Page 3 of 9 FirstFirst 12345 ... LastLast
Results 21 to 30 of 83

Thread: Virus Alert: Novarg / MiMail / MyDoom

  1. #21
    Senior Member
    Join Date
    Dec 2001
    Posts
    884
    To answer who asked why it was on Windows: The whole point of this virus, it seems, is to DDoS the SCO site, undoubtedly because of their attacks on Torvalds of recent. Linux users, generally, are much too savvy to 1) download a file attachment they don't know the send of or 2) wait more than one minute to patch their system. But, Windows users a lot of the time leave their computers succeptible to attacks because of a lot of their ignorance, and are thus better targets in this market... basically, the writers think they're too dumb to understand what's going on.

  2. #22
    I'd rather be fishing DjM's Avatar
    Join Date
    Aug 2001
    Location
    The Great White North
    Posts
    1,867
    Originally posted here by 576869746568617
    Not quite, DjM. See my post above. The symantec writeup does indeed say that the virus ignores .edu addresses.
    I think that's what I said

    Symantec does mention that it will bypass .edu accounts
    Cheers:
    DjM

  3. #23
    Yes, that's my CC number! 576869746568617's Avatar
    Join Date
    Dec 2003
    Location
    Earth
    Posts
    397
    I stand corrected....It's early and my mailserver's ate up like swiss cheese with this blasted worm! I misread your post.

    My apologies
    Windows 9x: n. A collection of 32 bit extensions and a graphical shell for a 16 bit patch to an 8 bit operating system originally coded for a 4 bit microprocessor. Written by a 2 bit company that can\'t stand 1 bit of competition.


  4. #24
    Senior Member
    Join Date
    Jan 2004
    Posts
    124
    Wow... this thing sounds serious.
    I didn't catch any worm for last 4 years because:
    1. I don't open attachments of any kind if I don't expect them
    2. If it is espected, and it is some kind of animated stuff, I duble check it before I start it
    3. My AV is checking for updates automaticaly, and install them at once!
    4. I check out antivirus sites oftem for fast spreading viruses
    5. I run Windows Update at least once per week


    And I don't still feel safe... Just remeber that damn Blaster thing...
    Ikalo
    ------
    Make your knowledge your deadliest weapon.

  5. #25
    Yes, that's my CC number! 576869746568617's Avatar
    Join Date
    Dec 2003
    Location
    Earth
    Posts
    397
    I do pretty much the same, but when the AV updates at one time, and the definitions come out after the update, you still aren't safe. Automation helps, but it's not a cure all.

    Oh yeah, all you guys with IDS, here's the IDS signature for the trojan portion of the worm. This one is specific to Symantec IS, Manhunt, and SCS (IDS Signature provided by Symantec)....I'm looking for one one for snort....If I can't find one, I'll write one myself (unless Q.o.D. beats me to it!) I will post it here.
    Symantec IDS Signature:

    *******************start file********************

    alert tcp any any -> any 80 (msg:"W32_Novarg_SCO_DOS"; content:"GET / HTTP/1.1|0d0a|Host: www.sco.com|0d0a0d0a|"; offset:0; dsize:37

    *************EOF*********************

  6. #26
    Junior Member
    Join Date
    Jan 2004
    Posts
    11

    Question eSAFE and Novarg (MyDOOM, mimail.q)

    Hi,

    We got eSAFE installed and running fine, removing every attachment which contains a zip, exe, bat, and so on...

    But here is what we see when eSAFE removes a ZIP attachment containing a threat.

