anomy-list

New "my party" worm -- uuencoded

From: D. J. Hagberg (33841@xyz.molar.is)
Date: Mon 28 Jan 2002 - 19:37:51 UTC

  • Next message: Bjarni R. Einarsson: "Re: New "my party" worm -- uuencoded"

    Does Anomy have any facilities to quarantine the new "my party" worm?
    That worm uses a vector that's new to me -- uuencoded file in the body of
    the message, not as a separate MIME part. Kinda like we used to use to
    send files around circa 1992 or so...

     From: "Some bozo Running Outlook [CONTRACTOR]" <33933@xyz.molar.is>
     To: 33976@xyz.molar.is
     Subject: new photos from my party!
            
            Hello!
            
            My party... It was absolutely amazing!
            I have attached my web page with new photos!
            If you can please make color prints of my photos. Thanks!
            
            
            begin 666 www.myparty.yahoo.com
            M35J0``,````$````__\``+@`````````0```````````````````````````
            M````````````````````@`````X?N@X`M`G-(;@!3,TA5&AI<R!P<F]G<F%M
            M(&-A;FYO="!B92!R=6X@:6X@1$]3(&UO9&4N#0T*)`````````!010``3`$#
            M`)(B4CP``````````.``#P$+`04``'`````0````T```X$P!``#@````4`$`
            M``!````0`````@``!``````````$``````````!@`0``$`````````,`````
            M`!```!``````$```$````````!````````````````!0`0`(`0``````````
            M````````````````````````````````````````````````````````````
            M````````````````````````````````````````````````````````````
            M`````````````````````````````````-`````0``````````(`````````
            M`````````(```.````````````!P````X````'`````"````````````````
            M``!```#@````````````$````%`!```"````<@``````````````````0```
            MP```````````(0P)`@APIK/NYMN=S<$E`0#';````-X``"8!`$W=_O__58OL
            M@>P$`0``BT4,4U97BP"CH`%!`.@0!!2_^V?W!&0)`<#XA<!T!0@-'VB@R$!O

    and so forth. Outlook, Eudora, and even Netscape 6 all show this as an
    attachment even though it isn't one, technically. Because it has the .com
    extension, users that double-click this attachment are asked if they want
    to execute it. And some bozos click Yes...

    Any suggestions appreciated.

                            -=- D. J.



    hosted by molar.is