, .wab, .txt
|
|
|
|
|
|
|
-
Backdoor.IRC.Cirebot aka RPC - Downloader.DM:
a Trojan Horse that exploits the Microsoft DCOM
RPC vulnerability. Will install Trojan Horse on
vulnerable systems. Characteristic is the existence
of files: C:\Rpc.exe, C:\Rpctest.exe, or C:\Lolx
|
-
W32.Mimail.A aka Mimail: a worm that spreads
by email with the ability to capture users information.
Uses it's own SMTP engine to send email to addresses
found in files without extension[s]:
COM,WAV,CAB,PDF,RAR,ZIP,TIF,PSD,OCX,VXD,MP3,MPG,AVI,DLL,EXE,GIF,JPG,BMP
Attachment name: message.zip
|
|
July
2003.
|
|
|
|
June
2003.
|
|
|
|
|
|
|
|
|
|
|
|
May
2003.
|
|
|
-
W32.HLLW.Magold aka Magold - W32.Auric:
a mass-mailing worm that attempts to spread
over e-mail, P2P networks and IRC chat. Will send
itself to all contacts in the Windows Address
Book and in files with the .html, .htm, and .hta
extensions. When executed, a fake message box
with the title "Directx" will be displayed.
Attachment name: Maya Gold.scr.
|
-
W32.Naco.B aka Naco.B - Anacon.B: a mass-mailing
worm containing multiple threats:
[1] Attempts to spread itself through file-sharing
networks KaZaA, Limewire, Morpheus, Grokster, Bearshare,
and Edonkey2000 and through email.
[2] Contains Backdoor functionality and tries
to replace HTML files on the Microsoft IIS server.
[3] Will try to perform a DOS [Denial of
Service] attack against a predefined list of sites.
[4] Attemps to delete files and format hard
disk[s].
Attachment name: WARS.EXE
|
-
W32.Sobig.B aka Sobig.B - Palyh: sends itself
to email addresses found in files with extension:
.wab, .dbx, .htm, .html, .eml, .txt
Characteristic is file: msccn32.exe
|
|
|
|
|
|
|
|
April
2003.
|
|
|
|
March
2003.
|
|
|
|
|
|
|
-
HLLW.W32.Deloder aka Deloder: a network-aware
worm that attempts to connect to a target host,
using TCP port 445 [Windows 2000 and Windows XP
only]. If the connection is succesful, file Inst.exe
will be copied to hard-coded locations. File Inst.exe
is a backdoor Trojan component that is detected
as Backdoor.Dvldr. After this, W32.HLLW.Deloder
will load from the Startup folder when you start
Windows.
|
-
W32.Bibrog: a mass-mailing worm that sends
itself to all the contacts in the Outlook Address
Book. Attempts to spread through KaZaA, Grokster,
and Morpheus file-sharing networks, as well as ICQ.
Attachment name: Academia.exe
|
-
W32.Yaha.P aka Yaha.P: uses its own SMTP
engine to email itself to all the contacts in the
Windows Address Book, MSN Messenger, .NET Messenger,
Yahoo Pager, and in all the files whose extensions
contain the letters HT.
|
|
February
2003.
|
-
W32.HLLW.Lovgate.C aka Lovgate: has both
backdoor and worm capabilities. As a worm, it
spreads via email and network-shared folders. As
a backdoor, it allows remote users to access
the system through port 10168.
|
|
January
2003.
|
-
W32.SQLExp aka W32/SQLSlammer - Slammer:
a worm that targets the systems running
Microsoft SQL Server 2000, as well as Microsoft
Desktop Engine (MSDE) 2000. The worm sends 376 bytes
to UDP port 1434, the SQL Server Resolution Service
Port.
|
-
W32.Sobig.A aka Sobig: spreads via email
and network shared drives. Tries to download other
files from web pages located on a geocities site.
Sends itself to all the addresses it finds in .txt,
.eml, .html, .htm, .dbx, and .wab files.
Attachment name: Movie_0074.mpeg.pif - Document003.pif
- Untitled1.pif - Sample.pif
|
-
W32.Lirva.A aka Avril: a mass-mailing worm
that also spreads by IRC, ICQ, KaZaA, and open network
shares. Tries to terminate antivirus and firewall
products. It also emails the cached Windows 95/98/Me
dial-up networking passwords to the virus writer.
|