    ------------------------------------------------------

    *** eSafe detected a hostile content in this email and removed it. ***
    /readme.zip/readme.txt .pif Msg #705 - The file type pif is on the Restricted List.
    T-ˆ÷Ž*Œåd~õIcaøc;WLóû~rÍ>gLÒ ë¢\Røi^z…q<è0Ñ{ˆ gD”g{ªe19Ð
    &þèCÖ)*¿.NüZµÝN¿æ™œ«¯)ª/J×ÇèsSWÙyûm"µó¡ôö§«
    KïižrE¹úoÚHdºp÷§EÞ~¯ÅY*ÚÁK^{r´ZùD¼8×*F-"ýÛs}Ït²™ö7jVéh'¶½„k5EÛØ:ãm‘bÕôo®ê*É$–×Ø}©d}UËjθ~’ãÀ÷þ?²-îO|²2wf²Ž”ç]ff^&_s9BÆŽŽ-׈6i]…H˪엫sg
    æPclÛA•Mð%q 8U!RÍ*á’4¤D*üwï_„æ‚M…Ó5ˇ2%„Åë0¥èøïÛ.«!mvB‘õüz×ïÉ•çÇé¯ÄvîÏ)ÍH_Í4Œkû‚¼ igŸÕMù>¾å2i7ñn1`
    5ïmüúZ8óŒ9oлy6B\ìr ÈÇMXY#·Žò}â]8ÃãЯ&ßÆYÉ-QMo PÇ Õ
    ÅülÙÍ‘jáPPö*þwñJ½C%X¿»ì‚¯#Ò– ñ}GØë¨27Sòß|$ ücC~-AÊK~YÓ¸ÔPÏ”gmÑQxL* o‡Ÿ|UTÁ,]~‰šÊ’²[çÖ-3•¿±Á ÏVÈüÎyA³ð]ÞRM/*rÛ^ùѽ„n>®8–‚¿Z”;;Ñ¢*MI¡}vÌok“
    ~0èêç Õ |`ó~©)
    ùa:곫Z3ó~Ö”¥BUÈzÄ×_&¶$*
    *,F¤ç
    !¿(õÀ®ÛÞŒƒÖŽ87‰jÏ̾C ký©tm{Ç·zõ?©Sš/é“·<ÍÌ´žyã4ÜmðL*óƒÜ[D?or‹1TÉ|QH¹·&¸ CgYGÜ–¼´OE¢L÷!ß³–,©|(VÓˆ&ËŽÝôÕˆ Ï]ðë;sú#}Ë`˱Z&§Ä”¸{$œ1,û. »w}4‹æŸÇéËZFöÜY© ²qÚÄ# öˆqé®~^Ì2 ØÀ¢‡¢«nùA'ëÚzÊ1Ä8ZÆBü6wb&… ¬a—;Påƒyȇmø~šÓ0¼¾ñö‘éV¨MõÙ
    ~,Ä)ümFsʉ/mïó¿ <#‘„i*ùßÀýkwÑlþD±S¬ÀBêEï¼_C·ÌyX¶~þðö«ôoº“CÙ*B¯–×}S‹æ¬#¢‘q£òÝ;‰’ òÉ< ÈÆSV¬>°ßY~¬yTáÈp÷F ÷?âÚc141·¢!8µðRFE®è ‰Z)ÞÝh¸æ)ë§~Ž—7ZW‘šêçj„ßÐËsBÇÐóê¶s¨•c¸òw*¿ö°Q:²°|bïk‘¶ÙSÊÀÛ•
    °—ýË¥t´yhYÿVè~c½
    òožT^ô*œfØ^•…y*‚>®»ê À¨T’
    •B;hË]M£.©Áfßx½IP‚Þ&·ÁŸš.þ±¹'Ý{×*xÀ?%ég<Y-“fû0:MÇShùý„åâîp êÄ£#;úä-‰N¬ ÜÆTúƒîQæÅúø ;i…-*qÁÊ<Ö)û•œ©¾¥ç\PÑF¯³Ùâ „,WÌžÕè,n»#>Ôc Q~yë¡W-°±n´/“ZqnH
    !|õ^ó‘õˆùCNóÕÐ)—W³sì®ù…G,5K„'tTò샕*NiØ`D¨SúæKË#]
    *5 8Ò0’ÂVn’–-ø3Í/[ÎØsb‡ª'A¤º‹ìï?Zùð'}*¤yC§_ÈÒÁ²óâ“ ÌØåù‰hñkø©‘ç µKMPOpÚáù
    .·;鉚®–Ùº,_êÊŸùŽ®[½ù“×*pùùòZ ¶]d¢ßL 8nl-{›T6¼~sY„> ãã)(ÐHPÔÝØDYMKã‚EJç5 –è©Cé‹õ…‰B¢¢”|#ñ%jWkI1ál¤*CY~ÄäRÛîæÖ¨¾º¹^OâC¸Èëø:ß%*õ*~}Nt¸År~ùG>´„j¶Ò>ÈìG§AÄÍ…>VÞkýšâêË~Ü(_¿ÓØ9½ÚÝÞDzS>5r0¹*ä Àìxôóùp¬`39i ±/žú£Œ2Ô-ðY¨Úܯãtº Ù9ÜðÁAt1ý¸ u‡ ›0Ö0Ú]]ðk¯
    nùZ´ åä£MÞ¢ã‚^e* ïOtù•Dr¿ô¼Úý¥õ5 e©(YÖdGÚ(ó HfôúÚY…|9õÂ_‚èûy‚å"ã²Qvç|ý¤
    kpÇãþ—dd
    îhª‡²‘«´f¨¯M$¬Vý”¤Ú¸º’…!}jëgPÖlw(ñŽ¶“„åÌ÷dK
    nÚ*ñT/¹w ôÓcE"Éï¥å#™^ÌæµÓ«¤yy‚záR*úÚµ¯šRDÛ¾!©Q”áÛ,káä¨7_¶.‡9fÏÍuÕ{ÇÇ~çWçÛÜx°‰dåÊG..2 ‘P·ŒD~áE™&*{“”*børÀº Ë«X~*×ç"¨ö¿8ÚýŒö‘·P¨âG{< I” ¸ŸŸÐ‘!Ó`*\õQ þõ|èPȵÑ÷0³G*[P±~¿jÙÌÉ NK¯Ôã1ì!m’-:1Õ›ZZmë"FŸBS|äÀQԤ̱ Q½!ò²`
    ïY´çfQ1
    •>£ë´DêÅ)S5xÆ*{lUk‡tèýÖ·‘ûTiR,Ò]Ùi^Þ7õE_ßT}Ú|S´E/0ÙªŸ±lçôMž[æÛÞHw¼º›£-E ‘$ëÈsŸùK¶<{ñØŒLý!‰æÙFC¡IÞdÜò{
    5 °}t®g\ø±$תT*¢ÄOãWž»´Ç[.¥Lã™9qƒg–»N÷q›¡…üú¢_‡a¨½6Âj~m)ÏVü™ók«pdç.œ’N ©ž¶›2[ ·o;Tƒ
    °Uq®Ú[-^‡Tþ‡óó_K/§Ì‡Ê‘™‹qåÛµëò«ôT{Ì>ÖaÜ·K}щ¸fӥ㓶¸Ûç’a>ª-&ÓV~²ØµB¥9”DO10säpdz‚Ó¾ç)åÏi•Øfµg-
    ~ -v“óAš{)w9Á)äóÙ¤3œî
    ¿A©^è þ5±¨Žp¿©c`¢Pn°
    X¾²ST_±ˆA¨O:¬²i7gðG‘’&*ï ·üi¡xÇ„'; CÏŒ,Ü -ÌGÈün-ÑÁ
    ÷ƒWaïêÉ*6›BÚãý„5ŸšFU³j Æ
    %[ÌšZÑYÄω;©Òtû¥Ê7‡è
    «!.XB¾måÄ9š&D×¾Tg|&/
    ,è„`óùVgdÒ:zŸÅ|vÂã«ëOûÊB 0¹ ÊÓdž |¸»2ú6£3Ää~ÏNtüçB÷aZû…&žñ¤6Ü£g£Óhù-;v¾kuo
    ÕÔÏy·…,P\ÔœFñcc{®Á,Òþ’§ÒÁr¿â—½î §©pÜ“Vü—*L*zªñÚð±FuNiŽw»Rßù´
    qtBÏ×aL™½÷ùk|©‘‹£¥Xk¤0#…ŽÏ~'ewÊÒÄ›
    l—ño

