WORM_DREFIR.C |
|
| BugsAlert Home > WORM_DREFIR.C | |
|
This memory-resident worm propagates by sending a copy of itself as an attachment to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine. It generates email addresses by using a list of names and any of the domain names of the previously gathered addresses. The email it sends out has the following details:
Subject: (any of the following) It spreads via Internet Relay Chat (IRC) servers. It connects to various servers and uses certain nicks. It then displays certain messages either containing a URL or hyperlinked phrases that when clicked downloads a copy of itself. It checks for the current month and day of the system. If it finds the month and day to be June 29 it deletes the contents of all accessible files in fixed and mapped network drives. It also displays the following message box:
Original Source: http://feeds.trendmicro.com/~r/MalwareTop10/~3/178716441/default5.asp Learn more about WORM_DREFIR.C |
|
| Tags: worm drefir.c | |
Related Items |
|
|
Bugtraq: Re: [SVRT-05-08] Critical BoF vulnerability found in ffdshowaffecting all internet browsers (SVRT-Bkis)
|
|
|
CVE-2008-2009 (libvorbis)
|
|
|
HP Oracle for OpenView Multiple Vulnerabilities
|
|
|
JS_BADPOPUP.A
|
|
|
VU#767825:Liferay Portal fails to protect against CSRF
|
|
|
CVE-2008-4674 (real_estate)
|
|
|
TUGzip 3.00 archiver .ZIP File Local Buffer Overflow Exploit
|
|