    ------------------------------------------------------------------

    You see in the top of the e-mail that everything is fine, it says it removed the hostile content but why do we get all that stuff? (with other files, not zips, we don't have this)


    Any ideas!?

    Thanks,

    Roach4

  7. #27
    AO Ancient: Team Leader
    Join Date
    Oct 2002
    Posts
    5,197
    A couple of additional notes:

    1. If you are running snort with the Swen.A rule defined it picks up many of the instances of this virus.

    2. One machine got infected inside my network by the look of it at a sister org who I have less control over....<sigh>. It probably got through before the definitions were available, my mailserver updates hourly. It was trying to send outbound email which is blocked at the firewall. An ethereal dump showed that it was resolving the domain of the recipients prior to attempting to send which was noted by Symantec.

    3. An Nmap of the machine indicated VNC running. The machine is shut down awaiting their tech staff.
    Don\'t SYN us.... We\'ll SYN you.....
    \"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides

  8. #28
    I'd rather be fishing DjM's Avatar
    Join Date
    Aug 2001
    Location
    The Great White North
    Posts
    1,867
    Originally posted here by Tiger Shark

    3. An Nmap of the machine indicated VNC running.
    Tiger, are you saying that the virus dropped VNC on to the system?

    Cheers:
    DjM

  9. #29
    AO Ancient: Team Leader
    Join Date
    Oct 2002
    Posts
    5,197
    NMap claimed that 2 ports used by VNC were open on the target machine...... Unfortunately, being in a hurry I didn't save the scan results and I forget the ports. Added to that I had the machine shut down so I can't rerun the scan.

    I tried to connect using Slarty's VNC thingy and it told me VNC was already running so the ports were definitely open and active. I didn't go any further but simply called the person who knows who's machine that is and had them close it down to stopp the "chatter" at the firewall so I could see if anything else got in.

    Symantec and the rest say it drops a trojan on any number of ports so I guess VNC's ports coincide with the trojan..... I thought that would be of use to some since they may use a VNC client on their systems so it may not be immediately apparent that this may not be what they think it is.
    Don\'t SYN us.... We\'ll SYN you.....
    \"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides

  10. #30
    I'd rather be fishing DjM's Avatar
    Join Date
    Aug 2001
    Location
    The Great White North
    Posts
    1,867

    Re: eSAFE and Novarg (MyDOOM, mimail.q)

    Originally posted here by Roach4

    You see in the top of the e-mail that everything is fine, it says it removed the hostile content but why do we get all that stuff? (with other files, not zips, we don't have this)

    Any ideas!?

    Thanks,

    Roach4
    I suspect this is the contents of the zip file before the virus is stripped away.

    Cheers:
    DjM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •